<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RADIUS Authorization Components (RAC) doesn't work on ACS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/radius-authorization-components-rac-doesn-t-work-on-acs/m-p/748307#M421020</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, I've solved the problem: you need to set the ePo server as the "default-gateway" for your Quarantine-VLAN. Otherwise, the client cannot connect for some reason with it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So this topic can be marked as solved.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Apr 2007 10:18:50 GMT</pubDate>
    <dc:creator />
    <dc:date>2007-04-20T10:18:50Z</dc:date>
    <item>
      <title>RADIUS Authorization Components (RAC) doesn't work on ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authorization-components-rac-doesn-t-work-on-acs/m-p/748302#M421015</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have made a shared RAC where I defined the following RADIUS attributes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tunnel-type: VLAN&lt;/P&gt;&lt;P&gt;Tunnel-medium-type: 802&lt;/P&gt;&lt;P&gt;Tunnel-Private-Group-ID: QuarantineVLAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So with this RAC I want to chance the VLAN from a user that is Quarantined.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in the NAP (Network Access Profiles) in the Authorization section, I added a rule that links the Quarantine Posture State with this RAC. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But even though the Quarantine state is returned by the Trust Agent (so the posture state is definitely Quarantine), the host stays in it's original VLAN instead of the Quarantine VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone who knows a solution?&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:06:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authorization-components-rac-doesn-t-work-on-acs/m-p/748302#M421015</guid>
      <dc:creator>admin_2</dc:creator>
      <dc:date>2019-03-10T22:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: RADIUS Authorization Components (RAC) doesn't work on ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authorization-components-rac-doesn-t-work-on-acs/m-p/748303#M421016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try using the vlan number instead of vlan name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vivek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2007 14:34:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authorization-components-rac-doesn-t-work-on-acs/m-p/748303#M421016</guid>
      <dc:creator>Vivek Santuka</dc:creator>
      <dc:date>2007-04-17T14:34:51Z</dc:date>
    </item>
    <item>
      <title>Re: RADIUS Authorization Components (RAC) doesn't work on ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authorization-components-rac-doesn-t-work-on-acs/m-p/748304#M421017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vsauntuka,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;first of all thank you for the quick response!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tried this but unfortunately, it doesn't seem to work...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the switch, this is my configuration for the fastethernet port where the client is on:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  interface fa0/17&lt;/P&gt;&lt;P&gt;  switchport mode access&lt;/P&gt;&lt;P&gt;  dot1x port-control auto&lt;/P&gt;&lt;P&gt;  spanning-tree portfast&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I debug on the switch (using "debug radius" ) I can see (for example) that the radius attribute with number 81 (tunnel-private-group-ID) is sent, but because of the encryption i guess I cannot understand the values that are sent with it ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Apr 2007 13:49:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authorization-components-rac-doesn-t-work-on-acs/m-p/748304#M421017</guid>
      <dc:creator />
      <dc:date>2007-04-18T13:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: RADIUS Authorization Components (RAC) doesn't work on ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authorization-components-rac-doesn-t-work-on-acs/m-p/748305#M421018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found out that the attributes aren't working at all. They also don't work in the group settings. (I thought it worked before but that was because I already assigned the vlan to the switchports via the command "switchport access vlan 8"). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've checked those attributes to be registered in the RADIUS accounting-log, but they never have values in the log, only three dots instead.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sometimes, with the command "debug radius", I can see these attributes (64: tunnel-type, 65: tunnel-medium-type and 81: tunnel-private-group-ID).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've tried to make a new user who has the same per-user attributes and then debug on the switch with "debug aaa per-user" but this debugging doesn't return anything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So it looks like the switch receives those attributes from the ACS server but they don't change the VLAN. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An example of the debug output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;attribute 64 6 0000000B&lt;/P&gt;&lt;P&gt;attribute 65 6 00000006&lt;/P&gt;&lt;P&gt;attribute 81 3 38191B43&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Apr 2007 08:27:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authorization-components-rac-doesn-t-work-on-acs/m-p/748305#M421018</guid>
      <dc:creator />
      <dc:date>2007-04-19T08:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: RADIUS Authorization Components (RAC) doesn't work on ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authorization-components-rac-doesn-t-work-on-acs/m-p/748306#M421019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, i found the "solution" myself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually it was a typing mistake in the switch configuration:&lt;/P&gt;&lt;P&gt;i typed:&lt;/P&gt;&lt;P&gt;aaa authorization network defualt group radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in stead of: &lt;/P&gt;&lt;P&gt;aaa authorization network default group radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now this problem is solved, so i get into the correct VLAN. But in the Quarantine VLAN, the Cisco Trust Agent Icon remains yellow and show that he is still connecting. Also, every few minutes he asks for my user credentials.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the device is in the correct VLAN and got the correct ip-address assigned from the DHCP-server in the quarantine VLAN zo that part works.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Apr 2007 12:09:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authorization-components-rac-doesn-t-work-on-acs/m-p/748306#M421019</guid>
      <dc:creator />
      <dc:date>2007-04-19T12:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: RADIUS Authorization Components (RAC) doesn't work on ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authorization-components-rac-doesn-t-work-on-acs/m-p/748307#M421020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, I've solved the problem: you need to set the ePo server as the "default-gateway" for your Quarantine-VLAN. Otherwise, the client cannot connect for some reason with it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So this topic can be marked as solved.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Apr 2007 10:18:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authorization-components-rac-doesn-t-work-on-acs/m-p/748307#M421020</guid>
      <dc:creator />
      <dc:date>2007-04-20T10:18:50Z</dc:date>
    </item>
  </channel>
</rss>

