<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: attribute definition syntax in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/attribute-definition-syntax/m-p/1536565#M253924</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Whether you put shell: or cisco-av-pair: depends on the RADIUS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The * instead of the = makes the attribute optional rather than mandatory. This will have relevance if those attributes will be sent to all devices in which the user logs in, in that case you will want to make the attributes optional or the device might fail authorization if it doesn't know what to do with a mandatory attribute (IOS, for example, will fail authorization if it receives a role assignment as mandatory).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 29 Nov 2010 20:18:07 GMT</pubDate>
    <dc:creator>Javier Henderson</dc:creator>
    <dc:date>2010-11-29T20:18:07Z</dc:date>
    <item>
      <title>attribute definition syntax</title>
      <link>https://community.cisco.com/t5/network-access-control/attribute-definition-syntax/m-p/1536564#M253895</link>
      <description>&lt;P&gt;Hi !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I planned to migrate our MDS switches to TACACS+ for AAA services.&amp;nbsp; I the documentation I find some different way to defining attributes :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/storage/san_switches/mds9000/sw/rel_2_x/fm/configuration/guide/radius.html#wp1224864" target="_blank"&gt;http://www.cisco.com/en/US/docs/storage/san_switches/mds9000/sw/rel_2_x/fm/configuration/guide/radius.html#wp1224864&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="pEx2_Example2"&gt;&lt;PRE&gt;shell:roles="network-admin"
&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt;&lt;A name="wp1224871" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV class="pEx2_Example2"&gt;&lt;PRE&gt;shell:roles*"network-admin"
&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt;&lt;A name="wp1224872" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV class="pEx2_Example2"&gt;&lt;PRE&gt;cisco-av-pair*shell:roles="network-admin"
&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt;&lt;A name="wp1224873" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV class="pEx2_Example2"&gt;&lt;PRE&gt;cisco-av-pair*shell:roles*"network-admin"
&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt;&lt;A name="wp1224874" target="_blank"&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV class="pEx2_Example2"&gt;&lt;PRE&gt;cisco-av-pair=shell:roles*"network-admin"
&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what is difference between those syntaxe ?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:37:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/attribute-definition-syntax/m-p/1536564#M253895</guid>
      <dc:creator>xine xine</dc:creator>
      <dc:date>2019-03-11T00:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: attribute definition syntax</title>
      <link>https://community.cisco.com/t5/network-access-control/attribute-definition-syntax/m-p/1536565#M253924</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Whether you put shell: or cisco-av-pair: depends on the RADIUS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The * instead of the = makes the attribute optional rather than mandatory. This will have relevance if those attributes will be sent to all devices in which the user logs in, in that case you will want to make the attributes optional or the device might fail authorization if it doesn't know what to do with a mandatory attribute (IOS, for example, will fail authorization if it receives a role assignment as mandatory).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Nov 2010 20:18:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/attribute-definition-syntax/m-p/1536565#M253924</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2010-11-29T20:18:07Z</dc:date>
    </item>
  </channel>
</rss>

