<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authorization FAILING in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authorization-failing/m-p/1551389#M274558</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vinashar, I'm using RADIUS (Windows 2008 NPS). The funny thing is the configuration on the RADIUS works for IOS 12.2(50) on another device. However, I'm encountering the problem on the 12.1. Also it's the same user that can successfully login to the 12.2(50) IOS and granted authorization who cannot get into the 12.1.&lt;/P&gt;&lt;P&gt;All thoughts welcome.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 02 Nov 2010 15:27:41 GMT</pubDate>
    <dc:creator>nikalleyne</dc:creator>
    <dc:date>2010-11-02T15:27:41Z</dc:date>
    <item>
      <title>Authorization FAILING</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-failing/m-p/1551386#M274531</link>
      <description>&lt;P&gt;Guys,&lt;/P&gt;&lt;P&gt;can someone tell me why my Authorization is failing once i enable "aaa authorization exec default group radius if-authenticated". If I omit the authorization line then I get put into user mode.&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authorization exec default group radius if-authenticated&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Debug aaa authorization&lt;/P&gt;&lt;P&gt;1w5d: AAA: parse name=tty2 idb type=-1 tty=-1&lt;BR /&gt;1w5d: AAA: name=tty2 flags=0x11 type=5 shelf=0 slot=0 adapter=0 port=2 channel=0&lt;BR /&gt;1w5d: AAA/MEMORY: create_user (0x1B5AEF8) user='NULL' ruser='NULL' ds0=0 port='tty2' rem_addr='190.168.2.8' authen_type=ASCII service=LOGIN priv=1 initial_task_id='0', vrf= (id=0)&lt;BR /&gt;1w5d: tty2 AAA/AUTHOR/EXEC (2449366269): Port='tty2' list='' service=EXEC&lt;BR /&gt;1w5d: AAA/AUTHOR/EXEC: tty2 (2449366269) user='User1'&lt;BR /&gt;1w5d: tty2 AAA/AUTHOR/EXEC (2449366269): send AV service=shell&lt;BR /&gt;1w5d: tty2 AAA/AUTHOR/EXEC (2449366269): send AV cmd*&lt;BR /&gt;1w5d: tty2 AAA/AUTHOR/EXEC (2449366269): found list "default"&lt;BR /&gt;1w5d: tty2 AAA/AUTHOR/EXEC (2449366269): Method=radius (radius)&lt;BR /&gt;1w5d: AAA/AUTHOR (2449366269): Post authorization status = FAIL&lt;BR /&gt;1w5d: AAA/AUTHOR/EXEC: Authorization FAILED&lt;BR /&gt;1w5d: AAA/MEMORY: free_user (0x1B5AEF8) user='User1' ruser='NULL' port='tty2' rem_addr='190.168.2.8' authen_type=ASCII service=LOGIN priv=1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;BR /&gt; session-timeout 15&lt;BR /&gt; exec-timeout 15 0&lt;BR /&gt; password test&lt;BR /&gt; login authentication My-RADIUS&lt;BR /&gt;line vty 5 15&lt;BR /&gt; password test&lt;BR /&gt; login authentication My-RADIUS&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This config works on other devices, however it does not work on this device with IOS&amp;nbsp; 12.2(25r)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All assistance welcome&lt;/P&gt;&lt;P&gt;Nik&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:31:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-failing/m-p/1551386#M274531</guid>
      <dc:creator>nikalleyne</dc:creator>
      <dc:date>2019-03-11T00:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization FAILING</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-failing/m-p/1551387#M274539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In order to get into authorization, user need to get priv lvl 15 whereas your user is getting only lvl 1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;' authen_type=ASCII service=LOGIN priv=1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check in ACS if you have given enough priv to the user at user profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Vinay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Nov 2010 15:05:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-failing/m-p/1551387#M274539</guid>
      <dc:creator>Vinay Sharma</dc:creator>
      <dc:date>2010-11-02T15:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization FAILING</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-failing/m-p/1551388#M274551</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also try this sample config:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a sample configuration:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;router(config)# enable password XXXXXXX &lt;/P&gt;&lt;P&gt;router(config)# username admin privilege 15 password xxxxx &lt;/P&gt;&lt;P&gt;router(config)# aaa new-model (Enables AAA configuration commands on the router)&lt;/P&gt;&lt;P&gt;router(config)# Tacacs-server host XXXXXXX ( IP address of the ACS server) &lt;/P&gt;&lt;P&gt;router(config)# Tacacs-server key XXXXXX ( This is the same shared secret key which we defined on the ACS for this IOS device) &lt;/P&gt;&lt;P&gt;router(config)# aaa authentication login default group Tacacs+ local &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authenticate telnet users on TACACS+ if TACACS+ is down authenticate users with locally configured telnet username password on router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;router(config)# aaa authentication enable default group Tacacs+ enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authenticate the enable password on the TACACS+ if TACACS+ is down authenticate enable password with locally configured enable password on router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router(config)# aaa accounting exec default start-stop group TACACS+ (Account all the user which are telneting based on start and stop session on TACACS+)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router(config)# line vty 04 (Change to line vty line)&lt;/P&gt;&lt;P&gt;Router(config-line)# Login authentication default (Enables tacacs authentication for the vty lines)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Nov 2010 15:06:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-failing/m-p/1551388#M274551</guid>
      <dc:creator>Vinay Sharma</dc:creator>
      <dc:date>2010-11-02T15:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization FAILING</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-failing/m-p/1551389#M274558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vinashar, I'm using RADIUS (Windows 2008 NPS). The funny thing is the configuration on the RADIUS works for IOS 12.2(50) on another device. However, I'm encountering the problem on the 12.1. Also it's the same user that can successfully login to the 12.2(50) IOS and granted authorization who cannot get into the 12.1.&lt;/P&gt;&lt;P&gt;All thoughts welcome.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Nov 2010 15:27:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-failing/m-p/1551389#M274558</guid>
      <dc:creator>nikalleyne</dc:creator>
