<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA and VRF in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-and-vrf/m-p/1532413#M301711</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;Ok problem solved. &lt;/P&gt;&lt;P&gt;I don't know why but my Sup720-10G 12.2(33)SXH5 was sending the request throug Radius extended source-port. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1097078: Sep&amp;nbsp; 8 12:47:22: RADIUS(00000C82): Send Access-Request to X.X.X.X:1812 id &lt;STRONG&gt;21645&lt;/STRONG&gt;/118, len 81&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the server did not like it, thus rejecting the Authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Adding the hidden command in global config =&amp;gt; &lt;/P&gt;&lt;P&gt;"&lt;EM&gt;radius-server source-ports 1645-1646&lt;/EM&gt;" resolved the situation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The authentificaiton is now OK;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks anyway.&lt;/P&gt;&lt;P&gt;Kind regards.&lt;BR /&gt;Karim &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 09 Sep 2011 13:21:18 GMT</pubDate>
    <dc:creator>krahmani323</dc:creator>
    <dc:date>2011-09-09T13:21:18Z</dc:date>
    <item>
      <title>AAA and VRF</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-vrf/m-p/1532408#M301542</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have some problems with the VRF that I made and the radius verification.&lt;/P&gt;&lt;P&gt;The problem is that it's imposlible to make authentication through the radius server.&lt;/P&gt;&lt;P&gt;The debug output is :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;000103: Nov 17 14:26:02: RADIUS/ENCODE(00000004):Orig. component type = EXEC&lt;/P&gt;&lt;P&gt;000104: Nov 17 14:26:02: RADIUS:&amp;nbsp; AAA Unsupported Attr: interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [171] 4&lt;/P&gt;&lt;P&gt;000105: Nov 17 14:26:02: RADIUS:&amp;nbsp;&amp;nbsp; 74 74&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ tt]&lt;/P&gt;&lt;P&gt;000107: Nov 17 14:26:02: RADIUS(00000004): Config NAS IP: 0.0.0.0&lt;/P&gt;&lt;P&gt;000108: Nov 17 14:26:02: RADIUS/ENCODE(00000004): acct_session_id: 4&lt;/P&gt;&lt;P&gt;000109: Nov 17 14:26:02: RADIUS(00000004): sending&lt;/P&gt;&lt;P&gt;000110: Nov 17 14:26:02: RADIUS/ENCODE: Best Local IP-Address 192.168.1.50 for Radius-Server 192.168.1.10&lt;/P&gt;&lt;P&gt;000111: Nov 17 14:26:02: RADIUS: No secret to encode request (rctx:0x5935DF4)&lt;/P&gt;&lt;P&gt;000112: Nov 17 14:26:02: RADIUS: Unable to encrypt (rctx:0x5935DF4)&lt;/P&gt;&lt;P&gt;000113: Nov 17 14:26:02: RADIUS(00000004): Send Access-Request to 192.168.1.10:1645 id 1645/4, len 84&lt;/P&gt;&lt;P&gt;000114: Nov 17 14:26:02: RADIUS:&amp;nbsp; authenticator 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00&lt;/P&gt;&lt;P&gt;000115: Nov 17 14:26:02: RADIUS:&amp;nbsp; User-Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 8&amp;nbsp;&amp;nbsp; "****"&lt;/P&gt;&lt;P&gt;000116: Nov 17 14:26:02: RADIUS:&amp;nbsp; User-Password&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [2]&amp;nbsp;&amp;nbsp; 18&amp;nbsp; *&lt;/P&gt;&lt;P&gt;000117: Nov 17 14:26:02: RADIUS:&amp;nbsp; NAS-Port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [5]&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp; 2&lt;/P&gt;&lt;P&gt;000118: Nov 17 14:26:02: RADIUS:&amp;nbsp; NAS-Port-Id&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [87]&amp;nbsp; 6&amp;nbsp;&amp;nbsp; "tty2"&lt;/P&gt;&lt;P&gt;vpn003151ro110#&lt;/P&gt;&lt;P&gt;000119: Nov 17 14:26:02: RADIUS:&amp;nbsp; NAS-Port-Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [61]&amp;nbsp; 6&amp;nbsp;&amp;nbsp; Virtual&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [5]&lt;/P&gt;&lt;P&gt;000120: Nov 17 14:26:02: RADIUS:&amp;nbsp; Calling-Station-Id&amp;nbsp; [31]&amp;nbsp; 14&amp;nbsp; "192.168.1.20"&lt;/P&gt;&lt;P&gt;000121: Nov 17 14:26:02: RADIUS:&amp;nbsp; NAS-IP-Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [4]&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp; 192.168.1.50&lt;/P&gt;&lt;P&gt;000122: Nov 17 14:26:02: RADIUS(00000004): Started 5 sec timeout&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;000257: Nov 17 14:26:02: RADIUS: Retransmit to (192.168.1.10:1645,1646) for id 1645/8&lt;/P&gt;&lt;P&gt;000258: Nov 17 14:26:02: RADIUS(00000004): Started 5 sec timeout&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;000268: Nov 17 14:27:05: RADIUS: No response from (192.168.1.10:1645,1646) for id 1645/8&lt;/P&gt;&lt;P&gt;000269: Nov 17 14:27:05: RADIUS/DECODE: parse response no app start; FAIL&lt;/P&gt;&lt;P&gt;000270: Nov 17 14:27:05: RADIUS/DECODE: parse response; FAIL&lt;/P&gt; &lt;P&gt;&lt;/P&gt; &lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From witin the vrf I can ping the radius server. From the radius server I can ping the router &lt;/P&gt;&lt;P&gt;So I don't understand where it's gonig wrong&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The little config is :&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;aaa group server radius radius_1&lt;/P&gt;&lt;P&gt; server 192.168.1.10 auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt; ip vrf forwarding vpn01&lt;/P&gt;&lt;P&gt; ip radius source-interface Vlan200&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan 200&lt;/P&gt;&lt;P&gt; name vpn01&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan200&lt;/P&gt;&lt;P&gt; ip vrf forwarding vpn01&lt;/P&gt;&lt;P&gt; ip address 192.168.1.50 255.255.255.240&lt;/P&gt;&lt;P&gt; no ip redirects&lt;/P&gt;&lt;P&gt; no ip unreachables&lt;/P&gt;&lt;P&gt; no ip proxy-arp&lt;/P&gt;&lt;P&gt; ip ospf authentication-key 7 ********&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In global&lt;/P&gt;&lt;P&gt;radius-server host 192.168.1.10 auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route vrf vpn01 0.0.0.0 0.0.0.0 192.168.1.254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:35:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-vrf/m-p/1532408#M301542</guid>
