ASA in multi context mode and AAA based on context

Hello, running ASA5520 in multicontext mode, and would like to apply AAA in separate contexts; eg. context A and B should have AAA authentication and context C not.
I am familliar how to setup AAA in single firewall mode but not sure about correct procedure when setting up AAA in multicontext mode.
Is it possibe to configure individual contexts for AAA?
Thanks

Hi,
Yes, it is possible to setup AAA in individual contexts. The procedure is going to be exaclty the same as when the firewall is in single context mode.
Just be careful while configuring command authorization on a firewall in multiple context.
http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/mgaccess.html#wp1060011
Hope it helps.
Thanks,
Amitashwa

Similar Messages

  • Does Firefox 13 run in a multi-threaded mode and can it utilize quad-core processors?

    When purchasing a new PC, one chooses between dual-core vs. quad-core processors and some people claim that Firefox run in a mulch-threaded mode and treats each tab as a separate process and that it can fully utilize the advantage of a quad-core processor. Is that true?

    Firefox doesn't treat each tab as a separate process. While this may be a feature sometime in the future, I don't know of any plans to introduce it anytime soon. Obviously, buying a quad core processor is going to be significantly faster than a dual-core, and your browser is usually less resource intensive than many other programs. I wouldn't use it as your purchasing decision. Firefox will run equally well on a dual-core or a quad-core, but windows and other programs will run better with 4 cores.

  • ASA in MultiContext mode and AAA

    Hi
    have two firewalls (ASA5540, ver8.2); one configured in multi mode (called A) and second configured in single mode (called B).
    Have Cisco ACS setup to perform AAA for both firewalls. Both (A,B) can authenticate using ACS (tacacs+) no problem. Local cauthorization is setup as fallback if ACS does not work.
    For firewall A (single mode) the ACS can perform authentication, authorization and accounting. Have setup a readonly and full access groups in ACS to provide readonly (only limited show commands available) and full access (read write) to firewalls. This works very well.
    Firewall B (in multimode) can provide authentication and accounting OK (not alll accounting info but some login messages are available), but cannot provide authorization. Simple, that option is not available in ASDM (user setup/AAA) and only LOCAL is available for authorization.
    Entering from CLI "aaa authorization command TACACS-ACS LOCAL" on firewall B, the message back say that only tacacs+ and local methods are available.
    Entering "aaa authorization command tacacs+ local" on firewall B, the message back say that local method is not defined but tacacs+ argument does not bring any errors.
    Bellow are commands entered in firewall A and are working fine:
    aaa-server RADIUS-ACS protocol radius
    aaa-server RADIUS-ACS (inside) host 1.1.1.2
    key xxxxx
    aaa-server TACACS-ACS protocol tacacs+
    aaa-server TACACS-ACS (inside) host 1.1.1.2
    key xxxxx
    aaa authentication ssh console TACACS-ACS LOCAL
    aaa authentication http console TACACS-ACS LOCAL
    aaa authentication enable console RADIUS-ACS LOCAL
    aaa authorization command TACACS-ACS LOCAL
    aaa accounting ssh console RADIUS-ACS
    aaa accounting command TACACS-ACS
    aaa accounting telnet console RADIUS-ACS
    Questions: is multimode firewall behive different then singel mode when it comes to AAA?
    If it does, how to setup AAA on multicontext firewall? Thur system, admin or individual contexts?
    What command(s) are missing from bellow to make multicontext authorized by AAA?
    i am trying to avoid entering autheorization commands and levels on every context individually.
    Constructive feedback appreciated.
    Regards,

    Hello,
    I guess you will have to configure the AAA configuration on individual contexts.
    The following link throws some light on the same.
    http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00808d2b63.shtml
    It says:
    The system execution space does not support any  AAA commands, but you can configure its own enable password, as well as  usernames in the local database to provide individual logins.
    Hope this helps.
    Regards,
    Anisha
    P.S.: Please mark this thread as answered if you feel your query is resolved. Do rate helpful posts.

  • Trying to figure out whether I can use an ASA cluster in Transparent mode to facilitate VRF based network ??

    Hi Guys,
    I had to re-post this here because I did not get any comments earlier.. hopefully I'll get something here.. :)
    I'm investigating the ways that I can use 2 x ASA (5525x) to accommodate Multi-tenancy situation with overlapping addresses. Unfortunately in this particular scenario we have to stick with 5525x firewalls.
    The ASAs are going to be placed in north-south traffic path between 2 routers and these routers need to be configured with multiple VRFs to segregate the traffic for each tenant with overlapping IP subnets ( We are not looking at NAT as a workaround for the time being).
    As we know, this ASA model won't support VRFs so we can't use the ASA as a intermediary routing hop and therefore this is not an option.. and using security contexts per VRF seems not scale-able enough (correct me if I'm wrong). So my thinking is that, if we put the ASAs in to the transparent mode and just use the ASAs as a layer 2 interconnect (configured with different VLANs connecting VRFs served by top and bottom routers)  I should be able to go up to maximum of 50 VRFs (since 5525x only supports 200 VLANs).  
    I'm also planning to use the 2 ASAs in a cluster mode to aggregate the bandwidth of both ASAs for better throughput.
    So I need to clarify following with you guys.. 
    1) Can I actually do this or am I missing something.
    2) Are there any limitations that I might run in to with this setup
    3) Is there anyone out there who's doing the same thing or can you think of a better way to tackle this scenario (with same hardware and requirements)
    4) Instead of using clustering, can I use simple Active/Stanby pare and still configure transparent mode and use it that way ?
    Appreciate your input.
    Thanks
    Shamal 

