I configured AAA on a number of PIX firewalls, ver 5.3(2), everything worked great in initial testing so it was installed in the production. We use an ACS and RSA to authenticate the administrators when they log in to PIX with ssh, simple enough. However quite often we would find that the passcode entered would be rejected, after the third failure you would then have to re-sync your token with the server to be able to use it again. We have lots of other Cisco equipment with and without ssh and it's only on the PIX that we see this problem, has anyone else experience of these problems with the combination of PIX and ACS
cheers Pat Message Posted at: http://www.groupstudy.com/form/read.php?f=7&i=53076&t=53076 -------------------------------------------------- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]