<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multiple shell AVPair entries in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/multiple-shell-avpair-entries/m-p/1181758#M400438</link>
    <description>&lt;P&gt;Is it possible to have muplitple Radius shell: AVPair entries for a single user/profile?  I want to be able to use 'shell:priv-lvl=15' to manage our switches and 'shell:Admin=Admin default-domain' to manage our ACE's.  What I am finding is that when I configure both I cannot get into our switches.  Also is there a document that explains how cisco devices process the radius attributes?  Thanks.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 23:18:25 GMT</pubDate>
    <dc:creator>jrbeining</dc:creator>
    <dc:date>2019-03-10T23:18:25Z</dc:date>
    <item>
      <title>Multiple shell AVPair entries</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-shell-avpair-entries/m-p/1181758#M400438</link>
      <description>&lt;P&gt;Is it possible to have muplitple Radius shell: AVPair entries for a single user/profile?  I want to be able to use 'shell:priv-lvl=15' to manage our switches and 'shell:Admin=Admin default-domain' to manage our ACE's.  What I am finding is that when I configure both I cannot get into our switches.  Also is there a document that explains how cisco devices process the radius attributes?  Thanks.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:18:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-shell-avpair-entries/m-p/1181758#M400438</guid>
      <dc:creator>jrbeining</dc:creator>
      <dc:date>2019-03-10T23:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple shell AVPair entries</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-shell-avpair-entries/m-p/1181759#M400439</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From an ACS and purely RADIUS perspective - yes this fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As to what the switch does - anyone's guess as this stuff is rarely documented. I've trawled CCO many times to find which cisco-av-pairs exist let alone which devices support them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can get some low level AAA debug off the switch you might find what its doing with the av-pairs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck! &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jan 2009 20:56:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-shell-avpair-entries/m-p/1181759#M400439</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2009-01-27T20:56:34Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple shell AVPair entries</title>
      <link>https://community.cisco.com/t5/network-access-control/multiple-shell-avpair-entries/m-p/1181760#M400440</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The switches were complaining about an unknown mandatory AV:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jan 28 10:12:57.633 PST: AAA/AUTHOR/EXEC: received unknown mandatory AV: Admin=Admin default-domain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to resolve this I defined the AV as optional with a '*' instead of an '=':&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;shell:Admin*Admin default-domain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Joshua&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Jan 2009 18:29:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multiple-shell-avpair-entries/m-p/1181760#M400440</guid>
      <dc:creator>jrbeining</dc:creator>
      <dc:date>2009-01-28T18:29:11Z</dc:date>
    </item>
  </channel>
</rss>