    There is a limitation on how many context you can have, which depends on the license you have.  This is quite possible with ASA multi routed mode and even with multi transparent mode.  You can have overlapping ip in each context without the need of using nat as long as you have unique mac address for each sub interface.
    Thanks

  • Pbm to display a formula in multi Writer mode

    hello,
    I attach my analytic workspace in multi write mode and when i want to display a formula in a crosstab, i have the following message :
    on Jan 17 16:22:30 CET 2005 In oracle.dss.dataSource.QueryServer::_restartFromPersistence
    oracle.express.ExpressServerExceptionClasse d'erreurs : OLAPI
    Descriptions des erreurs du serveur :
    DPR : Unable to create server cursor, Générique à TxsOqDefinitionManagerSince9202::crtCurMgrs2
    OES : ORA-37035: You can only DEFINE SESSION objects in analytic workspace EISEVAL because it is attached in MULTI mode.
    , Générique à TxsRdbResultSet:absolute()
         at oracle.express.olapi.data.full.DefinitionManager$ExceptionTranslator.translateExpressException(DefinitionManager.java:571)
         at oracle.express.olapi.data.full.DefinitionManager$ExceptionTranslator.translateException(DefinitionManager.java:551)
         at oracle.express.olapi.data.full.DefinitionManager.translateException(DefinitionManager.java:513)
         at oracle.express.olapi.data.full.DefinitionManager.translateException(DefinitionManager.java:520)
         at oracle.express.olapi.data.full.DefinitionManagerSince9202.createCursorManagerInterfaces(DefinitionManagerSince9202.java:522)
         at oracle.express.olapi.data.full.DefinitionManagerSince9202.createOLAPICursorManagers(DefinitionManagerSince9202.java:891)
         at oracle.express.olapi.data.full.ExpressDataProvider.createCursorManagers(ExpressDataProvider.java:1671)
         at oracle.express.olapi.data.full.ExpressDataProvider.internalCreateCursorManager(ExpressDataProvider.java:770)
         at oracle.express.olapi.data.full.ExpressDataProvider.createCursorManager(ExpressDataProvider.java:708)
         at oracle.olapi.data.source.DataProvider.createCursorManager(DataProvider.java:330)
         at oracle.olapi.data.source.DataProvider.createCursorManager(DataProvider.java:273)
         at oracle.dss.dataSource.QueryCursorManager.createCursorManager(QueryCursorManager.java:164)
         at oracle.dss.dataSource.QueryEvaluator.setUpCursors(QueryEvaluator.java:3546)
         at oracle.dss.dataSource.QueryEvaluator._setUpCursorsForMainQuery(QueryEvaluator.java:2547)
         at oracle.dss.dataSource.QueryEvaluator.getCursorForCube(QueryEvaluator.java:2579)
         at oracle.dss.dataSource.QueryEvaluator.createCubeAndCursor(QueryEvaluator.java:940)
         at oracle.dss.dataSource.MainQueryEvaluator.createCubeAndCursor(MainQueryEvaluator.java:144)
         at oracle.dss.dataSource.QueryServer.createCubeAndCursor(QueryServer.java:3698)
         at oracle.dss.dataSource.QueryServer._restartFromPersistence(QueryServer.java:6297)
         at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
         at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java)
         at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
         at java.lang.reflect.Method.invoke(Method.java)
         at oracle.dss.util.Operation.execute(Operation.java:72)
         at oracle.dss.dataSource.QueryManagerServer.sendQueue(QueryManagerServer.java:1991)
         at oracle.dss.dataSource.common.OperationQueue.update(OperationQueue.java:207)
         at oracle.dss.dataSource.common.BaseOperationQueue.addOperation(BaseOperationQueue.java:176)
         at oracle.dss.dataSource.common.BaseOperationQueue.addOperation(BaseOperationQueue.java:146)
         at oracle.dss.dataSource.client.QueryClient._databaseSet(QueryClient.java:3888)
         at oracle.dss.dataSource.client.QueryClient._reestablishFromPersistence(QueryClient.java:349)
         at oracle.dss.dataSource.client.QueryClient.setXMLAsString(QueryClient.java:518)
         at oracle.dss.persistence.persistencemanager.client.DefaultStateHandler.loadXML(DefaultStateHandler.java:131)
         at oracle.dss.persistence.persistencemanager.client.DefaultStateHandler.recreatePersistableFromStateAgent(DefaultStateHandler.java:395)
         at oracle.dss.metadataManager.client.handlers.persistence.PersistenceMetadataHandler$MDStateHandler.recreatePersistableFromStateAgent(PersistenceMetadataHandler.java:491)
         at oracle.dss.persistence.persistencemanager.client.DefaultStateHandler.loadAggregates(DefaultStateHandler.java:257)
         at oracle.dss.persistence.persistencemanager.client.DefaultStateHandler.recreatePersistableFromStateAgent(DefaultStateHandler.java:401)
         at oracle.dss.metadataManager.client.handlers.persistence.PersistenceMetadataHandler$MDStateHandler.recreatePersistableFromStateAgent(PersistenceMetadataHandler.java:491)
         at oracle.dss.metadataManager.client.handlers.persistence.PersistenceMetadataHandler.getObjectInstance(PersistenceMetadataHandler.java:669)
         at oracle.dss.metadataManager.client.MetadataManager.handleStateAgent(MetadataManager.java:6336)
         at oracle.dss.metadataManager.client.MetadataManager.lookup(MetadataManager.java:5966)
         at oracle.dss.metadataManager.common.MDFolder.lookup(MDFolder.java:378)
         at oracle.dss.metadataManager.common.MDFolder.lookup(MDFolder.java:258)
         at oracle.dss.metadataManager.common.MDFolder.lookup(MDFolder.java:254)
         at oracle.dss.metadataManager.common.MDFolder.lookup(MDFolder.java:550)
    Is there a workaround ?
    Thanks