      <dc:creator>Radek Zabicki</dc:creator>
      <dc:date>2019-03-11T00:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: AAA and VRF</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-vrf/m-p/1532409#M301547</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you check to see if the radius server is receiving the packets or not ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nicolas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Nov 2010 17:27:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-vrf/m-p/1532409#M301547</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2010-11-17T17:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: AAA and VRF</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-vrf/m-p/1532410#M301565</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Hello Radek, Nicolas, community,&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;I am currently experiencing the same exact issue...Trying to perform authentication on a 6500 12.2(33)SXH6 where multiple vrf are configured (vrf A can communicate with the radius)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My configuration is almost the same as yours with following difference :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In global &lt;/P&gt;&lt;P&gt;radius-server host x.x.x.x auth-port 1812 acct-port 1813 key string&lt;/P&gt;&lt;P&gt;(+ global ‘radius-server key string’)&lt;/P&gt;&lt;P&gt;ip radius source-interface vlan 10 vrf A&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The debug is similar as yours (file in attachments), the Radius does receives something but the authentication is denied and nothing is returned to the switch exaplaining the retransmission/timeout messages at the end (same secret and key double checked and validated) .&lt;/P&gt;&lt;P&gt;FYI it is working well for other 6500 without VRF in 12.2(33)SXI)….&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did your authentication issue solved, and if yes how ? Or any idea explaining this authentication problem ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestion will be appreciated !&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Karim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Sep 2011 22:35:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-vrf/m-p/1532410#M301565</guid>
      <dc:creator>krahmani323</dc:creator>
      <dc:date>2011-09-08T22:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: AAA and VRF</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-vrf/m-p/1532411#M301601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Troubleshooting path would be the same :&lt;/P&gt;&lt;P&gt;You say that the radius server receives the request. It then sends back an access-reject ? If yes, what is the failure reason marked on the radius server ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Sep 2011 05:22:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-vrf/m-p/1532411#M301601</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-09-09T05:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: AAA and VRF</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-vrf/m-p/1532412#M301645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Nicolas, &lt;/P&gt;&lt;P&gt;Many thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As stated the server receives the request, rejects it but the server does not send back an access-reject to the 6500...&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;================Server log===================================&lt;/P&gt;&lt;P&gt;[unix] invalid password "my_username"&lt;/P&gt;&lt;P&gt;++[unix] returns reject&lt;/P&gt;&lt;P&gt;Failed to authenticate the user.&lt;/P&gt;&lt;P&gt;WARNING: Unprintable characters in the password - Double-check the shared secret on the server and the NAS!&lt;/P&gt;&lt;P&gt;===================================================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is stucking me is the warning message in the server logs =&amp;gt; We DO use the same secret.&lt;/P&gt;&lt;P&gt;And the same user authenticates without any problem in other 6500 not using VRFs... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks anyway.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Karim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Sep 2011 08:44:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-vrf/m-p/1532412#M301645</guid>
      <dc:creator>krahmani323</dc:creator>
      <dc:date>2011-09-09T08:44:12Z</dc:date>
    </item>
    <item>
      <title>Re: AAA and VRF</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-vrf/m-p/1532413#M301711</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;Ok problem solved. &lt;/P&gt;&lt;P&gt;I don't know why but my Sup720-10G 12.2(33)SXH5 was sending the request throug Radius extended source-port. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1097078: Sep&amp;nbsp; 8 12:47:22: RADIUS(00000C82): Send Access-Request to X.X.X.X:1812 id &lt;STRONG&gt;21645&lt;/STRONG&gt;/118, len 81&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the server did not like it, thus rejecting the Authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Adding the hidden command in global config =&amp;gt; &lt;/P&gt;&lt;P&gt;"&lt;EM&gt;radius-server source-ports 1645-1646&lt;/EM&gt;" resolved the situation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The authentificaiton is now OK;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks anyway.&lt;/P&gt;&lt;P&gt;Kind regards.&lt;BR /&gt;Karim &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Sep 2011 13:21:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-vrf/m-p/1532413#M301711</guid>
      <dc:creator>krahmani323</dc:creator>
      <dc:date>2011-09-09T13:21:18Z</dc:date>
    </item>
  </channel>
</rss>

