<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sure thing, it's actually in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017571#M45282</link>
    <description>&lt;P&gt;Sure thing, it's actually quite straight forward:&lt;/P&gt;
&lt;P&gt;- Configure Radius servers on your central manager/waas&lt;/P&gt;
&lt;P&gt;- Configure it to use Radius as the first Authentication method&lt;/P&gt;
&lt;P&gt;- Configure your radius so it accepts the request and gives back the attribute&amp;nbsp;Radius:Service-Type =&amp;nbsp;Administrative&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;No local users needed on central manager or waas itself.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Nov 2015 15:40:17 GMT</pubDate>
    <dc:creator>Philipp Kreidl</dc:creator>
    <dc:date>2015-11-12T15:40:17Z</dc:date>
    <item>
      <title>Radius authorization for WAAS CM GUI</title>
      <link>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017561#M45272</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We would like to enable radius authorization to the WAAS Central Manager GUI. We are having some problems doing this. Also this is only documented for TACACS and not for Radius. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We've seen the waas_rbac_groups attribute that can be delivered via Tacacs, can this attribute also travel in the radius attributes? We've already tried: shell:waas_rbac_groups on a Cisco-AV-Pair but that doesn't do it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There should be a way; knowning that the TACACS is very rare these days.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help us &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/wink.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;&lt;P&gt;﻿&lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2012 12:50:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017561#M45272</guid>
      <dc:creator>etamminga</dc:creator>
      <dc:date>2012-10-29T12:50:41Z</dc:date>
    </item>
    <item>
      <title>Hi Guys, any update on this??</title>
      <link>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017562#M45273</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any update on this????&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2015 05:55:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017562#M45273</guid>
      <dc:creator>Sakun Sharma</dc:creator>
      <dc:date>2015-07-15T05:55:10Z</dc:date>
    </item>
    <item>
      <title>Same problem as well and can</title>
      <link>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017563#M45274</link>
      <description>&lt;P&gt;Same problem as well and can't get the individual WAAS to authenticate with Radius. I was able to disable "allow only admins to ssh" to this device which got me the login prompt but will not elevate to enable. What the heck are the WAAS Radius attributes??? Can't find any combo that works!!&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2015 14:59:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017563#M45274</guid>
      <dc:creator>jwornstaff</dc:creator>
      <dc:date>2015-09-16T14:59:27Z</dc:date>
    </item>
    <item>
      <title>Hi...      I received a</title>
      <link>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017564#M45275</link>
      <description>&lt;P&gt;Hi...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I received a message from Cisco TAC about this case and he sads that there's no possible to use radius to authenticate in WAAS.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2015 17:02:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017564#M45275</guid>
      <dc:creator>boticariocisco</dc:creator>
      <dc:date>2015-09-16T17:02:26Z</dc:date>
    </item>
    <item>
      <title>They are mistaken....I can</title>
      <link>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017565#M45276</link>
      <description>&lt;P&gt;They are mistaken....&lt;/P&gt;&lt;P&gt;I can get RADIUS authentication working with my WAAS devices using a window 2008 NPS. The thing you have to do is on the WAAS appliance issue the sshd allow-non-admin-users command. Then you can authenticate using Radius Login and password at the user prompt level as normal user. The problem is passing the privilege level 15 or what every it is on WAAS with the right Radius Attributes from the NPS server. The standard Cisco AV-PAIR "shell:priv-lvl=15" does not work, so you can not automatically login with enable prompt. However you can force the authentication enable to local and then use a local enable password and gain access.....if that makes sense.&lt;/P&gt;&lt;P&gt;If radius is not possible then why the heck do they have all the configuration built into the WAAS central manager GUI and doc that somewhat explains how to configure but they leave out the radius server side settings.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2015 18:22:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017565#M45276</guid>