    hello,
    My formula come from an express Server database 6.3.4.
    I have made a simple test case: The Express Database contains only 2 formulas
    with 2 dimensions. I export it , create an aw in the CS_OLAP schema and import the eif file by AWM 10.1.0.3.0
    and enable to standard form.
    I ran the bicheckconfig and apparently no problem :
    <?xml version="1.0" encoding="UTF-8" ?>
    <BICheckConfig version="1.0.2.0">
    <Check key="JDEV_ORACLE_HOME" value="G:\oracle\product\10.1.0\Dev"/>
    <Check key="JAVA_HOME" value="G:\oracle\product\10.1.0\Dev\jdk\jre"/>
    <Check key="JDeveloper version" value="10.1.2.0.0.1811"/>
    <Check key="BI Beans release description" value="BI Beans 10.1.2 Production Release"/>
    <Check key="BI Beans component number" value="10.1.2.52.0"/>
    <Check key="BI Beans internal version" value="3.2.1.0.13"/>
    <Check key="host" value="dev2"/>
    <Check key="port" value="1521"/>
    <Check key="sid" value="orc10G"/>
    <Check key="user" value="cs_olap"/>
    <Check key="Connecting to the database" value="Successful"/>
    <Check key="JDBC driver version" value="10.1.0.3.0"/>
    <Check key="JDBC JAR file location" value="G:\oracle\product\10.1.0\Dev\jdbc\lib"/>
    <Check key="Database version" value="10.1.0.3.0"/>
    <Check key="OLAP Catalog version" value="10.1.0.3.0"/>
    <Check key="OLAP AW Engine version" value="10.1.0.2.0"/>
    <Check key="OLAP API Server version" value="10.1.0.3.0"/>
    <Check key="BI Beans Catalog version" value="3.2.1.0.13"/>
    <Check key="OLAP API JAR file version" value="&#34;10.1.0.3.0&#34;"/>
    <Check key="OLAP API JAR file location" value="G:\oracle\product\10.1.0\Dev\jdev\lib\ext"/>
    <Check key="OLAP API Metadata Load" value="Successful"/>
    <Check key="Number of metadata folders" value="4"/>
    <Check key="Number of metadata measures" value="26"/>
    <Check key="Number of metadata dimensions" value="7"/>
    <Check key="OLAP API Metadata">
    <![CDATA[==============================================================================
    Type Name (S=Schema, C=Cube, M=Measure, D=Dimension) Status
    ========= ======================================================= ============
    Folder... ROOT
    Measure.. Nombre de Jours par mois Successful
    S=CS_OLAP, C=NBJ_MOIS_CUBE4151, M=NBJ_MOIS
    Measure.. Formule Xdimension Successful
    S=CS_OLAP, C=FULE_XDIMENSION_CUBE4151, M=FULE_XDIMENSION
    Dimension Temps Successful
    S=CS_OLAP, D=EISEVAL_TEMPS
    Dimension Dimensions Successful
    S=CS_OLAP, D=EISEVAL_XDIMENSION
    Folder... Electronics - KPIs
    Measure.. Revenue Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD
    Measure.. Cost Successful
    S=CS_OLAP, C=SHAWSALES, M=COSTS
    Measure.. Quantity Successful
    S=CS_OLAP, C=SHAWSALES, M=QUANTITY_SOLD
    Dimension Time Successful
    S=CS_OLAP, D=SHAWT_TIME
    Dimension Promotion Successful
    S=CS_OLAP, D=SHAWPROMOTIONS
    Dimension Product Successful
    S=CS_OLAP, D=SHAWPRODUCTS
    Dimension Geography Successful
    S=CS_OLAP, D=SHAWGEOGRAPHIES
    Dimension Channel Successful
    S=CS_OLAP, D=SHAWCHANNELS
    Folder... Electronics - Trend Calculations
    Measure.. Revenue Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD
    Measure.. Revenue 12 Mo MV Avg Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD_12MMA
    Measure.. Revenue 6 Mo MV Avg Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD_6MMA
    Measure.. Revenue Fcst Best Fit Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD_FCAST_BF
    Measure.. Revenue Fcst Exponential Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD_FCAST_EXPO
    Measure.. Revenue Fcst Linear Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD_FCAST_LINEAR
    Measure.. Revenue Fcst Non-Linear Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD_FCAST_NLINEAR
