每个ASA最多设置15个组,每个组最多16个server,多个server可能设置多个做冗余的ACS 服务器,多个组可让不同的条件去不同的ACS上做认证,更灵活。
在多模式的单context下最多设置4个组,每个组里最大有4个server。
有一个用户访问需要认证,同时只能有一个server被访问,它没响应则去第二台server,依此类推,直到有server响应为止。响应了,后面的不会轮到了。
aaa-server a protocol radius
aaa-server a (inside) host 1.1.1.1
aaa-server a (inside) host 1.2.2.2
aaa-server a (inside) host 1.3.3.3
aaa-server a (inside) host 1.4.4.4
aaa-server b protocol tacacs+
aaa-server b (inside) host 2.2.2.1
aaa-server b (inside) host 2.2.2.2
aaa-server b (inside) host 2.2.2.3
aaa-server b (inside) host 2.2.2.4
aaa authentication match 110 inside a
aaa authentication match 111 inside b