      <dc:creator>jwornstaff</dc:creator>
      <dc:date>2015-09-16T18:22:57Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017566#M45277</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Try the attribute "Radius:Service-Type=Administrative" instead of the Cisco AV-PAIR.&lt;/P&gt;
&lt;P&gt;We use ISE 1.4 as Radius Server and with this attribute also CLI privilege 15 access works well&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2015 15:13:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017566#M45277</guid>
      <dc:creator>Marco Biffi</dc:creator>
      <dc:date>2015-11-06T15:13:48Z</dc:date>
    </item>
    <item>
      <title>Yes that will do the trick,</title>
      <link>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017567#M45278</link>
      <description>&lt;P&gt;Yes that will do the trick, we also use Radius with Cisco ISE on more than 60 WAAS devices and it just works fine.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2015 07:59:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017567#M45278</guid>
      <dc:creator>Philipp Kreidl</dc:creator>
      <dc:date>2015-11-12T07:59:03Z</dc:date>
    </item>
    <item>
      <title>Thanks for the info from both</title>
      <link>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017568#M45279</link>
      <description>&lt;P&gt;Thanks for the info from both of you. Do you use radius on both the physical WAAS devices i.e. for CLI and on the WAAS Central manager? I had read there was similar issues with the central manager using radius.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2015 11:48:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017568#M45279</guid>
      <dc:creator>jwornstaff</dc:creator>
      <dc:date>2015-11-12T11:48:53Z</dc:date>
    </item>
    <item>
      <title>Yes, Radius for both, they</title>
      <link>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017569#M45280</link>
      <description>&lt;P&gt;Yes, Radius for both, they use the same Radius attributes - if you need I can tell you the exact settings on CM and WAAS devices. But it definetly works.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2015 12:30:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017569#M45280</guid>
      <dc:creator>Philipp Kreidl</dc:creator>
      <dc:date>2015-11-12T12:30:42Z</dc:date>
    </item>
    <item>
      <title>That would be great...if not</title>
      <link>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017570#M45281</link>
      <description>&lt;P&gt;That would be great...if not to much trouble. It's always good to have a working example! Plus I'm new to the WAAS, as just inherited a network that has about 4 and couple virtuals.&lt;/P&gt;
&lt;P&gt;I'm also using Windows NPS as my radius server currently.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2015 15:14:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017570#M45281</guid>
      <dc:creator>jwornstaff</dc:creator>
      <dc:date>2015-11-12T15:14:38Z</dc:date>
    </item>
    <item>
      <title>Sure thing, it's actually</title>
      <link>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017571#M45282</link>
      <description>&lt;P&gt;Sure thing, it's actually quite straight forward:&lt;/P&gt;
&lt;P&gt;- Configure Radius servers on your central manager/waas&lt;/P&gt;
&lt;P&gt;- Configure it to use Radius as the first Authentication method&lt;/P&gt;
&lt;P&gt;- Configure your radius so it accepts the request and gives back the attribute&amp;nbsp;Radius:Service-Type =&amp;nbsp;Administrative&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;No local users needed on central manager or waas itself.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2015 15:40:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017571#M45282</guid>
      <dc:creator>Philipp Kreidl</dc:creator>
      <dc:date>2015-11-12T15:40:17Z</dc:date>
    </item>
    <item>
      <title>Hi Philipp,</title>
      <link>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017572#M45283</link>
      <description>&lt;P&gt;Hi Philipp,&lt;/P&gt;
&lt;P&gt;I have exactly the same config but after login in CM i receive this message:&lt;/P&gt;
&lt;P&gt;"Your account does not have privileges to access any of the Central Manager pages. Please check with your administrator about provisioned roles and domains."&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2015 20:04:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017572#M45283</guid>
      <dc:creator>boticariocisco</dc:creator>
      <dc:date>2015-11-12T20:04:20Z</dc:date>
    </item>
    <item>
      <title>Do you have the user</title>
      <link>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017573#M45284</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Edit: just saw that you're not the guy who responded first, so which Radius server are you using? Can you confirm that Radius will send&amp;nbsp;"access accept" and "service-type = 6"?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2015 22:24:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017573#M45284</guid>