    Measure.. Revenue Fcst Seasonal Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD_FCAST_SEASONAL
    Measure.. Revenue Fcst Trend Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD_FCAST_TREND
    Measure.. Revenue % Growth Prior Period Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD_PCT_CHANGE_PP
    Measure.. Revenue % Growth Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD_PCT_CHANGE_YRAGO
    Measure.. Cost Successful
    S=CS_OLAP, C=SHAWSALES, M=COSTS
    Measure.. Cost 12 Mo MV Avg Successful
    S=CS_OLAP, C=SHAWSALES, M=COSTS_12MMA
    Measure.. Cost 6 Mo MV Avg Successful
    S=CS_OLAP, C=SHAWSALES, M=COSTS_6MMA
    Measure.. Cost Fcst Best Fit Successful
    S=CS_OLAP, C=SHAWSALES, M=COSTS_FCAST_BF
    Measure.. Cost % Growth Prior Period Successful
    S=CS_OLAP, C=SHAWSALES, M=COSTS_PCT_CHANGE_PP
    Measure.. Cost % Growth Successful
    S=CS_OLAP, C=SHAWSALES, M=COSTS_PCT_CHANGE_YRAGO
    Measure.. Margin 12 Mo MV Avg Successful
    S=CS_OLAP, C=SHAWSALES, M=MARGIN_12MMA
    Measure.. Margin 6 Mo MV Avg Successful
    S=CS_OLAP, C=SHAWSALES, M=MARGIN_6MMA
    Measure.. Margin Fcst Best Fit Successful
    S=CS_OLAP, C=SHAWSALES, M=MARGIN_FCAST_BF
    Measure.. Margin % Growth Prior Period Successful
    S=CS_OLAP, C=SHAWSALES, M=MARGIN_PCT_CHANGE_PP
    Measure.. Margin % Growth Successful
    S=CS_OLAP, C=SHAWSALES, M=MARGIN_PCT_CHANGE_YRAGO
    Measure.. Margin % Successful
    S=CS_OLAP, C=SHAWSALES, M=MARGIN_PERCENT
    Measure.. Quantity Successful
    S=CS_OLAP, C=SHAWSALES, M=QUANTITY_SOLD
    Dimension Time Successful
    S=CS_OLAP, D=SHAWT_TIME
    Dimension Promotion Successful
    S=CS_OLAP, D=SHAWPROMOTIONS
    Dimension Product Successful
    S=CS_OLAP, D=SHAWPRODUCTS
    Dimension Geography Successful
    S=CS_OLAP, D=SHAWGEOGRAPHIES
    Dimension Channel Successful
    S=CS_OLAP, D=SHAWCHANNELS
    Folder... Electronics - Trend Calculations
    Measure.. Quantity Successful
    S=CS_OLAP, C=SHAWSALES, M=QUANTITY_SOLD
    Measure.. Margin % Successful
    S=CS_OLAP, C=SHAWSALES, M=MARGIN_PERCENT
    Measure.. Margin % Growth Successful
    S=CS_OLAP, C=SHAWSALES, M=MARGIN_PCT_CHANGE_YRAGO
    Measure.. Margin Fcst Best Fit Successful
    S=CS_OLAP, C=SHAWSALES, M=MARGIN_FCAST_BF
    Measure.. Margin 12 Mo MV Avg Successful
    S=CS_OLAP, C=SHAWSALES, M=MARGIN_12MMA
    Measure.. Cost % Growth Prior Period Successful
    S=CS_OLAP, C=SHAWSALES, M=COSTS_PCT_CHANGE_PP
    Measure.. Cost 6 Mo MV Avg Successful
    S=CS_OLAP, C=SHAWSALES, M=COSTS_6MMA
    Measure.. Cost 12 Mo MV Avg Successful
    S=CS_OLAP, C=SHAWSALES, M=COSTS_12MMA
    Measure.. Revenue % Growth Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD_PCT_CHANGE_YRAGO
    Measure.. Revenue 12 Mo MV Avg Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD_12MMA
    Measure.. Revenue 6 Mo MV Avg Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD_6MMA
    Measure.. Revenue Fcst Best Fit Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD_FCAST_BF
    Measure.. Revenue Fcst Exponential Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD_FCAST_EXPO
    Measure.. Revenue Fcst Linear Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD_FCAST_LINEAR
    Measure.. Revenue Fcst Non-Linear Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD_FCAST_NLINEAR
    Measure.. Revenue Fcst Seasonal Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD_FCAST_SEASONAL
    Measure.. Revenue Fcst Trend Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD_FCAST_TREND
    Measure.. Revenue % Growth Prior Period Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD_PCT_CHANGE_PP
    Measure.. Revenue Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD
    Measure.. Cost Successful
    S=CS_OLAP, C=SHAWSALES, M=COSTS
    Measure.. Cost Fcst Best Fit Successful
