<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.3 authorization with Juniper WXC-3400 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235342#M250261</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Shawn,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Looks like the logs you mentioned, doesnt show if they are passing the read-write attributes:&lt;/P&gt;&lt;P&gt;- Can you check if its hitting the right rule?, if possible could you please take the snap shot of Tacacs authorization from ACS 5 and send it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Minakshi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 06 May 2013 21:17:56 GMT</pubDate>
    <dc:creator>minkumar</dc:creator>
    <dc:date>2013-05-06T21:17:56Z</dc:date>
    <item>
      <title>ACS 5.3 authorization with Juniper WXC-3400</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235333#M249460</link>
      <description>&lt;P&gt;In the process of migrating from ACS 4.1 to ACS 5.3. Authentication works fine, but having issues with authorization on the Juniper WXC-3400 devices. In ACS&amp;nbsp; 4.1 we were passing TACACS+Shell (exec) Custom attributes Privilege level=15, which allowed a user to login with read/write privileges. In ACS 5.3&amp;nbsp; tried setting the Shell Profiles common task to 15 for both Default and Maximum (one at a time, and together), as well as setting the Custom Attributes for priv-lvl=15 (with and without Common Tasks set).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A capture shows Auth Status: 0x11&amp;nbsp; (ERROR).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:23:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235333#M249460</guid>
      <dc:creator>shawn</dc:creator>
      <dc:date>2019-03-11T03:23:57Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 authorization with Juniper WXC-3400</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235334#M249573</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you need to push couple more attributes in the same shell profile to make this work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;under shell profiles &amp;gt; custom attributes &amp;gt; add the following attributes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;attribute&amp;nbsp;&amp;nbsp;&amp;nbsp; Requirement&amp;nbsp;&amp;nbsp; value&lt;/P&gt;&lt;P&gt;vsys&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mandatory&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&lt;/P&gt;&lt;P&gt;privilege&amp;nbsp;&amp;nbsp;&amp;nbsp; maddatory&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; read-write&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;try this please and let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 May 2013 16:16:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235334#M249573</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-06T16:16:42Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 authorization with Juniper WXC-3400</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235335#M249696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've tried adding both of those custom attributes with and without Default/Maximum Privilege being set to 15.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No luck, still Read only access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks-&lt;/P&gt;&lt;P&gt; Shawn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 May 2013 16:21:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235335#M249696</guid>
      <dc:creator>shawn</dc:creator>
      <dc:date>2013-05-06T16:21:58Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 authorization with Juniper WXC-3400</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235336#M249800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what do you see in tacacs authorization?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also can you upload the pcap file?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 May 2013 16:45:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235336#M249800</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-06T16:45:02Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 authorization with Juniper WXC-3400</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235337#M249897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;... never see anything in the tacacs authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can't upload a capture, as it's within our non-public infrastructure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you just wanting to look at the query and response or complete conversation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Shawn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 May 2013 17:04:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235337#M249897</guid>
      <dc:creator>shawn</dc:creator>
      <dc:date>2013-05-06T17:04:10Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 authorization with Juniper WXC-3400</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235338#M249975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yup. I want to see Tacacs+ authorization &lt;STRONG&gt;Query &lt;/STRONG&gt;and &lt;STRONG&gt;Response&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even the ACS/Tacacs authorization result should show us what exactly it is sending it out to Juniper.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 May 2013 20:06:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235338#M249975</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-06T20:06:17Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 authorization with Juniper WXC-3400</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235339#M250060</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is what I found for you:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/message/3417297#3417297"&gt;https://supportforums.cisco.com/message/3417297&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This may give you quick review of your config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 May 2013 20:08:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235339#M250060</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-06T20:08:44Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 authorization with Juniper WXC-3400</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235340#M250127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Time&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VLAN Protocol Info&lt;/P&gt;&lt;P&gt;18 09:14:00.268166580&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WX_Juniper&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ACS_5_3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TACACS+&amp;nbsp; Q: Authorization&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Frame 18: 107 bytes on wire (856 bits), 107 bytes captured (856 bits)&lt;/P&gt;&lt;P&gt;Ethernet II, Src: Cisco_cd:46:af (00:07:7d:cd:46:af), Dst: Ibm_fe:9a:63 (5c:f3:fc:fe:9a:63)&lt;/P&gt;&lt;P&gt;Internet Protocol, Src: WX_Juniper (WX_Juniper), Dst: ACS_5_3 (ACS_5_3)&lt;/P&gt;&lt;P&gt;Transmission Control Protocol, Src Port: l2c-control (4371), Dst Port: tacacs (49), Seq: 1, Ack: 1, Len: 49&lt;/P&gt;&lt;P&gt;TACACS+&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Major version: TACACS+&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Minor version: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type: Authorization (2)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Sequence number: 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Flags: 0x04 (Encrypted payload, Single connection)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session ID: 1491582254&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Packet length: 37&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Encrypted Request&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Decrypted Request&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Auth Method: TACACSPLUS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Privilege Level: 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authentication type: ASCII&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Service: Login&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User len: 8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User: stmartin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Port len: 7&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Port: console&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Remaddr len: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Arg count: 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Arg[0] length: 13&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Arg[0] value: service=shell&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Time&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Source&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Destination&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VLAN Protocol Info&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20 09:14:00.271608140 ACS_5_3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WX_Juniper&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; TACACS+&amp;nbsp; R: Authorization&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Frame 20: 76 bytes on wire (608 bits), 76 bytes captured (608 bits)&lt;/P&gt;&lt;P&gt;Ethernet II, Src: Ibm_fe:9a:63 (5c:f3:fc:fe:9a:63), Dst: Cisco_cd:46:af (00:07:7d:cd:46:af)&lt;/P&gt;&lt;P&gt;Internet Protocol, Src: ACS_5_3 (ACS_5_3), Dst: WX_Juniper (WX_Juniper)&lt;/P&gt;&lt;P&gt;Transmission Control Protocol, Src Port: tacacs (49), Dst Port: l2c-control (4371), Seq: 1, Ack: 50, Len: 18&lt;/P&gt;&lt;P&gt;TACACS+&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Major version: TACACS+&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Minor version: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Type: Authorization (2)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Sequence number: 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Flags: 0x00 (Encrypted payload, Multiple Connections)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Session ID: 1491582254&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Packet length: 6&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Encrypted Reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Decrypted Reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Auth Status: 0x11 (ERROR)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Server Msg length: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Data length: 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Arg count: 0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 May 2013 21:01:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235340#M250127</guid>
      <dc:creator>shawn</dc:creator>
      <dc:date>2013-05-06T21:01:44Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 authorization with Juniper WXC-3400</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235341#M250182</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've been though that last link a dozen times .... argh &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks-&lt;/P&gt;&lt;P&gt; Shawn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 May 2013 21:02:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235341#M250182</guid>
      <dc:creator>shawn</dc:creator>
      <dc:date>2013-05-06T21:02:16Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 authorization with Juniper WXC-3400</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235342#M250261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Shawn,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Looks like the logs you mentioned, doesnt show if they are passing the read-write attributes:&lt;/P&gt;&lt;P&gt;- Can you check if its hitting the right rule?, if possible could you please take the snap shot of Tacacs authorization from ACS 5 and send it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Minakshi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 May 2013 21:17:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235342#M250261</guid>
      <dc:creator>minkumar</dc:creator>
      <dc:date>2013-05-06T21:17:56Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 authorization with Juniper WXC-3400</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235343#M250331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Shawn,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per the error message, the ACS is rejecting the request, What do you get on the ACS for this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, the Junper device is&amp;nbsp; not asking for any extra attributes, just the shell, as usually third party devices show the attributes that they need in the Author Request.&lt;/P&gt;&lt;P&gt;Request:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Arg[0] length: 13&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Arg[0] value: service=shell&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Response:&lt;/P&gt;&lt;P&gt;Decrypted Reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Auth Status: 0x11 (ERROR)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rate if useful &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 May 2013 21:44:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235343#M250331</guid>
      <dc:creator>edwjames</dc:creator>
