<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: &amp;quot;ip radius source loop0&amp;quot; not working for enable? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/quot-ip-radius-source-loop0-quot-not-working-for-enable/m-p/1183981#M405494</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is not a radius source issue. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enable authentication was actually designed to work with TACACS. In IOS devices when we do "enable" authentication using the Radius protocol, the username sent to Radius Server (ACS), is not the one with which you logged in. It is "$enab15$", if you check the failed logs, I am sure you'll see that username. In case of Radius you would be required to create a user account with the username "$enab15$" and use the password for this account to be able to log into enable privilege mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Apr 2009 20:03:01 GMT</pubDate>
    <dc:creator>Jagdeep Gambhir</dc:creator>
    <dc:date>2009-04-09T20:03:01Z</dc:date>
    <item>
      <title>"ip radius source loop0" not working for enable?</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-ip-radius-source-loop0-quot-not-working-for-enable/m-p/1183980#M405493</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have recently upgraded one of our routers to version 12.2SR.&lt;/P&gt;&lt;P&gt;One of the problems we are facing is that radius authentication is not working correcly for the enable part.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using loopback address as a source.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip radius source-interface Loopback0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;while for the user authentication the request from the router is using the loopback address, for the enable is using the physical address!!! we tried to remove and add all the aaa commands but same thing. This is not the case for older version i.e. 12.2SX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Find below the aaa and radius commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login my_radius group radius local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication enable default group radius enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;no cns aaa enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login my_radius group radius local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication enable default group radius enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip radius source-interface Loopback0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;radius-server host 1.1.1.1 auth-port 1812 acct-port 1813 key 7 xxxxxxxxxx&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:25:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-ip-radius-source-loop0-quot-not-working-for-enable/m-p/1183980#M405493</guid>
      <dc:creator>pavlosd</dc:creator>
      <dc:date>2019-03-10T23:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: "ip radius source loop0" not working for enable?</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-ip-radius-source-loop0-quot-not-working-for-enable/m-p/1183981#M405494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is not a radius source issue. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enable authentication was actually designed to work with TACACS. In IOS devices when we do "enable" authentication using the Radius protocol, the username sent to Radius Server (ACS), is not the one with which you logged in. It is "$enab15$", if you check the failed logs, I am sure you'll see that username. In case of Radius you would be required to create a user account with the username "$enab15$" and use the password for this account to be able to log into enable privilege mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Apr 2009 20:03:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-ip-radius-source-loop0-quot-not-working-for-enable/m-p/1183981#M405494</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2009-04-09T20:03:01Z</dc:date>
    </item>
    <item>
      <title>Re: "ip radius source loop0" not working for enable?</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-ip-radius-source-loop0-quot-not-working-for-enable/m-p/1183982#M405495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi JG,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have already defined the "$enab15$" user. As I told you, the problem is that user authentication is using loopback address as a source, while enable is using local interface address. I can confirm this because, we added local address to the radius, till we sort out the problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Apr 2009 12:08:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-ip-radius-source-loop0-quot-not-working-for-enable/m-p/1183982#M405495</guid>
      <dc:creator>pavlosd</dc:creator>
      <dc:date>2009-04-15T12:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: "ip radius source loop0" not working for enable?</title>
      <link>https://community.cisco.com/t5/network-access-control/quot-ip-radius-source-loop0-quot-not-working-for-enable/m-p/1183983#M405496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;It seems we are hitting this bug,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip radius source-interface ignored during enable authentication &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?caller=pluginredirector&amp;amp;method=fetchBugDetails&amp;amp;bugId=CSCsg01035" target="_blank"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?caller=pluginredirector&amp;amp;method=fetchBugDetails&amp;amp;bugId=CSCsg01035&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Apr 2009 15:20:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/quot-ip-radius-source-loop0-quot-not-working-for-enable/m-p/1183983#M405496</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2009-04-15T15:20:10Z</dc:date>
    </item>
  </channel>
</rss>

