- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Tacacs authentication from standby member in R80.x...
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Tacacs authentication from standby member in R80.xx
I have a Cluster HA with 3 members, i enabled the parameter fwha_forw_packet_to_not_active indicated in the sk42695.
But i saw that the traffic is blocked by the active member. In R80.10 and R80.20 i had this problem.
The workaround that i applied is:
* Permit the Physical IP of the FWs in the Tacacs servers for authetication
* Create a NAT exception (prevent the hide nat cluster VIP) for the FWs send the request to the tacacs Server with its own address
* Tacacs authentication working in the standbys members.
0 Replies
