<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 5.2 selection policy/access service attribute question in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-2-selection-policy-access-service-attribute-question/m-p/1625983#M325695</link>
    <description>&lt;P&gt;hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i'm using ACS 5.2.0.26 and have created Service Selection Policys to authenticate wireless PEAP clients based on the domain suffix used by the clients. if i use the RADIUS attribute RADIUS-IETF:User-Name to do this, am i right in saying that this matches the "Roaming Identity" as opposed to the users actual login id?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under Access Services i can use the attribute System:UserName which does match based on the clients actual login id . My questions are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the RADIUS-IETF:User-Name attribute match "Roaming Identity"?&lt;/P&gt;&lt;P&gt;I can use the System:UserName attribute with an Access Service but not it seems with a Service Selection Policy. Why is this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 00:40:05 GMT</pubDate>
    <dc:creator>andrewswanson</dc:creator>
    <dc:date>2019-03-11T00:40:05Z</dc:date>
    <item>
      <title>ACS 5.2 selection policy/access service attribute question</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-selection-policy-access-service-attribute-question/m-p/1625983#M325695</link>
      <description>&lt;P&gt;hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i'm using ACS 5.2.0.26 and have created Service Selection Policys to authenticate wireless PEAP clients based on the domain suffix used by the clients. if i use the RADIUS attribute RADIUS-IETF:User-Name to do this, am i right in saying that this matches the "Roaming Identity" as opposed to the users actual login id?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Under Access Services i can use the attribute System:UserName which does match based on the clients actual login id . My questions are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the RADIUS-IETF:User-Name attribute match "Roaming Identity"?&lt;/P&gt;&lt;P&gt;I can use the System:UserName attribute with an Access Service but not it seems with a Service Selection Policy. Why is this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:40:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-selection-policy-access-service-attribute-question/m-p/1625983#M325695</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2019-03-11T00:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 selection policy/access service attribute question</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-selection-policy-access-service-attribute-question/m-p/1625984#M325726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the RADIUS-IETF:User-Name attribute match "Roaming Identity"?&lt;/P&gt;&lt;P&gt;-&amp;gt; No.The roaming identity is particular to some supplicants and do not always match the username.&lt;/P&gt;&lt;P&gt; If the Roaming Identity is cleared, %domain%\%username% is the default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;&lt;P&gt;When 802.1x MS RADIUS is used as an authentication server, the server authenticates the device that uses the Roaming Identity user name from Intel PROSet/Wireless software, and ignores the Authentication Protocol MS-CHAP-V2&amp;nbsp; user name. This feature is the 802.1x identity supplied to the&amp;nbsp; authenticator. Microsoft IAS RADIUS accepts only a valid user name&amp;nbsp; (dotNet user) for EAP clients. When 802.1x MS RADIUS is used, enter a&amp;nbsp; valid user name. For all other servers, this is optional. Therefore, it&amp;nbsp; is recommended to use the desired realm (for example, anonymous@myrealm)&amp;nbsp; instead of a true identity.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can use the System:UserName attribute with an Access Service but not it seems with a Service Selection Policy. Why is this?&lt;/P&gt;&lt;P&gt;-&amp;gt; Because that attribute is not valid for Service selection Policy. It was designed this way...nothing we can do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;BR /&gt;Tiago&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Dec 2010 14:03:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-selection-policy-access-service-attribute-question/m-p/1625984#M325726</guid>
      <dc:creator>Tiago Antunes</dc:creator>
      <dc:date>2010-12-22T14:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 selection policy/access service attribute question</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-selection-policy-access-service-attribute-question/m-p/1625985#M325800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the quick and thorough response - yes, i am using Intel PROSet on the client. So is the System:UserName attibute on the ACS always the users correct username regardless of the suplicant used?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;andy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Dec 2010 14:19:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-selection-policy-access-service-attribute-question/m-p/1625985#M325800</guid>
      <dc:creator>andrewswanson</dc:creator>
      <dc:date>2010-12-22T14:19:05Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.2 selection policy/access service attribute question</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-2-selection-policy-access-service-attribute-question/m-p/1625986#M325876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That attribute will contain the username searched on the Identity Sources for authentication, regardless of the supplicant software.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;BR /&gt;Tiago&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 08:34:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-2-selection-policy-access-service-attribute-question/m-p/1625986#M325876</guid>
      <dc:creator>Tiago Antunes</dc:creator>
      <dc:date>2010-12-23T08:34:52Z</dc:date>
    </item>
  </channel>
</rss>

