<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Custom attribute in ACS4.2 patch 17 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/custom-attribute-in-acs4-2-patch-17/m-p/2218730#M105689</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Petr,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You're running into a defect. &lt;/P&gt;&lt;P&gt; &lt;A href="https://www.cisco.com/cisco/psn/bssprt/bss?searchType=bstbugidsearch&amp;amp;page=bstBugDetail&amp;amp;BugID=CSCth75577" target="_blank"&gt;CSCth75577&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACS incorrectly sends optional custom TACACS+ attributes &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Symptom:&lt;/B&gt;&lt;/P&gt;&lt;P&gt;TACACS+ Authorization from IOS fails if customer attributes (even optional attributes) are configured on the ACS user group.&amp;nbsp; The login will work but any attributes passed will not be honored.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Conditions:&lt;/B&gt;&lt;/P&gt;&lt;P&gt;ACS 4.2.0.124 patch 16&lt;/P&gt;&lt;P&gt;ACS 4.2.1.15 patch 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Workaround:&lt;/B&gt;&lt;/P&gt;&lt;P&gt;Downgrade to a previous ACS patch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This has been fixed in &lt;/P&gt;&lt;P&gt;ACS 4.2.1.15 patch 3 or later.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Upgrade the ACS to 4.2.1.15 and apply the latest patch 10.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 30 May 2013 11:13:14 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2013-05-30T11:13:14Z</dc:date>
    <item>
      <title>Custom attribute in ACS4.2 patch 17</title>
      <link>https://community.cisco.com/t5/network-access-control/custom-attribute-in-acs4-2-patch-17/m-p/2218729#M105688</link>
      <description>&lt;P&gt;I have optional custom attribute in my ACS group to be able to enter config mode on ACE: &lt;SPAN style="font-size: 10pt;"&gt;shell:Admin*Admin default-domain&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Privilege level 15 is also part of exec&amp;nbsp; configuration.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/9/2/7/140729-author-custom-setup.JPG" alt="author-custom-setup.JPG" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Recently I applied patch 17 on ACS 4.2(0) Build 124.&lt;STRONG&gt; Since then I can not login with privilege level 15 into IOS routers/switches&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;It looks like IOS box considers this custom attribute as a mandatory now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;IOS debug (Cat6500,&lt;SPAN style="font-size: 10pt;"&gt;12.2(33)SXJ4 &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;May 27 13:23:56.819: TPLUS: Authorization request created for 61929(pehruby)&lt;/P&gt;&lt;P&gt;May 27 13:23:56.819: TPLUS: using previously set server 10.105.24.44 from group tacacs+&lt;/P&gt;&lt;P&gt;May 27 13:23:56.819: TPLUS(0000F1E9)/0/NB_WAIT/550052A4: Started 5 sec timeout&lt;/P&gt;&lt;P&gt;May 27 13:23:56.819: TPLUS(0000F1E9)/0/NB_WAIT: socket event 2&lt;/P&gt;&lt;P&gt;May 27 13:23:56.819: TPLUS(0000F1E9)/0/NB_WAIT: wrote entire 62 bytes request&lt;/P&gt;&lt;P&gt;May 27 13:23:56.819: TPLUS(0000F1E9)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;May 27 13:23:56.823: TPLUS(0000F1E9)/0/READ: Would block while reading&lt;/P&gt;&lt;P&gt;May 27 13:23:56.823: TPLUS(0000F1E9)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;May 27 13:23:56.823: TPLUS(0000F1E9)/0/READ: read entire 12 header bytes (expect 51 bytes data)&lt;/P&gt;&lt;P&gt;May 27 13:23:56.823: TPLUS(0000F1E9)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;May 27 13:23:56.823: TPLUS(0000F1E9)/0/READ: read entire 63 bytes response&lt;/P&gt;&lt;P&gt;May 27 13:23:56.823: TPLUS(0000F1E9)/0/550052A4: Processing the reply packet&lt;/P&gt;&lt;P&gt;May 27 13:23:56.823: TPLUS: Processed AV priv-lvl=15&lt;/P&gt;&lt;P&gt;May 27 13:23:56.823: TPLUS: Failed to decode unknown AV shell - FAIL&lt;/P&gt;&lt;P&gt;May 27 13:23:56.823: TPLUS(0000F1E9)/0/REQ_WAIT/550052A4: timed out&lt;/P&gt;&lt;P&gt;May 27 13:23:56.823: TPLUS: Protocol set to None .....Skipping&lt;/P&gt;&lt;P&gt;May 27 13:23:56.823: TPLUS: Sending AV service=shell&lt;/P&gt;&lt;P&gt;May 27 13:23:56.823: TPLUS: Sending AV cmd*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS.log from ACS (different time, the same attempt):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS 05/27/2013 11:59:39 I 0043 5088 0x15 &amp;lt;&amp;lt;&amp;lt; PACKET TO CLIENT:10.106.11.114 TYPE:AUTHOR/PASS_ADD, SEQ 2, FLAGS 1&lt;/P&gt;&lt;P&gt;TCS 05/27/2013 11:59:39 I 0043 5088 0x15 SESSIONID -998342923 (0xc47e7ef5), DATALEN 51 (0x33)&lt;/P&gt;&lt;P&gt;TCS 05/27/2013 11:59:39 I 0043 5088 0x15 type=AUTHOR/REPLY status=1 (AUTHOR/PASS_ADD) &lt;/P&gt;&lt;P&gt;TCS 05/27/2013 11:59:39 I 0043 5088 0x15 msg_len=0, data_len=0 arg_cnt=2&lt;/P&gt;&lt;P&gt;TCS 05/27/2013 11:59:39 I 0043 5088 0x15 arg[0] size=11 =priv-lvl=15&lt;/P&gt;&lt;P&gt;TCS 05/27/2013 11:59:39 I 0043 5088 0x15 arg[1] size=32 =shell:Admin*Admin default-domain&lt;/P&gt;&lt;P&gt;TCS 05/27/2013 11:59:39 I 0043 5088 0x15 End &amp;gt;&amp;gt;&amp;gt;&lt;/P&gt;&lt;P&gt;------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IOS debug (C1841, 12.3(14)T7 &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May 30 12:21:58.248: AAA/BIND(00000A52): Bind i/f&lt;/P&gt;&lt;P&gt;May 30 12:21:58.272: AAA/AUTHOR (0xA52): Pick method list 'acs'&lt;/P&gt;&lt;P&gt;May 30 12:21:58.272: TPLUS: Queuing AAA Authorization request 2642 for processing&lt;/P&gt;&lt;P&gt;May 30 12:21:58.272: TPLUS: processing authorization request id 2642&lt;/P&gt;&lt;P&gt;May 30 12:21:58.272: TPLUS: Protocol set to None .....Skipping&lt;/P&gt;&lt;P&gt;May 30 12:21:58.276: TPLUS: Sending AV service=shell&lt;/P&gt;&lt;P&gt;May 30 12:21:58.276: TPLUS: Sending AV cmd*&lt;/P&gt;&lt;P&gt;May 30 12:21:58.276: TPLUS: Authorization request created for 2642(ph)&lt;/P&gt;&lt;P&gt;May 30 12:21:58.276: TPLUS: using previously set server 10.105.24.44 from group tacacs+&lt;/P&gt;&lt;P&gt;May 30 12:21:58.276: TPLUS(00000A52)/0/NB_WAIT/656FB000: Started 5 sec timeout&lt;/P&gt;&lt;P&gt;May 30 12:21:58.276: TPLUS(00000A52)/0/NB_WAIT: socket event 2&lt;/P&gt;&lt;P&gt;May 30 12:21:58.276: TPLUS(00000A52)/0/NB_WAIT: wrote entire 59 bytes request&lt;/P&gt;&lt;P&gt;May 30 12:21:58.276: TPLUS(00000A52)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;May 30 12:21:58.276: TPLUS(00000A52)/0/READ: Would block while reading&lt;/P&gt;&lt;P&gt;May 30 12:21:58.280: TPLUS(00000A52)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;May 30 12:21:58.280: TPLUS(00000A52)/0/READ: read entire 12 header bytes (expect 51 bytes data)&lt;/P&gt;&lt;P&gt;May 30 12:21:58.280: TPLUS(00000A52)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;May 30 12:21:58.280: TPLUS(00000A52)/0/READ: read entire 63 bytes response&lt;/P&gt;&lt;P&gt;May 30 12:21:58.280: TPLUS(00000A52)/0/656FB000: Processing the reply packet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May 30 12:21:58.280: TPLUS: Processed AV priv-lvl=15&lt;/P&gt;&lt;P&gt;May 30 12:21:58.280: TPLUS: Failed to decode AV shell:Admin*Admin default-domain - PASS - PASS&lt;/P&gt;&lt;P&gt;May 30 12:21:58.284: AAA/AUTHOR/EXEC(00000A52): processing AV cmd=&lt;/P&gt;&lt;P&gt;May 30 12:21:58.284: AAA/AUTHOR/EXEC(00000A52): Authorization successful&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS.log:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0043 1280 0x0 &amp;lt;&amp;lt;&amp;lt; RECEIVED FROM CLIENT:10.106.0.50 TYPE=AUTHOR, SEQ=1, FLAGS=1&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0043 1280 0x0 SESSIONID 1990425999 (0x76a37d8f), DATALEN 47 (0x2f)&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0043 1280 0x0 type=AUTHOR, priv_lvl=1, authen=1&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0043 1280 0x0 METHOD=tacacs+&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0043 1280 0x0 SVC=1 USER_LEN=2 PORT_LEN=6 REM_ADDR_LEN=12 ARG_CNT=2&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0043 1280 0x0 USER=ph&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0043 1280 0x0 PORT=tty195&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0043 1280 0x0 REM_ADDR=10.106.33.22&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0043 1280 0x0 arg[0](size=13)=service=shell&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0043 1280 0x0 arg[1](size=4)=cmd*&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0043 1280 0x0 END &amp;gt;&amp;gt;&amp;gt;&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0850 3244 0xf Single Connect thread 1 allocated work&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0143 3244 0xf Author Data: phtty19510.106.33.22service=shellcmd.=13362timezone=MEZservi&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0163 3244 0xf -- Extracted service info&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0189 3244 0xf -- Checked NARs&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0199 3244 0xf -- Set up Reqs:&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0209 3244 0xf -- Got Profiles&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0261 3244 0xf -- executed&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0263 3244 0xf -- command set clean done&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0265 3244 0xf -- NDG release done&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0043 3244 0xf &amp;lt;&amp;lt;&amp;lt; PACKET TO CLIENT:10.106.0.50 TYPE:AUTHOR/PASS_ADD, SEQ 2, FLAGS 1&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0043 3244 0xf SESSIONID 1990425999 (0x76a37d8f), DATALEN 51 (0x33)&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0043 3244 0xf type=AUTHOR/REPLY status=1 (AUTHOR/PASS_ADD) &lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0043 3244 0xf msg_len=0, data_len=0 arg_cnt=2&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0043 3244 0xf arg[0] size=11 =priv-lvl=15&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0043 3244 0xf arg[1] size=32 =shell:Admin*Admin default-domain&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0043 3244 0xf End &amp;gt;&amp;gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Putty session:&lt;/P&gt;&lt;P&gt;login as: ph&lt;/P&gt;&lt;P&gt;ph@10.106.0.16's password:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;------ (10.106.0.16 and 10.106.0.50 are IP addresses of the same router)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1841_hra_lab&amp;gt;&lt;/P&gt;&lt;P&gt;1841_hra_lab&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;------ I'm not in enable mode (priv.level 15)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Unfortunalety I haven't got logs/debugs from the period before update, when everything was ok.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I guess the problem is somewhere in this argument which goes from ACS to client:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;TCS 05/30/2013 12:21:58 I 0043 3244 0xf arg[1] size=32 =shell:Admin*Admin default-domain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone can tell me how this argument with optional parametr should looks like? &lt;/P&gt;&lt;P&gt;Perhaps *shell:Admin*Admin default-domain?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Petr&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:29:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/custom-attribute-in-acs4-2-patch-17/m-p/2218729#M105688</guid>
      <dc:creator>p.hruby</dc:creator>
      <dc:date>2019-03-11T03:29:03Z</dc:date>
    </item>
    <item>
      <title>Custom attribute in ACS4.2 patch 17</title>
      <link>https://community.cisco.com/t5/network-access-control/custom-attribute-in-acs4-2-patch-17/m-p/2218730#M105689</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Petr,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You're running into a defect. &lt;/P&gt;&lt;P&gt; &lt;A href="https://www.cisco.com/cisco/psn/bssprt/bss?searchType=bstbugidsearch&amp;amp;page=bstBugDetail&amp;amp;BugID=CSCth75577" target="_blank"&gt;CSCth75577&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACS incorrectly sends optional custom TACACS+ attributes &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Symptom:&lt;/B&gt;&lt;/P&gt;&lt;P&gt;TACACS+ Authorization from IOS fails if customer attributes (even optional attributes) are configured on the ACS user group.&amp;nbsp; The login will work but any attributes passed will not be honored.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Conditions:&lt;/B&gt;&lt;/P&gt;&lt;P&gt;ACS 4.2.0.124 patch 16&lt;/P&gt;&lt;P&gt;ACS 4.2.1.15 patch 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;Workaround:&lt;/B&gt;&lt;/P&gt;&lt;P&gt;Downgrade to a previous ACS patch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This has been fixed in &lt;/P&gt;&lt;P&gt;ACS 4.2.1.15 patch 3 or later.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Upgrade the ACS to 4.2.1.15 and apply the latest patch 10.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 May 2013 11:13:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/custom-attribute-in-acs4-2-patch-17/m-p/2218730#M105689</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-30T11:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: Custom attribute in ACS4.2 patch 17</title>
      <link>https://community.cisco.com/t5/network-access-control/custom-attribute-in-acs4-2-patch-17/m-p/2218731#M105690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jatin,&lt;/P&gt;&lt;P&gt;thanks a lot!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the proper way to downgrade to the previous patch? Should I apply &lt;SPAN style="font-size: 10pt;"&gt;Acs-4.2.0.124.15-SW.zip directy over my current installation which contains Patch 17?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Petr&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: Petr Hruby&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 May 2013 11:24:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/custom-attribute-in-acs4-2-patch-17/m-p/2218731#M105690</guid>
      <dc:creator>p.hruby</dc:creator>
      <dc:date>2013-05-30T11:24:51Z</dc:date>
    </item>
    <item>
      <title>Custom attribute in ACS4.2 patch 17</title>
      <link>https://community.cisco.com/t5/network-access-control/custom-attribute-in-acs4-2-patch-17/m-p/2218732#M105691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you ACS appliance or software running on windows server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 May 2013 11:32:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/custom-attribute-in-acs4-2-patch-17/m-p/2218732#M105691</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-30T11:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: Custom attribute in ACS4.2 patch 17</title>
      <link>https://community.cisco.com/t5/network-access-control/custom-attribute-in-acs4-2-patch-17/m-p/2218733#M105692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Software running on windows server.&lt;/P&gt;&lt;P&gt;P.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 May 2013 11:34:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/custom-attribute-in-acs4-2-patch-17/m-p/2218733#M105692</guid>
      <dc:creator>p.hruby</dc:creator>
      <dc:date>2013-05-30T11:34:51Z</dc:date>
    </item>
    <item>
      <title>Re: Custom attribute in ACS4.2 patch 17</title>
      <link>https://community.cisco.com/t5/network-access-control/custom-attribute-in-acs4-2-patch-17/m-p/2218734#M105693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Petr,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we do have a rollback command for acs appliance. However, in case of acs windows it's not recommended to install the previous patch over the existing/latest patch. I'd suggest you to upgrade.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may download the upgrade image and patch from the below listed link:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/squish/bF79B"&gt;http://tools.cisco.com/squish/bF79B&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Executable of ACS v4.2.1.15&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ACS-4.2.1.15-BIN-K9.zip&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS 4.2.1.15.10 cumulative patch &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Acs-4.2.1.15.10-SW.zip&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOTE: Please take backup of your current configuration before you proceed with the upgrade.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline; "&gt;In case you're not comfortable with the above procedure, please open a TAC case.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 May 2013 12:12:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/custom-attribute-in-acs4-2-patch-17/m-p/2218734#M105693</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-30T12:12:33Z</dc:date>
    </item>
  </channel>
</rss>