      <dc:creator>Philipp Kreidl</dc:creator>
      <dc:date>2015-11-12T22:24:05Z</dc:date>
    </item>
    <item>
      <title>Hi Guys,</title>
      <link>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017574#M45285</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I opened a TAC case with Cicso and below was the final results:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Lucida Sans Unicode',sans-serif; color: #1f497d;"&gt;Problem Description&lt;/SPAN&gt;&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Lucida Sans Unicode',sans-serif; color: #1f497d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Lucida Sans Unicode',sans-serif; color: #1f497d;"&gt;Issue with Radius Authorization for WAAS CM GUI. Radius server is using ISE.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Lucida Sans Unicode',sans-serif; color: #1f497d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Lucida Sans Unicode',sans-serif; color: #1f497d;"&gt;Authentication to WAAS CM GUI is successful, but with error message "Your account does not have privileges to access any of the Central Manager pages. Please check with your administrator about provisioned roles and domains."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Lucida Sans Unicode',sans-serif; color: #1f497d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Lucida Sans Unicode',sans-serif; color: #1f497d;"&gt;On ISE authorization profile the attribute setting is configured:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Lucida Sans Unicode',sans-serif; color: #1f497d;"&gt;Radius:Service-Type = Administrative&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Lucida Sans Unicode',sans-serif; color: #1f497d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Lucida Sans Unicode',sans-serif; color: #1f497d;"&gt;With this attribute setting, authentication and authorization to WAAS CM using CLI are successful. But using GUI, only authentication is successful .&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Lucida Sans Unicode',sans-serif; color: #1f497d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Lucida Sans Unicode',sans-serif; color: #1f497d;"&gt;Action Taken&lt;/SPAN&gt;&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Lucida Sans Unicode',sans-serif; color: #1f497d;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Lucida Sans Unicode',sans-serif; color: #1f497d;"&gt;WAAS will use local authorization and will not consider what the Radius is returning. This is expected behaviour and dynamic assignment to different roles via Radius is not supported as this stage.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Lucida Sans Unicode',sans-serif; color: #1f497d;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Lucida Sans Unicode',sans-serif; color: #1f497d;"&gt;What we have did as a workaorund, we have to create same user in WAAS local database as we have in AD (same username, password doesn't matter) then we assign that local user to admin group in WAAS authorization. So now when we login to WAAS, it passess username and password to ISE to authenticate and ISE will check it with AD and send ACCEPT to WAAS, then WAAS consider that username as local user and authorize using local database.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Lucida Sans Unicode',sans-serif; color: #1f497d;"&gt;If you try this, and try to create a user in local database same as AD, it will give you an error while creating user, that is due to Cache&amp;nbsp; - When we try AD account, it cache the username and doesn't allow to create same username in local database - workaround -&amp;gt; the WAAS caches the remote users for 60 days by default and that what prevented you from adding these users. We had changed the setting to the minimum value (1 day). Waieted for 25 hours then tried to add your usernames to CM and verified that it was working.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10.0pt; font-family: 'Lucida Sans Unicode',sans-serif; color: #1f497d;"&gt;So end result, Authentication from ISE, Authorization local, but atleast you can use AD credentials.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2015 23:18:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017574#M45285</guid>
      <dc:creator>Sakun Sharma</dc:creator>
      <dc:date>2015-11-12T23:18:39Z</dc:date>
    </item>
    <item>
      <title>I'm using ise radius.</title>
      <link>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017575#M45286</link>
      <description>&lt;P&gt;I'm using ise radius.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2015 10:00:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/radius-authorization-for-waas-cm-gui/m-p/2017575#M45286</guid>
      <dc:creator>boticariocisco</dc:creator>
      <dc:date>2015-11-13T10:00:33Z</dc:date>
    </item>
  </channel>
</rss>