    S=CS_OLAP, C=SHAWSALES, M=COSTS_FCAST_BF
    Measure.. Cost % Growth Successful
    S=CS_OLAP, C=SHAWSALES, M=COSTS_PCT_CHANGE_YRAGO
    Measure.. Margin 6 Mo MV Avg Successful
    S=CS_OLAP, C=SHAWSALES, M=MARGIN_6MMA
    Measure.. Margin % Growth Prior Period Successful
    S=CS_OLAP, C=SHAWSALES, M=MARGIN_PCT_CHANGE_PP
    Dimension Time Successful
    S=CS_OLAP, D=SHAWT_TIME
    Dimension Promotion Successful
    S=CS_OLAP, D=SHAWPROMOTIONS
    Dimension Product Successful
    S=CS_OLAP, D=SHAWPRODUCTS
    Dimension Geography Successful
    S=CS_OLAP, D=SHAWGEOGRAPHIES
    Dimension Channel Successful
    S=CS_OLAP, D=SHAWCHANNELS
    Folder... Electronics - KPIs
    Measure.. Quantity Successful
    S=CS_OLAP, C=SHAWSALES, M=QUANTITY_SOLD
    Measure.. Revenue Successful
    S=CS_OLAP, C=SHAWSALES, M=AMOUNT_SOLD
    Measure.. Cost Successful
    S=CS_OLAP, C=SHAWSALES, M=COSTS
    Dimension Time Successful
    S=CS_OLAP, D=SHAWT_TIME
    Dimension Promotion Successful
    S=CS_OLAP, D=SHAWPROMOTIONS
    Dimension Product Successful
    S=CS_OLAP, D=SHAWPRODUCTS
    Dimension Geography Successful
    S=CS_OLAP, D=SHAWGEOGRAPHIES
    Dimension Channel Successful
    S=CS_OLAP, D=SHAWCHANNELS
    ]]>
    </Check>
    </BICheckConfig>
    The formula has the following description :
    DEFINE NBJ_MOIS FORMULA INTEGER <TEMPS>
    LD Nombre de Jours par mois
    EQ 1
    PROPERTY 'AW$CLASS' -
    'IMPLEMENTATION'
    PROPERTY 'AW$CREATEDBY' -
    'AW$XML'
    PROPERTY 'AW$LASTMODIFIED' -
    '24JAN05_17:05:22'
    PROPERTY 'AW$LOGICAL_NAME' -
    'NBJ_MOIS'
    PROPERTY 'AW$MEASUREDEF' NA
    PROPERTY 'AW$PARENT_NAME' -
    'NBJ_MOIS_CUBE4151'
    PROPERTY 'AW$ROLE' -
    'MEASUREDEF'
    PROPERTY 'AW$STATE' -
    'VALID_MEMBER'
    PROPERTY 'COLUMN_NAME' -
    'MEASURE_19'
    PROPERTY 'CURRSYMBOL' -
    '¿'
    PROPERTY 'DATA_TYPE' -
    'INTEGER'
    PROPERTY 'DECIMALDIGITS' 2
    PROPERTY 'DESCRIPTION' -
    'Nombre de Jours par mois'
    PROPERTY 'DISPLAYNAME' -
    'Nombre de Jours par mois'
    PROPERTY 'FORMATNEGCURR' -
    '($1)'
    PROPERTY 'FORMATNEGNUM' -
    '(¿1)'
    PROPERTY 'FORMATPOSCURR' -
    '$1'
    PROPERTY 'FORMATPOSNUM' -
    '¿1'
    PROPERTY 'ISCURRENCY' non
    PROPERTY 'IS_SOLVETARGET' oui
    PROPERTY 'LONGNAME' -
    'Nombre de Jours par mois'
    PROPERTY 'NAME' -
    'NBJ_MOIS'
    PROPERTY 'NUMFORMAT' -
    '0.00;¿1;(¿1);;,=;;'
    PROPERTY 'SHORTNAME' -
    'Nombre de Jours par mois'
    PROPERTY 'SHOWLEADZERO' oui
    PROPERTY 'USERDATA' oui
    PROPERTY 'USETHOUSANDSEP' non
    In the sample JAVA bibeans 10G "adhoc_tool"
    I insert just one line to reproduce the problem
    AnalyzerConnection.java
    protected void connect() {
    m_queryManager.setSession(m_session);
    m_queryManager.setMetadataManager(m_metadataManager);
    m_connected = true;
    // Save the connection details
    saveConnectionSettings();
    System.out.println(olapCon.executeCommand("aw attach EISEVAL multi;aw list")); <------------this line
    catch (Exception e) {
    // The _mm.attach method call can fail if the user - who is a valid
    // database user, is not a valid catalog user
    showConnectionError(e);
    and when i choose my fomula for a new presentation i have the following error :
    Mon Jan 24 19:21:43 CET 2005 In BuilderWizardAdapter::wizardFinished
    BIB-9509 Oracle OLAP n'a pas créé le curseur.
    oracle.express.ExpressServerExceptionClasse d'erreurs : OLAPI
    Descriptions des erreurs du serveur :
    DPR : Unable to create server cursor, Générique à TxsOqDefinitionManagerSince9202::crtCurMgrs2
    OES : ORA-37035: You can only DEFINE SESSION objects in analytic workspace EISEVAL because it is attached in MULTI mode.
    , Générique à TxsRdbResultSet:absolute()......
    If i attach in RO mode , it works.
    jean marc

