Forum Discussion
XINGYU_99486
Nimbostratus
May 22, 2014How to configure TACACS+ on Cisco ACS 5.3 for authenticating administrative users on LTM 11.2.0?
Hello,
I was desperate to get the Tacacs+ working on Cisco ACS for LTM 11.2.0. However I was not be able to find a direct answer.
There is my configuration on LTM ->System -> Users -> Auth...
Cory_50405
Noctilucent
May 22, 2014Sure. Here's our remote role config for our administrator role:
auth remote-role {
role-info {
/Common/GW_Administrator {
attribute F5-LTM-User-Info-1=adm
console tmsh
line-order 1
role administrator
user-partition all
}
Your TACACS+ server config should look something like this:
auth tacacs /Common/system-auth {
protocol ip
secret ******
servers { 10.1.1.1 10.1.1.2 }
service ppp
}
The ACS group that you wish to have administrator access will need to be assigned that shell profile you created in ACS. But the ACS group name will have to match verbatim what the remote role name is (in our case, it's GW_Administrator).
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects