<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.X - External Proxy in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-x-external-proxy/m-p/1757897#M218711</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; i contacted TAC who confirmed the above wasn't possible with current ACS 5 code. i've put in a feature request for a future release:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;SPAN style="font-family: Arial;"&gt;Request:&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-family: Arial;"&gt;Requirement for ACS to draft an authentication request with additional attributes before forwarding it to proxy radius server&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;cheers&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;andy&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 Nov 2011 16:08:18 GMT</pubDate>
    <dc:creator>andrewswanson</dc:creator>
    <dc:date>2011-11-23T16:08:18Z</dc:date>
    <item>
      <title>ACS 5.X - External Proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-x-external-proxy/m-p/1757896#M218708</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;hello&lt;/P&gt;&lt;P&gt;i'm running into some problems with ACS 5 and the External Proxy Access Service policy. The issue is the same as outlined here:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/thread/2075329" target="_blank"&gt;https://supportforums.cisco.com/thread/2075329&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i've also tried this with ACS 5.2 and 5.3. when i use the External Proxy policy in acs 5, only a set list of attributes is sent to the proxy - i can't add any additional attributes to this list. Is there a workaround for this or plans to introduce this capability in any future releases?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;andy&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:29:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-x-external-proxy/m-p/1757896#M218708</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2019-03-11T01:29:45Z</dc:date>
    </item>
    <item>
      <title>ACS 5.X - External Proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-x-external-proxy/m-p/1757897#M218711</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; i contacted TAC who confirmed the above wasn't possible with current ACS 5 code. i've put in a feature request for a future release:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;SPAN style="font-family: Arial;"&gt;Request:&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-family: Arial;"&gt;Requirement for ACS to draft an authentication request with additional attributes before forwarding it to proxy radius server&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;cheers&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;andy&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Nov 2011 16:08:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-x-external-proxy/m-p/1757897#M218711</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2011-11-23T16:08:18Z</dc:date>
    </item>
    <item>
      <title>ACS 5.X - External Proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-x-external-proxy/m-p/1757898#M218713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For background information on this request can you share which attributes you would like to add and what is the use case&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Nov 2011 23:03:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-x-external-proxy/m-p/1757898#M218713</guid>
      <dc:creator>jrabinow</dc:creator>
      <dc:date>2011-11-23T23:03:30Z</dc:date>
    </item>
    <item>
      <title>ACS 5.X - External Proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-x-external-proxy/m-p/1757899#M218715</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; i'm looking to configure ACS 5 to take part in the eduroam service ( see &lt;A href="http://www.eduroam.org/"&gt;http://www.eduroam.org/&lt;/A&gt;). this service allows users of participating institutions to use their university credentials to login to other university's WLANS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to do this, we have to proxy 'visitors' authentication requests to&amp;nbsp; a central proxy service which directs the request to the appropriate institution for authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the setup on ACS 5 is pretty straight forward but there is an additional requirement where we have to 'inject' a radius ietf attribute 126 operator-name into the authentication requests that are sent to the central proxy. the operator-name attribute will be a string and will contain the name of the institution that is sending the authentication request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i can add the operator-name attribute to the ACS 5 radius dictionary but can't use it when using an External Proxy Access Service policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;andy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Nov 2011 23:30:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-x-external-proxy/m-p/1757899#M218715</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2011-11-23T23:30:43Z</dc:date>
    </item>
    <item>
      <title>ACS 5.X - External Proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-x-external-proxy/m-p/1757900#M218716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Just finished taking part in ACS 5.4 beta test and this is resolved. ACS 5.4 allows the Outbound manipulation (Add/Delete/Modify) of RADIUS attributes when using an External Proxy access policy. Inbound manipulation (e.g. set attributes for aaa override) will hopefully be included in later releases.&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;P&gt;andy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jul 2012 10:41:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-x-external-proxy/m-p/1757900#M218716</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2012-07-09T10:41:22Z</dc:date>
    </item>
  </channel>
</rss>

