<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.2 Cisco-AV-Pair Problem in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-2-cisco-av-pair-problem/m-p/1689686#M248159</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jrabinow,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your help. I have configured this condition and now it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Andreas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Jun 2011 11:24:25 GMT</pubDate>
    <dc:creator>Andreas_Seybold-Epting</dc:creator>
    <dc:date>2011-06-09T11:24:25Z</dc:date>
    <item>
      <title>ACS 5.2 Cisco-AV-Pair Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-cisco-av-pair-problem/m-p/1689680#M248060</link>
      <description>&lt;P&gt;Hi at all&lt;/P&gt;&lt;P&gt;i have a Problem with the cisco-av-pair string on the Cisco ACS and a SSID.&lt;/P&gt;&lt;P&gt;We&amp;nbsp; have here some SSID and some AD Groups. It was no Problem with the old&amp;nbsp; Cisco ACS 4.2. I have here configured the string: cisco-av-pair&amp;nbsp; ssid=myssid. The Clients have only rights to this ssid. It works without&amp;nbsp; Problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the new ACS 5.2. I have here Problem to configure this. &lt;/P&gt;&lt;P&gt;My Configuration is a new Identity Policy.&lt;/P&gt;&lt;P&gt;Compound Condition:&lt;/P&gt;&lt;P&gt;Radius-Cisco --&amp;gt;cisco-av-pair--&amp;gt;equals--&amp;gt;myssid&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But this string works not. &lt;/P&gt;&lt;P&gt;Did you have any ideas about this Problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My System:&lt;/P&gt;&lt;P&gt;Cisco ACS 5.2 with all new Patches&lt;/P&gt;&lt;P&gt;Cisco WLC newest Version&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Andreas&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:09:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-cisco-av-pair-problem/m-p/1689680#M248060</guid>
      <dc:creator>Andreas_Seybold-Epting</dc:creator>
      <dc:date>2019-03-11T01:09:05Z</dc:date>
    </item>
    <item>
      <title>ACS 5.2 Cisco-AV-Pair Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-cisco-av-pair-problem/m-p/1689681#M248072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I think you need to match on the string that appears in the attribute. In this case. "ssid=myssid"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to confirm what string should be used select: Monitoring and reports -&amp;gt; Launch Monitoring &amp;amp; Report Viewer&lt;/P&gt;&lt;P&gt;and then select Authentications -&amp;gt; RADIUS today&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should see a list of the requests including the ones you had tried. In the details column click on the icon and you will see the details of your RADIUS request. This includes the list of RADIUS attributes received. You can look at what is in the AV pair field and make sure a correct condition is specified&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jun 2011 06:52:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-cisco-av-pair-problem/m-p/1689681#M248072</guid>
      <dc:creator>jrabinow</dc:creator>
      <dc:date>2011-06-09T06:52:54Z</dc:date>
    </item>
    <item>
      <title>ACS 5.2 Cisco-AV-Pair Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-cisco-av-pair-problem/m-p/1689682#M248092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi jrabinow,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your Answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My Authorization Policy is with follow string:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RADIUS-Cisco:cisco-av-pair equals ssid=OFFEN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can the in Other Attributes:&lt;/P&gt;&lt;DIV&gt;ACSVersion=acs-5.2.0.26-B.3075 &lt;BR /&gt;ConfigVersionId=56 &lt;BR /&gt;Device&amp;nbsp; Port=32769 &lt;BR /&gt;RadiusPacketType=AccessRequest &lt;BR /&gt;Protocol=Radius &lt;BR /&gt;Service-Type=Framed &lt;BR /&gt;Framed-MTU=1300 &lt;BR /&gt;Called-Station-ID=1c-17-d3-fc-9b-00:&lt;STRONG&gt;OFFEN &lt;/STRONG&gt;&lt;BR /&gt;Airespace-Wlan-Id=7 &lt;BR /&gt;Device&amp;nbsp; IP Address=10.99.11.16&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OFFEN is my SSID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the Steps from the Report i can see:&lt;/P&gt;&lt;TABLE id="S2"&gt;&lt;TBODY&gt;&lt;TR align="left" style="border-bottom: #8499a2 thin; border-left: #8499a2 thin solid; padding-bottom: 1pt; padding-left: 2pt; padding-right: 2pt; color: #000000; border-top: #8499a2 thin; font-weight: normal; border-right: #8499a2 thin solid; padding-top: 1pt;"&gt;&lt;TD style="padding-bottom: 2pt; padding-left: 4pt; padding-right: 4pt; padding-top: 2pt;"&gt;&lt;P style="margin-top: 0pt;"&gt;15006&amp;nbsp; Matched Default Rule&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="border-bottom: #8499a2 thin; border-left: #8499a2 thin solid; padding-bottom: 1pt; padding-left: 2pt; padding-right: 2pt; color: #000000; border-top: #8499a2 thin; font-weight: normal; border-right: #8499a2 thin solid; padding-top: 1pt;"&gt;&lt;TD