  • PO - Inv Receipt and Srv Based IV Tick

    Dear All,
    In PO,how do i make the IR tick in Invoice tab to be in Display mode and Serv Based IR in Display mode for service Po's.
    Regards

    Hi
    You can make them as mandatory for the Sefvice items using filed selection , instead of making them as display using field selction for Document types
    In the Customizing of account assignement category being used for Sefvices you can specify IR is binding, so that it always is ticked in the PO.
    Similary in the Vendor master you can flag the Service ased IV flag, to get copied in the PO.
    Thanks & Regards
    Kishore

  • BVI doesn't show up in multi context ASA

    I have an ASA 5585 in transparent mode, multi-context. It seems that the option to configure a BVI in one of the traffic contexts isn't there. In other words, while I see the option to configure a bridge group interface in the admin context, no such option comes up in the traffic context.
    ciscoasa/admin(config)# interface ?
    configure mode commands/options:
      BVI         Bridge-Group Virtual Interface
      Management  Prefix of interface Management0/0
    ciscoasa/admin(config)#
    ciscoasa/admin(config)# changeto context dmz
    ciscoasa/dmz(config)#
    ciscoasa/dmz(config)# interface ?
    configure mode commands/options:
      Port-channel  Prefix of interface Port-channel30.411, 30.412, 30.413, 30.414
    ciscoasa/dmz(config)#
    I thought that maybe I need to first allocate BVI interface(s) in the system context (in order to seem them in the traffic context) but that doesn't seem to be an option either.
    ciscoasa/dmz(config)# ch system
    ciscoasa(config)# interface ?
    configure mode commands/options:
      GigabitEthernet     GigabitEthernet IEEE 802.3z
      Management          Management interface
      Port-channel        Ethernet Channel of interfaces
      Redundant           Redundant Interface
      TenGigabitEthernet  Ten GigabitEthernet
      <cr>
    ciscoasa(config)#
    Has anyone seen this or know what the issue is? Thanks.

    I think I figured it out. It seems that when you create a context, it is created in routed mode by default. So you have to explicitly go in and change it to transparent mode. Then the BVI interface shows up of course.

  • ASA X-series firewalls difference & multi context features

    Does anyone have a quick guide to show the feature differences between the X and regular ASA series firewalls?
    And does this still hold true WRT multi-context ASA in the X-series?
    No multi-context.....
    - If you need to provide VPN services such as remote access or site-to-site VPN tunnels.
    - If you need to use dynamic routing protocols. With multiple context mode, you can use only static routes.
    - If you need to use QoS.
    - If you need to support multicast routing.
    - If you need to provide Threat Detection.
    tia,
    Will

    A few changes in the new ASA version 9.0 (supported on both ASA and ASA-X series):
    http://www.cisco.com/en/US/docs/security/asa/asa90/release/notes/asarn90.html#wp586890
    In multiple context mode, it does support the following:
    - Site to site VPN tunnels only.
    - Dynamic routing protocols: EIGRP and OSPFv2 only.
    - QoS is not supported.
    - Multicast routing is not supported.
    - Thread Detection is not supported
    Here is the unsupported feature on multiple context as off Version 9.0:
    http://www.cisco.com/en/US/docs/security/asa/asa90/configuration/guide/ha_contexts.html#wp1382237

  • Multiple context mode and Active Active

    Hi Everyone,
    ASA in multiple context  mode works as active active mode.
    ASA has 2 contexts admin and  x.
    We have 2  physical ASA say ASA1 and ASA2 .
    Under system context we have hostname ASA
    When i ssh to ASA1 it brings the ASA/admin mode.
    sh failover shows
    sh failover shows
    This host:    Primary
    This host:    Primary
    When i try to login to ASA 2 it brings me to ASA/x prompt.
    sh failover shows
      This context: Active
    Peer context: Standby Ready
    Need to  know is there any way that i can login to other physical ASA?
    i hope my question makes sense.
    Message was edited by: mahesh parmar

    Hi Mahesh,
    To it seems that you are logging to different contexts in these 2 cases.
    Normally an admin always logs to the "admin" context IP address owned either by the primary IP address for the Active unit or the secondary IP address for the Standby unit.
    So what I would suggest you do first is that you go to the context "admin" and issue the command "show run interface"
    Then go to the context "x" and issue the command "show run interface"
    Now check the IP addresses on the interfaces.
    Especially the interface on the "admin" context should contain an IP address for both of the ASA units. Check the interface IP address which originally lead you to the "admin" context.
    For example
    ip address 10.10.10.1 255.255.255.0 standby 10.10.10.2
    If the above were true you would connecto the IP address 10.10.10.1 when you wanted to connect to the Active unit and use the IP address 10.10.10.2 when you wanted to connect to the current Standby unit
    - Jouni

  • Will up coming 9.0 release support multicast in multi-context mode?

    I understand that in 8.4 multicast is not support in multi-context mode.  How about the up-and-coming release of 9.0?

    No, multicast is still not supported on multi context mode in the upcoming 9.0 release.
    However, IPSec LAN-to-LAN VPN is supported on multi context mode.