      <dc:date>2010-11-02T15:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization FAILING</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-failing/m-p/1551390#M274565</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nik&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am confused. In your original post you tell us the version of code on the box is 12.2(25r). Now in this post it seems that the problem is in 12.1. Perhaps you can clarify the issue of versions on the various boxes?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also it might help us to know whether the box that is having the problem ever worked? Or is this a new install for this box and it is having the problem from the beginning?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It may seem a bit obsessive, but can you verify that the box that does successfully authorize the user is using exactly the same radius server as the box that has the problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the same user authorizing to the same server works on one version and fails on another version, then it sounds like there may be some problem in the version. Is there any chance to put different code on the box that is having the problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Nov 2010 22:38:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-failing/m-p/1551390#M274565</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2010-11-02T22:38:25Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization FAILING</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-failing/m-p/1551391#M274570</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Burts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's look at it this way. I have the&amp;nbsp; following configuration on the 12.2 box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication attempts login 5&lt;/P&gt;&lt;P&gt;aaa authentication login myRADIUS GRoup Radius Local&lt;/P&gt;&lt;P&gt;aaa authorization exec default group radius local if-authenticated&lt;/P&gt;&lt;P&gt;aaa accounting exec myRADIUS start-stop group radius&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line vty 0 15&lt;/P&gt;&lt;P&gt;login authentication myRADIUS&lt;/P&gt;&lt;P&gt;session-timeout 15&lt;/P&gt;&lt;P&gt;exec-timeout 4 30&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above configuration works the way I want it to by allowing the user to go directly into Enable mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the configuration for the 12.1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login myRADIUS GRoup Radius Local&lt;/P&gt;&lt;P&gt;aaa accounting exec myRADIUS start-stop group radius&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line vty 0 15&lt;/P&gt;&lt;P&gt;login authentication myRADIUS&lt;/P&gt;&lt;P&gt;session-timeout 15&lt;/P&gt;&lt;P&gt;exec-timeout 4 30&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you may notice with the 12.1 config there is no "aaa authentication login myRADIUS GRoup Radius Local".&lt;/P&gt;&lt;P&gt;The reason for this is because once it is entered Authentication is successful but "Authorization Fails" and the user's session is closed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My only conclusion is this has to be an issue with the version of IOS because a capture from the 12.2 NAS and the 12.1 NAS communication with the RADIUS server returns the same result. They both have "Access-Accept" VSA: 19 t=Cisco-AVPair(1): shell:priv-lvl=15. So this tells me the&lt;/P&gt;&lt;P&gt;user is getting the correct information - as in priviledge level returned - when he/she authenticates but something else is causing the authorization to fail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this an issue with the 12.1 IOS because it's the same problemn on all the 12.1 devices I have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for verifying the same RADIUS they are both using the same box. As I mentioned above a capture at the RADIUS servers proves that they are.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this clears it up. I'm still hoping you guys can help me resolve this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Nov 2010 13:51:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-failing/m-p/1551391#M274570</guid>
      <dc:creator>nikalleyne</dc:creator>
      <dc:date>2010-11-03T13:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization FAILING</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-failing/m-p/1551392#M274574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nik&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am quite puzzled at part of this post. You say :"As you may notice with the 12.1 config there is no "aaa authentication login myRADIUS GRoup Radius Local".". But clearly that command is in the part of the config that you posted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But putting that part of the confusion aside, if it is the same lines of config (eliminating the possibility of something fat fingered), and if it consistently works with 12.2 and consistently does not work with 12.1 then it certainly suggests that there is a problem in the 12.1 code that you are running. I do not know what your maintenance situation is with these boxes, but I would suggest trying a different version of code on them and see if that resolves your problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do not remember the version of code, but I do remember some years ago I was installing several 5350 routers and was having problems with authorization, especially with the if-authenticated functionality. A change of code version was very successful in resolving my problem. I hope that might also be the case with your problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Nov 2010 17:13:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-failing/m-p/1551392#M274574</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2010-11-03T17:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization FAILING</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-failing/m-p/1551393#M274579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Burts,&lt;BR /&gt;First my apologies for the confusion. That should have been there is no "aaa authorization exec default group radius local if-authenticated" on the 12.1 config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Second I agree that we should upgrade and that will be the next project I will undertake. So I will mark your previous response as the answer and consider this case close.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the assistance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Nov 2010 17:29:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-failing/m-p/1551393#M274579</guid>
      <dc:creator>nikalleyne</dc:creator>
      <dc:date>2010-11-03T17:29:30Z</dc:date>
    </item>
  </channel>
</rss>

