Mailing List Archive

TACACS interface 'opt-out'
Hi,
We have, for years, used TACACS to control access to all interfaces on our
a-servers. I've a requirement to allow access to users dialing a particular
DNIS on a 5300 without TACACS AAA while still forcing different DNIS callers to
authenticate. I thought the 'AAA DNIS MAP' would do it but it doesn't seem to
allow you to config. no authentication. Any suggestions on how I might
accomplish this?.....Is it even possible?

.......thanks in advance...........Jamie

James Savage York University
Senior Com. Tech. 108 Steacie Bldg.
jsavage@yorku.ca 4700 Keele Street
phone: 416-736-2100 ext.22605 Toronto, Ontario
fax: 416-736-5701 M3J 1P3, CANADA
/\ /\ /\ /\
/ \ / \ / \ / \
\ / \ / \ /
\/ \/ \/
Re: TACACS interface 'opt-out' [ In reply to ]
You can use RPM to apply different templates to different DNIS's. Each
template can have different types of ppp/aaa configuration. Kind of
overkill for your needs, but the dnis map won't be able to do what you
want.

http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fdial_c/fnsprt11/dafrpm.htm

Dennis

James Savage [jsavage@yorku.ca] wrote:
> Hi,
> We have, for years, used TACACS to control access to all interfaces on our
> a-servers. I've a requirement to allow access to users dialing a particular
> DNIS on a 5300 without TACACS AAA while still forcing different DNIS callers to
> authenticate. I thought the 'AAA DNIS MAP' would do it but it doesn't seem to
> allow you to config. no authentication. Any suggestions on how I might
> accomplish this?.....Is it even possible?
>
> .......thanks in advance...........Jamie
>
> James Savage York University
> Senior Com. Tech. 108 Steacie Bldg.
> jsavage@yorku.ca 4700 Keele Street
> phone: 416-736-2100 ext.22605 Toronto, Ontario
> fax: 416-736-5701 M3J 1P3, CANADA
> /\ /\ /\ /\
> / \ / \ / \ / \
> \ / \ / \ /
> \/ \/ \/
>
> _______________________________________________
> cisco-nas mailing list
> cisco-nas@puck.nether.net
> https://puck.nether.net/mailman/listinfo/cisco-nas