<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can you show us the AAA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/openldap-freeradius-and-authentication-authorization/m-p/2860267#M36886</link>
    <description>&lt;P&gt;Can you show us the AAA configuration on your router? I suspect you're missing exec authorization.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Javier Henderson&lt;/P&gt;
&lt;P&gt;Cisco Systems&lt;/P&gt;</description>
    <pubDate>Fri, 01 Apr 2016 11:42:10 GMT</pubDate>
    <dc:creator>Javier Henderson</dc:creator>
    <dc:date>2016-04-01T11:42:10Z</dc:date>
    <item>
      <title>OpenLDAP / FreeRadius and authentication/authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/openldap-freeradius-and-authentication-authorization/m-p/2860266#M36884</link>
      <description>&lt;P&gt;I have a what I consider to be an issue. &amp;nbsp;I'm running OpenLDAP integrated with FreeRadius and I have a NetworkAdmins group configured. &amp;nbsp;This group, I want to have full priv15 and the users should drop into enable mode upon their initial successful log in. &amp;nbsp;I've added the below to the /etc/raddb/users file but for some reason it still asks for an enable password.&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;Service-Type = NAS-Prompt-User,&lt;BR /&gt;        cisco-avpair :="shell:priv-lvl=15"&lt;/PRE&gt;
&lt;P&gt;I have it working to where &amp;nbsp;the user can authenticate into enable/exec mode but that only works when I create a user "$enab15$" and a password. &amp;nbsp;It appears when you type enable in the cisco it sends another authentication request to FreeRadius with that name. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;My goal is to have two LDAP groups&lt;/P&gt;
&lt;P&gt;1. NetworkAdmins - privilege level 15&lt;/P&gt;
&lt;P&gt;2. NetworkOperators - privilege level&amp;nbsp;1&lt;/P&gt;
&lt;P&gt;There has to be a way to do this.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any suggestions?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:37:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/openldap-freeradius-and-authentication-authorization/m-p/2860266#M36884</guid>
      <dc:creator>ppalmerjr</dc:creator>
      <dc:date>2019-03-11T06:37:56Z</dc:date>
    </item>
    <item>
      <title>Can you show us the AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/openldap-freeradius-and-authentication-authorization/m-p/2860267#M36886</link>
      <description>&lt;P&gt;Can you show us the AAA configuration on your router? I suspect you're missing exec authorization.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Javier Henderson&lt;/P&gt;
&lt;P&gt;Cisco Systems&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2016 11:42:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/openldap-freeradius-and-authentication-authorization/m-p/2860267#M36886</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2016-04-01T11:42:10Z</dc:date>
    </item>
    <item>
      <title>I do have that command...and</title>
      <link>https://community.cisco.com/t5/network-access-control/openldap-freeradius-and-authentication-authorization/m-p/2860268#M36887</link>
      <description>&lt;P&gt;I do have that command...and I figured out what the issue was. &amp;nbsp;Here it is....&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I had to do the following in the /etc/raddb/users file&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;DEFAULT LDAP-Group := NetworkAdmins &amp;nbsp; &amp;lt;----this is your LDAP group to be allowed&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;Server-Type = NAS-Prompt-Users,&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;cisco-avpair = "shell:priv-lvl=15"&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;From here I'm going to add another LDAP group with level 1 and see if I can get that to work.&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;Thanks for your response!&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2016 15:06:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/openldap-freeradius-and-authentication-authorization/m-p/2860268#M36887</guid>
      <dc:creator>ppalmerjr</dc:creator>
      <dc:date>2016-04-01T15:06:18Z</dc:date>
    </item>
  </channel>
</rss>