style="padding-bottom: 2pt; padding-left: 4pt; padding-right: 4pt; padding-top: 2pt;"&gt;&lt;DIV style="margin-top: 0pt;"&gt;15012&amp;nbsp; Selected Access Service -&amp;nbsp; DenyAccess&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="border-bottom: #8499a2 thin; border-left: #8499a2 thin solid; padding-bottom: 1pt; padding-left: 2pt; padding-right: 2pt; color: #000000; border-top: #8499a2 thin; font-weight: normal; border-right: #8499a2 thin solid; padding-top: 1pt;"&gt;&lt;TD style="padding-bottom: 2pt; padding-left: 4pt; padding-right: 4pt; padding-top: 2pt;"&gt;&lt;P style="margin-top: 0pt;"&gt;11019&amp;nbsp; Selected DenyAccess Service&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR align="left" style="border-bottom: #8499a2 thin; border-left: #8499a2 thin solid; padding-bottom: 1pt; padding-left: 2pt; padding-right: 2pt; color: #ff0000; border-top: #8499a2 thin; font-weight: normal; border-right: #8499a2 thin solid; padding-top: 1pt;"&gt;&lt;TD style="padding-bottom: 2pt; padding-left: 4pt; padding-right: 4pt; padding-top: 2pt;"&gt;&lt;P style="margin-top: 0pt;"&gt;11003&amp;nbsp; Returned RADIUS Access-Reject&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Andreas&lt;/P&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jun 2011 07:01:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-cisco-av-pair-problem/m-p/1689682#M248092</guid>
      <dc:creator>Andreas_Seybold-Epting</dc:creator>
      <dc:date>2011-06-09T07:01:05Z</dc:date>
    </item>
    <item>
      <title>ACS 5.2 Cisco-AV-Pair Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-cisco-av-pair-problem/m-p/1689683#M248108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; from the steps can see that no Access Service is being matched. It is selecting the default rule. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A first step will be to look at the Service Selection Policy (Access Policies &amp;gt; Access Services &amp;gt; Service Selection Rules) and see why an access service is not being selected&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jun 2011 07:34:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-cisco-av-pair-problem/m-p/1689683#M248108</guid>
      <dc:creator>jrabinow</dc:creator>
      <dc:date>2011-06-09T07:34:54Z</dc:date>
    </item>
    <item>
      <title>ACS 5.2 Cisco-AV-Pair Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-cisco-av-pair-problem/m-p/1689684#M248122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have make a Test with the "Airespace-WLAN-ID" Attribute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can configure a rule with &lt;/P&gt;&lt;P&gt;RADIUS-Cisco Airespace-Wlan-ID=7&lt;/P&gt;&lt;P&gt;This works. I can only connect to this Wlan-ID.&lt;/P&gt;&lt;P&gt;I have found this in the Other Attributes list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACSVersion=acs-5.2.0.26-B.3075 &lt;/P&gt;&lt;P&gt;ConfigVersionId=56 &lt;/P&gt;&lt;P&gt;Device&amp;nbsp; Port=32769 &lt;/P&gt;&lt;P&gt;RadiusPacketType=AccessRequest &lt;/P&gt;&lt;P&gt;Protocol=Radius &lt;/P&gt;&lt;P&gt;Service-Type=Framed &lt;/P&gt;&lt;P&gt;Framed-MTU=1300 &lt;/P&gt;&lt;P&gt;Called-Station-ID=1c-17-d3-fc-9b-00:OFFEN &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Airespace-Wlan-Id=7 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Device&amp;nbsp; IP Address=10.99.11.16&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But i can not find only the name of the SSID, only in the String "Called-Station-ID..."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible that the ACS get not this Information from the WLC?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jun 2011 08:53:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-cisco-av-pair-problem/m-p/1689684#M248122</guid>
      <dc:creator>Andreas_Seybold-Epting</dc:creator>
      <dc:date>2011-06-09T08:53:08Z</dc:date>
    </item>
    <item>
      <title>ACS 5.2 Cisco-AV-Pair Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-cisco-av-pair-problem/m-p/1689685#M248141</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could try a condition:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Called-Station-ID&amp;nbsp; ends-with ":0FFEN"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jun 2011 09:18:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-cisco-av-pair-problem/m-p/1689685#M248141</guid>
      <dc:creator>jrabinow</dc:creator>
      <dc:date>2011-06-09T09:18:56Z</dc:date>
    </item>
    <item>
      <title>ACS 5.2 Cisco-AV-Pair Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-cisco-av-pair-problem/m-p/1689686#M248159</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jrabinow,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your help. I have configured this condition and now it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Andreas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jun 2011 11:24:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-cisco-av-pair-problem/m-p/1689686#M248159</guid>
      <dc:creator>Andreas_Seybold-Epting</dc:creator>
      <dc:date>2011-06-09T11:24:25Z</dc:date>
    </item>
  </channel>
</rss>

