<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA Session Context Error in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-session-context-error/m-p/1103109#M364559</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My Issue is fixed now &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "aaa session-id common" command was enabled already . But my Issue was different &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got two interfaces from NAS going to two different switches and both were seeing as two different NAS by radius . So sometimes the radius request go from one interface and comes from another interface and it was conflicting the session . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per Cisco , For a call to be disconnected, all parameters must match their expected values at the gateway. If the parameters do not match, the gateway discards the packet of disconnect packet and sends a NACK (negative acknowledgement message) to the agent &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.faqs.org/rfcs/rfc2882.html" target="_blank"&gt;http://www.faqs.org/rfcs/rfc2882.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Haris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 14 Dec 2008 08:28:15 GMT</pubDate>
    <dc:creator>Haris P</dc:creator>
    <dc:date>2008-12-14T08:28:15Z</dc:date>
    <item>
      <title>AAA Session Context Error</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-session-context-error/m-p/1103107#M364557</link>
      <description>&lt;P&gt;Dear Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using Cisco 7301 as our NAS for our DSL users and a third party software as Radius &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We configured PoD radius server for our DSL . But it seems that radius can't remove the users from the NAS . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following is the error &lt;/P&gt;&lt;P&gt;Dec 7 20:33:27.547: POD: Added Reply Message: No Matching Session &lt;/P&gt;&lt;P&gt;Dec 7 20:33:27.547: POD: Added NACK Error Cause: Session Context Not Found &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following is my config &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa server radius dynamic-author &lt;/P&gt;&lt;P&gt;client &amp;lt;radius ip address&amp;gt; &lt;/P&gt;&lt;P&gt;server-key cisco &lt;/P&gt;&lt;P&gt;auth-type any &lt;/P&gt;&lt;P&gt;ignore session-key &lt;/P&gt;&lt;P&gt;ignore server-key &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa pod server auth-type any server-key cisco &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards &lt;/P&gt;&lt;P&gt;Haris&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:13:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-session-context-error/m-p/1103107#M364557</guid>
      <dc:creator>Haris P</dc:creator>
      <dc:date>2019-03-10T23:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Session Context Error</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-session-context-error/m-p/1103108#M364558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The work around, to avoid this failure, is "aaa session-id common" needs to be enabled.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Dec 2008 22:37:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-session-context-error/m-p/1103108#M364558</guid>
      <dc:creator>wdrootz</dc:creator>
      <dc:date>2008-12-12T22:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Session Context Error</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-session-context-error/m-p/1103109#M364559</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My Issue is fixed now &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "aaa session-id common" command was enabled already . But my Issue was different &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got two interfaces from NAS going to two different switches and both were seeing as two different NAS by radius . So sometimes the radius request go from one interface and comes from another interface and it was conflicting the session . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per Cisco , For a call to be disconnected, all parameters must match their expected values at the gateway. If the parameters do not match, the gateway discards the packet of disconnect packet and sends a NACK (negative acknowledgement message) to the agent &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.faqs.org/rfcs/rfc2882.html" target="_blank"&gt;http://www.faqs.org/rfcs/rfc2882.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Haris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 Dec 2008 08:28:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-session-context-error/m-p/1103109#M364559</guid>
      <dc:creator>Haris P</dc:creator>
      <dc:date>2008-12-14T08:28:15Z</dc:date>
    </item>
    <item>
      <title>Add below mentioned commands</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-session-context-error/m-p/1103110#M364560</link>
      <description>&lt;P&gt;Add below mentioned commands under aaa config of cisco router&lt;/P&gt;
&lt;P style="font-size: 14px;"&gt;ignore session-key&lt;/P&gt;
&lt;P style="font-size: 14px;"&gt;ignore server-key&lt;/P&gt;
&lt;P style="font-size: 14px;"&gt;post it freeradius will start disconnection active sessions on cisco NAS.&lt;/P&gt;
&lt;P style="font-size: 14px;"&gt;Freeradius config.NAS IP( 10.0.0.1)&lt;/P&gt;

&lt;PRE style="margin-top: 15px; margin-bottom: 15px; padding: 6px 10px; font-family: Consolas, 'Liberation Mono', Courier, monospace; border-color: rgb(204, 204, 204); line-height: 19px; overflow: auto; border-top-left-radius: 3px; border-top-right-radius: 3px; border-bottom-right-radius: 3px; border-bottom-left-radius: 3px; background-color: rgb(248, 248, 248);"&gt;
# echo "Acct-Session-Id=D91FE8E51802097" &amp;gt; packet.txt
# echo "User-Name=somebody" &amp;gt;&amp;gt; packet.txt
# echo "NAS-IP-Address=10.0.0.1" &amp;gt;&amp;gt; packet.txt

# cat packet.txt | radclient -x 10.0.0.1:3799 disconnect ''secret''

Sending Disconnect-Request of id 214 to 10.0.0.1 port 3799
      Acct-Session-Id = "D91FE8E51802097"
      User-Name = "somebody"
      NAS-IP-Address = 10.0.0.1
rad_recv: Disconnect-ACK packet from host 10.0.0.1 port 3799, id=214, length=20
&lt;/PRE&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jun 2014 14:26:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-session-context-error/m-p/1103110#M364560</guid>
      <dc:creator>novanetinc</dc:creator>
      <dc:date>2014-06-09T14:26:50Z</dc:date>
    </item>
  </channel>
</rss>