      <dc:date>2013-05-06T21:44:09Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 authorization with Juniper WXC-3400</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235344#M250376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not ever seeing anything in the tacacs authorization, looked at AAA Diagnostics this morning and I'm seeing:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE id="__TOC_0"&gt;&lt;TBODY&gt;&lt;TR align="left" valign="top"&gt;&lt;TD style="padding-bottom: 2pt; padding-left: 4pt; padding-right: 4pt; padding-top: 2pt;" valign="top"&gt;&lt;P style="white-space: nowrap;"&gt;May 7,13 2:59:27.073 PM&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding-bottom: 2pt; padding-left: 4pt; padding-right: 4pt; padding-top: 2pt;" valign="top"&gt;&lt;P&gt;May 7,13 2:59:27.050 PM&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding-bottom: 2pt; padding-left: 4pt; padding-right: 4pt; padding-top: 2pt;" valign="top"&gt;&lt;P style="white-space: nowrap;"&gt;p-msfc-acs2/151373657/554798&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding-bottom: 2pt; padding-left: 4pt; padding-right: 4pt; padding-top: 2pt;" valign="top"&gt;&lt;P style="white-space: nowrap;"&gt;WARN&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding-bottom: 2pt; padding-left: 4pt; padding-right: 4pt; padding-top: 2pt;" valign="top"&gt;&lt;P&gt;Invalid TACACS+ authorization request&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding-bottom: 2pt; padding-left: 4pt; padding-right: 4pt; padding-top: 2pt;" valign="top"&gt;&lt;P style="white-space: nowrap;"&gt;CSCOacs_TACACS_Diagnostics&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding-bottom: 2pt; padding-left: 4pt; padding-right: 4pt; padding-top: 2pt;" valign="top"&gt;&lt;P style="white-space: nowrap;"&gt;13000&lt;/P&gt;&lt;/TD&gt;&lt;TD style="padding-bottom: 2pt; padding-left: 4pt; padding-right: 4pt; padding-top: 2pt;" valign="top"&gt;&lt;DIV&gt;Device IP Address=192.xxx.xxx.xxx.xxx&lt;BR /&gt;Device&amp;nbsp; Port=4712&lt;BR /&gt;MajorVersion=Default&lt;BR /&gt;MinorVersion=Default&lt;BR /&gt;Type=Authorization&lt;BR /&gt;Sequence-Number=1&lt;BR /&gt;Header-Flags=Encrypted&lt;BR /&gt;SessionId=950056336&lt;BR /&gt;Privilege-Level=1&lt;BR /&gt;Authen-Type=ASCII&lt;BR /&gt;Service=Login&lt;BR /&gt;User=stmartin&lt;BR /&gt;Port=console&lt;BR /&gt;Authen-Method=TacacsPlus&lt;BR /&gt;Service-Argument=shell&lt;BR /&gt;EnableSingleConnect=false&lt;BR /&gt;CiscoIOS=true&lt;BR /&gt;UseSingleConnect=false&lt;BR /&gt;AcsSessionID=p-msfc-acs2/151373657/554798&lt;BR /&gt;SelectedAccessService=CNOC&amp;nbsp; Network Ops&amp;nbsp; WOA&lt;BR /&gt;Sequence-Number=2&lt;BR /&gt;SessionId=950056336&lt;BR /&gt;Response={AuthenticationResult=Passed;&amp;nbsp; MajorVersion=Default; MinorVersion=Default; Type=Authorization;&amp;nbsp; Header-Flags=Encrypted; SessionId=950056336; Author-Reply-Status=Error;&amp;nbsp; }&lt;/DIV&gt;&lt;/TD&gt;&lt;TD style="padding-bottom: 2pt; padding-left: 4pt; padding-right: 4pt; padding-top: 2pt;" valign="top"&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 15:02:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235344#M250376</guid>
      <dc:creator>shawn</dc:creator>
      <dc:date>2013-05-07T15:02:20Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 authorization with Juniper WXC-3400</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235345#M250421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see...&lt;SPAN __jive_emoticon_name="confused" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; if you look at Authorization Query...it's only sending&lt;STRONG&gt; Arg[0] value: service=shell&lt;/STRONG&gt; and didn't send&lt;STRONG&gt; "cmd=" arg&lt;/STRONG&gt;. As per T+ draft if service is shell, "cmd" attribute must be sent in Q.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;&lt;A href="http://tools.ietf.org/html/draft-grant-tacacs-02" target="_blank"&gt;http://tools.ietf.org/html/draft-grant-tacacs-02&lt;/A&gt;
&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cmd&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; a shell (exec) command. This indicates the command name for a shell&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; command that is to be run. This attribute MUST be specified if ser-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; vice equals "shell". A NULL value indicates that the shell itself is&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; being referred to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now you must be thinking why it's working with ACS 4.x and just not with ACS 5.x &lt;/P&gt;&lt;P&gt;ACS 4.x doesn't check the presence of cmd and treat cmd= and no cmd as same, ACS 5.x is more strict&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've seen this happening with variety of 3rd party devices like bluecoat, zone ranger and now Juniper.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to involve Juniper support or development team to get a patch so that the authorization Q should contain cmd=&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 May 2013 15:46:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235345#M250421</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-07T15:46:14Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 authorization with Juniper WXC-3400</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235346#M250466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Let me know if you still have any doubt.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 15:27:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235346#M250466</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-08T15:27:09Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 authorization with Juniper WXC-3400</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235347#M250506</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your help.&amp;nbsp; This has been resolved in new WX OS (5.7.7).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 May 2013 19:05:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235347#M250506</guid>
      <dc:creator>shawn</dc:creator>
      <dc:date>2013-05-15T19:05:47Z</dc:date>
    </item>
    <item>
      <title>ACS 5.3 authorization with Juniper WXC-3400</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235348#M250534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the update. I guess Juniper dev's has already added the patch for this issue in WX OS 5.7.7 rather than launching a new patch. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 May 2013 19:24:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-3-authorization-with-juniper-wxc-3400/m-p/2235348#M250534</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-15T19:24:15Z</dc:date>
    </item>
  </channel>
</rss>

