<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: as5300 not sending username to radius in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/as5300-not-sending-username-to-radius/m-p/1438309#M351675</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Athiqur,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Consider, if you haven't recievded any solution on this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;If you are not seeing radius access request coming from the AS5300 that means its not trying to communicate over UDP port 1812 that what we have configured on the free radius server.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Could you please issue the below listed command and see if that helps;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;radius-server host &lt;IP-ADDRESS&gt; auth-port 1812 acct-port 1813 key &lt;KEY&gt;&lt;/KEY&gt;&lt;/IP-ADDRESS&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Command refrence;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/ios/12_3t/secur/command/reference/sec_r1gt.html#wp1173811"&gt;http://www.cisco.com/en/US/docs/ios/12_3t/secur/command/reference/sec_r1gt.html#wp1173811&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Also if that doesn't help, please provide me the o/p of the following debugs;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;debug aaa authentication&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;debug radius&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;term mon&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Also send me the "Sh Run" from the IOS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Regds,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;JK&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Do rate helpul posts-&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 16 May 2010 07:32:13 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2010-05-16T07:32:13Z</dc:date>
    <item>
      <title>as5300 not sending username to radius</title>
      <link>https://community.cisco.com/t5/network-access-control/as5300-not-sending-username-to-radius/m-p/1438308#M351630</link>
      <description>&lt;P&gt;I have an AS5300 IOS (tm) 5300 Software (C5300-I-M), Version 12.2(16) using it as RAS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using&amp;nbsp; FreeRADIUS Version 2.1.8 for accounting puposes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem I am facing is that when opening a ppp dial up connection to the as5300, it is not sending the username. I need the as5300 to send the username so that a realm can be matched.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is snippet of debug output from FreeRadius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rad_recv: Accounting-Request packet from host 192.168.0.57 port 1646, id=211, length=97&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NAS-IP-Address = 192.168.0.57&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NAS-Port = 182&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NAS-Port-Type = Async&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Called-Station-Id = "02081131234"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Calling-Station-Id = "2075176623"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct-Status-Type = Start&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Service-Type = Framed-User&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct-Session-Id = "0000006E"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Framed-Protocol = PPP&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Acct-Delay-Time = 0&lt;BR /&gt;+- entering group preacct {...}&lt;BR /&gt;++[preprocess] returns ok&lt;BR /&gt;&lt;STRONG&gt;[acct_unique] WARNING: Attribute User-Name was not found in request, unique ID MAY be inconsistent &lt;/STRONG&gt;&lt;BR /&gt;[acct_unique] Hashing 'NAS-Port = 182,Client-IP-Address = 192.168.0.57,NAS-IP-Address = 217.73.64.57,Acct-Session-Id = "0000006E",'&lt;BR /&gt;[acct_unique] Acct-Unique-Session-ID = "93340c227b9a5bca".&lt;BR /&gt;++[acct_unique] returns ok&lt;BR /&gt;[suffix] Proxy reply, or no User-Name.&amp;nbsp; Ignoring.&lt;BR /&gt;++[suffix] returns ok&lt;BR /&gt;++[files] returns noop&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is my AAA config from my cisco&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;BR /&gt;aaa authentication login default local&lt;BR /&gt;aaa authentication ppp default group radius&lt;BR /&gt;aaa authorization network default none&lt;BR /&gt;aaa accounting send stop-record authentication failure&lt;BR /&gt;aaa accounting network default start-stop group radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tested with radtest with username testing@secureroot and i get the following output which does ffind the username and thus the realm. this indicates to me that there is nothing wrong with my freeradius config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;rad_recv: Access-Request packet from host 127.0.0.1 port 37443, id=212, length=67&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User-Name = "testing@secureroot"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User-Password = "mypassword"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NAS-IP-Address = 217.73.64.75&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NAS-Port = 1812&lt;BR /&gt;+- entering group authorize {...