  • Wwan 3G/4G 4G LTE HWIC VPN (with dynamic ip)Configuration assistance to multi context asa

    Hello All
    I have a customer that has several sites all over the world and they want to use 3G and possibly 4G (where available) as  a backup vpn solution.
    I need some assistance/ guidance in configuring the cellular radio and configuring the vpn (dynamic ip)to work over the wwan.
    Countries involved are France, Spain, Australia, Thailand and Malaysia.
    I understand that I will need the APN credentials from the service provider. Is this normally the same for 3g and 4g?
    Do I get chat scripts from them too?
    My vpn gateway in the HQ is a Cisco multi-context asa so I can't configure remote access as its not supported yet. Can I possibly use the 1921 router(4lte hwic installed) at the sites as a  hardware client?
    I have seen the following urls. One has the 3g router as a "remote access" vpn but I guess this won't work in my scenario.
    The other is between ios router and asa which I think will work. I don't need nat on the 3g/4g router as all traffic will be using the vpn.
    http://www.networking-forum.com/blog/?p=708  . Will I need this for all the sub-interfaces I configure on the router
    interface Vlan1
    description LAN
    ip address 10.0.0.14 255.255.255.240
    no ip redirects
    no ip proxy-arp
    ip tcp adjust-mss 1452
    crypto ipsec client ezvpn ASA inside <--is this needed per interface????
    Remote access reference in config:
    group-policy 3GPolicy attributes
    vpn-tunnel-protocol IPSec
    password-storage enable
    nem enable
    tunnel-group 3GRAGroup type remote-access <---Remote access config
    tunnel-group 3GRAGroup general-attributes
    authorization-server-group LOCAL
    default-group-policy 3GPolicy
    tunnel-group 3GRAGroup ipsec-attributes
    pre-shared-key **Same key as the ASA profile on the 881**
    http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/112075-dynamic-ipsec-asa-router-ccp.html 
    Anyone got a helpful configuration and guide?
    Thanks
    Feisal

  • What does multi, one, premium and limited mean in the context of Indesign servers please?

    what does multi, one, premium and limited mean in the context of Indesign servers please

    You will likely get better program help in a program forum InDesign
    The Cloud forum is not about using individual programs
    The Cloud forum is about the Cloud as a delivery & install process
    If you will start at the Forums Index https://forums.adobe.com/welcome
    You will be able to select a forum for the specific Adobe product(s) you use
    Click the "down arrow" symbol on the right (where it says All communities) to open the drop down list and scroll

  • Add multi context asa to mars

    when I try to add a  multi context asa to MARS, I get error
    Error occured during PIX multicontext discovery. More detailed info may be available under View Error button of individual context devices.
    If you can not find detailed error info, please make sure 'hostname.domain-name' for each context device is unique"
    So this mean I should change host name of each context in the ASA differrent to add to MARS ?
    thank you,
    Duyen

    Hi duyendaica,
    I try to answer, maybe you just need to add domain-name configuration in every context, not to change the hostname.
    Thanks

  • Multi Context IPSec VPN limitations

    Hello,
    We are looking to deploy mult-context IPSec lan to lan VPNs on ASA 9.x  now that the functionality is available and I'm trying to understand if there are limitations to the number of tunnels that can be deployed per context? The below link may seem to indicate that there is a limit of 5 "IPSec sessions" per context but I can't see any reference to such limitations anywhere else.
    http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/contexts.html#wp1147166
    Does anybody know if there is a hard limit of number of IPSec connections per context or is it down to the general capabilities of the hardware (i.e. we're looking initially to deploy on 5520 so we'd get a throughput capability of 225Mb based on the datasheet -obviously depending on crypto parameters)?
    Thanks

    Hey found the updated document
    http://www.cisco.com/en/US/docs/security/asa/command-reference/l1.html#wp1697181
    Ok, this is the real document:
    By default, all security contexts have unlimited access to the resources of the ASA, except where maximum limits per context are enforced; the only exception is VPN resources, which are disabled by default. If you find that one or more contexts use too many resources, and they cause other contexts to be denied connections, for example, then you can configure resource management to limit the use of resources per context. For VPN resources, you must configure resource management to allow any VPN tunnels.
    vpn burst other
    Concurrent
    N/A
    The Other VPN session amount for your model minus the sum of the sessions assigned to all contexts for vpn other.
    The number of site-to-site VPN sessions allowed beyond the amount assigned to a context withvpn other. For example, if your model supports 5000 sessions, and you assign 4000 sessions across all contexts with vpn other, then the remaining 1000 sessions are available for vpn burst other. Unlike vpn other, which guarantees the sessions to the context, vpn burst othercan be oversubscribed; the burst pool is available to all contexts on a first-come, first-served basis.
    vpn other
    Concurrent
    N/A
    See the "Supported Feature Licenses Per Model" section in the CLI configuration guide for the Other VPN sessions available for your model.
    Site-to-site VPN sessions. You cannot oversubscribe this resource; all context assignments combined cannot exceed the model limit. The sessions you assign for this resource are guaranteed to the context.
    Value our effort and rate the assistance!

