<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello Jan, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/what-does-mean-aaa-authorization-network-what-does-limit-network/m-p/3083345#M25794</link>
    <description>&lt;P&gt;Hello Jan,&lt;/P&gt;
&lt;P&gt;aaa authorization network can be used to allow users access to the network if dot1x authentication have been configured on the cisco switch.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the case that you use aaa authorization network default group SRV-ISE : this command can be used to to allow the SRV-ISE (which is an ACS or ISE server) to dynamically&amp;nbsp;assign vlan to user ports and this is based on their identities (username or MAC address).&lt;/P&gt;
&lt;P&gt;if you need more details, try to read this article&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/12-2/31sga/configuration/guide/config/dot1x.html#wp1133313&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Wed, 12 Jul 2017 22:05:55 GMT</pubDate>
    <dc:creator>netsysconsultant</dc:creator>
    <dc:date>2017-07-12T22:05:55Z</dc:date>
    <item>
      <title>What does mean 'aaa authorization network', what does limit 'network' keyword?</title>
      <link>https://community.cisco.com/t5/network-access-control/what-does-mean-aaa-authorization-network-what-does-limit-network/m-p/3083344#M25793</link>
      <description>&lt;DIV class="field field-name-body field-type-text-with-summary field-label-hidden"&gt;
&lt;DIV class="field-items"&gt;
&lt;DIV class="field-item even" property="content:encoded"&gt;
&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I am studying CCNP Switch course and stuck in AAA authorization topic. I do not understand what actually is purpose of the following command chain '&lt;SPAN style="font-family: courier new,courier,monospace; color: #000000;"&gt;&lt;STRONG&gt;aaa authorization network&lt;/STRONG&gt; ....&lt;/SPAN&gt;'.&lt;/P&gt;
&lt;P&gt;Cisco books and web-pages define this like sonething:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN style="font-family: courier new,courier,monospace; color: #000000;"&gt;&lt;STRONG&gt;network&lt;/STRONG&gt;&lt;/SPAN&gt;: The server must return permission to use network-related services.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;However, do does it means '&lt;EM&gt;network-related services&lt;/EM&gt;'? Is the &lt;STRONG&gt;telnet&lt;/STRONG&gt; network related service? I have been serching info about details what this command does and no success. Some network pages mean authorization for PPP, PPPoE, SLIP.... I am confused.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Let's say I entered following command on the switch:&lt;/P&gt;
&lt;PRE class="prettyprint prettyprinted"&gt;&lt;SPAN class="pln"&gt; &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;switch&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;(&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;config&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;)#&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;aaa authorization network &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;default&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; &lt;/SPAN&gt;&lt;SPAN class="kwd"&gt;group&lt;/SPAN&gt;&lt;SPAN class="pln"&gt; SRV&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;-&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;ISE&amp;nbsp;&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;What can I do on this switch and what cannot? What is limited and what is not? What will be authorized and what won't be?&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:50:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-does-mean-aaa-authorization-network-what-does-limit-network/m-p/3083344#M25793</guid>
      <dc:creator>Yan Merchy</dc:creator>
      <dc:date>2019-03-11T07:50:59Z</dc:date>
    </item>
    <item>
      <title>Hello Jan,</title>
      <link>https://community.cisco.com/t5/network-access-control/what-does-mean-aaa-authorization-network-what-does-limit-network/m-p/3083345#M25794</link>
      <description>&lt;P&gt;Hello Jan,&lt;/P&gt;
&lt;P&gt;aaa authorization network can be used to allow users access to the network if dot1x authentication have been configured on the cisco switch.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the case that you use aaa authorization network default group SRV-ISE : this command can be used to to allow the SRV-ISE (which is an ACS or ISE server) to dynamically&amp;nbsp;assign vlan to user ports and this is based on their identities (username or MAC address).&lt;/P&gt;
&lt;P&gt;if you need more details, try to read this article&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/12-2/31sga/configuration/guide/config/dot1x.html#wp1133313&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2017 22:05:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-does-mean-aaa-authorization-network-what-does-limit-network/m-p/3083345#M25794</guid>
      <dc:creator>netsysconsultant</dc:creator>
      <dc:date>2017-07-12T22:05:55Z</dc:date>
    </item>
    <item>
      <title>On switches "aaa</title>
      <link>https://community.cisco.com/t5/network-access-control/what-does-mean-aaa-authorization-network-what-does-limit-network/m-p/3083346#M25795</link>
      <description>&lt;P&gt;On switches "aaa authorization network" refers to authorization of devices connected to the switch, so you would point "aaa authorization network" to a group of ISE/ACS servers, like in your example.&lt;/P&gt;
&lt;P&gt;If you do not configure the authorization command and have only the "aaa authentication dot1x", you would run into strange dot1x issues. (basically switch would authenticate dot1x session, but would not apply the RADIUS session attributes sent by ISE)&lt;/P&gt;
&lt;P&gt;For telnet or ssh you would use the "aaa authorization exec/commands", attach that to the vty lines, and that would then control telnet/ssh access to the switch.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate if helpful&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2017 22:15:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-does-mean-aaa-authorization-network-what-does-limit-network/m-p/3083346#M25795</guid>
      <dc:creator>agrissimanis</dc:creator>
      <dc:date>2017-07-12T22:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: What does mean 'aaa authorization network', what does limit 'netwo</title>
      <link>https://community.cisco.com/t5/network-access-control/what-does-mean-aaa-authorization-network-what-does-limit-network/m-p/5298395#M596743</link>
      <description>&lt;P&gt;Just a comment to the original question.&lt;/P&gt;&lt;P&gt;"Some network pages mean authorization for PPP, PPPoE, SLIP.... I am confused."&lt;/P&gt;&lt;P&gt;I am too. Especially because:&lt;/P&gt;&lt;P&gt;1. The list of mentioned "network" services in Cisco pages is not complete.&lt;/P&gt;&lt;P&gt;2. Without this "aaa authorization network default group SRV-ISE" type of command, the dot1x breaks (I just tested): the computer authenticates but it doesn't get the IP-address -- because the VLAN information, if this is being sent by the Radius server, is not accepted and no VLAN will be set to the authenticated computer. Maybe, if the VLAN name or number is being set by the switch, it works but I haven't tested it.&lt;/P&gt;&lt;P&gt;The document referred to above has this information: "Enable AAA authorization with the network keyword to allow interface configuration from the RADIUS server." The confusing part comes from the fact that I need to use "network" instead of "dot1x" for a dot1x-related configuration and as the original post has it, the term "network" is ambiguous because anything can be considered under this term because we are dealing with network devices here.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jun 2025 11:51:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-does-mean-aaa-authorization-network-what-does-limit-network/m-p/5298395#M596743</guid>
      <dc:creator>echo</dc:creator>
      <dc:date>2025-06-11T11:51:19Z</dc:date>
    </item>
  </channel>
</rss>