}&lt;BR /&gt;++[preprocess] returns ok&lt;BR /&gt;++[chap] returns noop&lt;BR /&gt;++[mschap] returns noop&lt;BR /&gt;[suffix] Looking up realm "secureroot" for User-Name = "testing@secureroot"&lt;BR /&gt;[suffix] Found realm "secureroot"&lt;BR /&gt;[suffix] Adding Stripped-User-Name = "testing"&lt;BR /&gt;[suffix] Adding Realm = "secureroot"&lt;BR /&gt;[suffix] Authentication realm is LOCAL.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;i have done tcpdump of my successful radtest and it looks like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;15:12:42.183076 IP 87.102.106.147.43340 &amp;gt; 217.73.64.75.1812: RADIUS, Access Request (1), id: 0x64 length: 67&lt;BR /&gt;15:12:42.183079 IP 217.73.64.75.1812 &amp;gt; 87.102.106.147.43340: RADIUS, Access Accept (2), id: 0x64 length: 62&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;below is the tcpdump of the cisco communicating with the radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;14:29:59.998964 IP 217.73.64.57.1646 &amp;gt; 217.73.64.75.1813: RADIUS, Accounting Request (4), id: 0xe3 length: 97&lt;BR /&gt;14:30:00.003907 IP 217.73.64.75.1813 &amp;gt; 217.73.64.57.1646: RADIUS, Accounting Response (5), id: 0xe3 length: 20&lt;BR /&gt;14:30:12.061861 IP 217.73.64.57.1646 &amp;gt; 217.73.64.75.1813: RADIUS, Accounting Request (4), id: 0xe4 length: 150&lt;BR /&gt;14:30:12.063124 IP 217.73.64.75.1813 &amp;gt; 217.73.64.57.1646: RADIUS, Accounting Response (5), id: 0xe4 length: 20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The tcpdump shows that when opening ppp connection to the cisco it is not sending any access requests to port 1812, only accounting packets. Somethinge definitely wrong with the config on the cisco.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am thinking i have missed something simple&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:07:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/as5300-not-sending-username-to-radius/m-p/1438308#M351630</guid>
      <dc:creator>Athiqur Rahman</dc:creator>
      <dc:date>2019-03-11T00:07:35Z</dc:date>
    </item>
    <item>
      <title>Re: as5300 not sending username to radius</title>
      <link>https://community.cisco.com/t5/network-access-control/as5300-not-sending-username-to-radius/m-p/1438309#M351675</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Athiqur,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Consider, if you haven't recievded any solution on this.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;If you are not seeing radius access request coming from the AS5300 that means its not trying to communicate over UDP port 1812 that what we have configured on the free radius server.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Could you please issue the below listed command and see if that helps;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;radius-server host &lt;IP-ADDRESS&gt; auth-port 1812 acct-port 1813 key &lt;KEY&gt;&lt;/KEY&gt;&lt;/IP-ADDRESS&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Command refrence;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/ios/12_3t/secur/command/reference/sec_r1gt.html#wp1173811"&gt;http://www.cisco.com/en/US/docs/ios/12_3t/secur/command/reference/sec_r1gt.html#wp1173811&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Also if that doesn't help, please provide me the o/p of the following debugs;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;debug aaa authentication&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;debug radius&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;term mon&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Also send me the "Sh Run" from the IOS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Regds,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;JK&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Do rate helpul posts-&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 May 2010 07:32:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/as5300-not-sending-username-to-radius/m-p/1438309#M351675</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2010-05-16T07:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: as5300 not sending username to radius</title>
      <link>https://community.cisco.com/t5/network-access-control/as5300-not-sending-username-to-radius/m-p/1438310#M351720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, but I have solved the problem. The cisco was not sending requests to radius becuase I was missing the line&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ppp authentication chap pap&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in the Dialer interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 May 2010 08:14:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/as5300-not-sending-username-to-radius/m-p/1438310#M351720</guid>
      <dc:creator>Athiqur Rahman</dc:creator>
      <dc:date>2010-05-17T08:14:49Z</dc:date>
    </item>
  </channel>
</rss>

