<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Windows 2012 Radius failed authorization on ASA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/windows-2012-radius-failed-authorization-on-asa/m-p/3002458#M38429</link>
    <description>&lt;P&gt;Hello experts&lt;/P&gt;
&lt;P&gt;I have a Windows 2012 Radius server setup for my ASA(ver 9.4). First I used service type NAS Prompt, then when tested on the ASA against the Radius server, authentication was successful, but authorization failed, error authorization rejected: AAA failed. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then I changed Radius to use service-type LOGIN, then test on ASA was successful for both authorization and authentication, but when I used aaa authorization &lt;G class="gr_ gr_383 gr-alert gr_spell gr_run_anim ContextualSpelling ins-del multiReplace" id="383" data-gr-id="383"&gt;http&lt;/G&gt;&amp;nbsp;console RADIUS, I still&amp;nbsp;got authorization rejected error.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can someone please give me a guild of how to use WIN Radius server for ASA authorization(not authentication)?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks a lot.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 07:03:42 GMT</pubDate>
    <dc:creator>rhienwei2010</dc:creator>
    <dc:date>2019-03-11T07:03:42Z</dc:date>
    <item>
      <title>Windows 2012 Radius failed authorization on ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-2012-radius-failed-authorization-on-asa/m-p/3002458#M38429</link>
      <description>&lt;P&gt;Hello experts&lt;/P&gt;
&lt;P&gt;I have a Windows 2012 Radius server setup for my ASA(ver 9.4). First I used service type NAS Prompt, then when tested on the ASA against the Radius server, authentication was successful, but authorization failed, error authorization rejected: AAA failed. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then I changed Radius to use service-type LOGIN, then test on ASA was successful for both authorization and authentication, but when I used aaa authorization &lt;G class="gr_ gr_383 gr-alert gr_spell gr_run_anim ContextualSpelling ins-del multiReplace" id="383" data-gr-id="383"&gt;http&lt;/G&gt;&amp;nbsp;console RADIUS, I still&amp;nbsp;got authorization rejected error.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can someone please give me a guild of how to use WIN Radius server for ASA authorization(not authentication)?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks a lot.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:03:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-2012-radius-failed-authorization-on-asa/m-p/3002458#M38429</guid>
      <dc:creator>rhienwei2010</dc:creator>
      <dc:date>2019-03-11T07:03:42Z</dc:date>
    </item>
    <item>
      <title>Similar issue here.  I had a</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-2012-radius-failed-authorization-on-asa/m-p/3002459#M38430</link>
      <description>&lt;P&gt;Similar issue here. &amp;nbsp;I had a working AAA configuration with RADIUS and Win 2012 on IOS 9.1.6. &amp;nbsp;I just upgraded to 9.4.4 and it stopped working. &amp;nbsp;I found that if I disable aaa authorization entirely, the authentication and accounting pieces work.&lt;/P&gt;
&lt;P&gt;Also of interest is ssh to the CLI never stopped working with all three "AAA's" configured. &amp;nbsp;This only impacted http (ASDM). &amp;nbsp;Bug in 9.4?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 20:09:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-2012-radius-failed-authorization-on-asa/m-p/3002459#M38430</guid>
      <dc:creator>ramos1</dc:creator>
      <dc:date>2017-03-30T20:09:33Z</dc:date>
    </item>
    <item>
      <title>Hello,</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-2012-radius-failed-authorization-on-asa/m-p/3002460#M38431</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Have you found solution for this issue?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Gabor&lt;/P&gt;</description>
      <pubDate>Sun, 02 Apr 2017 20:47:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-2012-radius-failed-authorization-on-asa/m-p/3002460#M38431</guid>
      <dc:creator>gbercsenyi</dc:creator>
      <dc:date>2017-04-02T20:47:30Z</dc:date>
    </item>
    <item>
      <title>Same issue here, too. Running</title>
      <link>https://community.cisco.com/t5/network-access-control/windows-2012-radius-failed-authorization-on-asa/m-p/3002461#M38432</link>
      <description>&lt;P&gt;Same issue here, too. Running ASA 9.5(2) and ASDM 7.7(1)151.&lt;/P&gt;
&lt;P&gt;Also, I'm using service-type ADMINISTRATIVE. This was the only setting that would give me automatic authorization (to enable mode) in SSH. When logging into ASDM, it will authenticate but fails the authorization.&lt;/P&gt;
&lt;P&gt;No resolution found yet.&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2017 19:22:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/windows-2012-radius-failed-authorization-on-asa/m-p/3002461#M38432</guid>
      <dc:creator>rhdoughten</dc:creator>
      <dc:date>2017-05-04T19:22:12Z</dc:date>
    </item>
  </channel>
</rss>