  • Multi Seat Mode - Multiple X Servers on 1 Machine

    I need to configure a SunBlade 2000 configured with an XVR1000 graphics board to be used by 2 people simultaneously with the own keyb & mouse.
    To summarize :
    1 Sun Blade 2000
    1 Xvr1000
    First Port connected to one monitor /dev/fbs/gfb0a
    Second Port Connected to a second monitor /dev/fbs/gfb0b
    2 Keyb & 2 mouse connected to the 4 USB ports
    The 2 monitors must be handled by to istances of X server (2 dtlogin prompt) so the 2 people can work
    indipendently.
    I tried the following procedure with NO success.
    Does anybody can help me ?
    Thanks in advance
    Luigi Paganini
    =============================================================================
    In recent versions of Solaris, the Xsun keyboard & mouse DDX modules
    have been extended to support multiple keyboards and mice on Solaris.
    The Xorg server on Solaris x86 has similarly been extended to support
    multiple mice, but not yet multiple keyboards.
    Unfortunately, this is not a very well documented feature, though it is
    supported - but you must pay close attention to the configuration
    instructions and Limitations described below.
    There are currently two choices for configuring X on a machine with
    multiple input devices:
    * One X server with the extra devices available via the X Input
    extension (commonly used for accessibility helper programs, or for x86
    laptop users)
    * Multiple X servers, each with its own set of input & output
    devices ("multi-seat" mode)
    The two methods can be mixed on a single machine - when configuring you
    simply need to determine which X server each device is going to be
    associated with.
    Requirements
    * Solaris 9 FCS or later (SPARC or x86)
    * USB-capable machine
    * For Solaris 9, USB patch 115338-01 (sparc)/115339-01 (x86) or
    newer. For Solaris 10, s10_17 or newer.
    Limitations
    Due to the nature of USB and Sun's implementation, USB devices may get
    different numbers when initialized or hot-plugged in a different order.
    A partial solution is to use the full path name under the /devices
    hierarchy - this is tied to the physical port a device is plugged into,
    so the order is no longer a problem, but devices must always be plugged
    into the same port this way.
    Xsun Configuration
    The following sections may be added to either
    /etc/openwin/server/etc/OWconfig or /usr/openwin/server/etc/OWconfig.
    Xsun reads both when starting up and merges their contents.
    * 1. Run ls -l /dev/usb/hid* to see what the existing device names are.
    * 2. Attach the additional input devices to the machine
    * 3. ls -l /dev/usb/hid* to see what the newly attached device names
    are. Note at the end of each symlink line it will list whether it is a
    keyboard or a mouse.
    * 4. Add lines of the following form to OWconfig, one for each
    device, and each with a unique name beginning with "IMOUSE" or "IKBD":
    # sun Keyboard module
    class="XINPUT" name="IKBD2"
    dev="/dev/usb/hid2" strmod="usbkbm"
    ddxHandler="ddxSUNWkbd.so.1"
    ddxInitFunc="ddxSUNWkbdProc";
    # sun Mouse module
    class="XINPUT" name="IMOUSE2"
    dev="/dev/usb/hid3" strmod="usbms"
    ddxHandler="ddxSUNWmouse.so.1"
    ddxInitFunc="ddxSUNWmouseProc";
    * 5. To configure multiseat mode, add a section to OWconfig to
    associate each keyboard, mouse, and frame buffer with a specific display
    (in this case ":1"):
    class="XDISPLAY" name="1"
    coreKeyboard="IKBD2" corePointer="IMOUSE2"
    dev0="/dev/fb1";
    * 6. Test your configuration. For multiseat mode, run an Xserver on
    the display you listed (xinit :1 or add a line for :1 to
    /etc/dt/config/Xservers ). For use with the X input extension, restart X
    and run xinputdev -l (source code here) to list the devices the server
    sees. You can also run xinputdev -k & xinputdev -m to switch your core
    keyboard and mouse to the specified devices.

    The report gets called via the rwservlet (hope that answers your question correctly)
    The application is in OAS.
    The separation i require is both in the database and the reports themselves.
    For example let's say i have devapp and testapp - both the exact same app. But they both need to access reports under the same key, but the report needs to get its info from its respective dev and test databases. The key is hardcoded so can't change.
    If i understand correctly (a big "if"), the cgicmd.dat file tells wich report to grab and which database to connect to based on the key. Is there a way to have separate key map files (cgicmd.dat) called by separate applications? So that devapp will get Report1 using devdatabase, where testapp wil get Report1 using testdatabase?
    It may not be possible to do this kind of server consolidation, I just need to know one way or another for sure - and if it is possible, how to proceed.

Maybe you are looking for

  • Crystal Report not visible when using IE9

    Hello, I have a report that has been displaying fine in IE8 for me, but when I upgraded to IE9, the report stopped displaying.  This problem seems to only occur if the report has more than 5 columns of data in it.   If it has 5 or less columns, every

  • "A Bad Filename or volume name encountered" ?!!!

    I searched but I didnt find an answer for this problem. I get the message "Bad Filename or volume name encountered" when I try to play a video file with Quicktime. When I try to add it to my playlist on iTunes it doesnt add it. All of this happened a

  • Error in Database monitoring in Solution Manager Diagnostic

    Hello All, I'm facing issue in configuring Database monitoring for Java system (EP/PI) from Solution manager . It could be configured from sol man diagnostic>Diagnostic System>Managed system>Database monitoring, iei'm unable to have java system in DB

  • Po check error (Jurisdiction code could not be determined)

    Hello everybody. I am in SRM 5.0 and in Brazil we use jurisdiction code too, all notes for jurisdiction codes are applied and the calculation is occurring in R/3 in the moment of Po creations, the problem is that when the po are created and I need to

  • WLAN Identifier

    I have this issue where i have two wism's with the same amount of WLAN's and the same names: 15 to be exact.  The problem i'm having is that the WLAN identifier is different between the two wism's even though there are the same amount and the same na