Friday, June 2, 2017

cisco ACS max subnet limits 40

When defining your AAA clients,  it critical to be aware of the max ip entries are limited to 40 max in cisco ACS appliance.

 Here's what happens when you try to exceed this set max value;




The easiest means to circumvent this; "  is to craft numerous  device groups,  and keep the entries under  40 items or define a CIDR prefix  ip_subnet instead "


here's some  examples on how you  could  stroke numerous  groups


( Geograohical   )

WEST   /   CENTRAL   / EAST

or

USA1  USA2  EU ASIA AFRICA


And within group just make sure you have  40 or less entries. If you need more address just add more group by appending a number.instance  or  Alpha.Characters


USA1
USA2
USA3
USA4

or

EU1
EU2
EU3
EU4

or

ASIA_A
ASIA_B
ASIA_C

or

ROUTER1
ROUTER2
ROUTER3
ROUTER4


Ken Felix





Ken Felix
NSE ( network security expert) and Route/Switching Engineer
kfelix  -----a----t---- socpuppets ---dot---com
     ^      ^
=(  @  @ )=
         o 

        /  \

No comments:

Post a Comment