Forum Discussion
LTM (v11.3) TACACS+ authentication - Cisco ACSv4.1
The attribute string we use for device administrators looks like this:
F5-LTM-User-Info-1=adm
You can check out Jason's writeup on remote TACACS authorization here:
https://devcentral.f5.com/articles/v10-remote-authorization-via-tacacs-43.Uxca8oUgvZc
When we originally set this up, we were using ACS 4.2. We've since migrated to 5.2, then to 5.3, so I don't have a 4.1 instance to check on, so I'll go by memory. You specify the attribute per user group (or per user), and use the same attribute that you specified in the remote role group within the BIG IP. I think you specify it in group attributes. A guide from Cisco is here:
http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4-2/user/guide/ACS4_2UG/GrpMgt.htmlwp479948
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
