<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radius User Defined Vendor (VSA) issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/radius-user-defined-vendor-vsa-issue/m-p/535912#M426751</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok, I can add UDVs with new vendors. But how can I add new Cisco VSAs? I tried the csutil.exe -addUDV, but I receive a message that "Vendor with IETF code 9 already defined".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to have the ACS to recognize and report the accountig info sent by a vocie gw.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Attila&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 Jul 2008 08:39:01 GMT</pubDate>
    <dc:creator>gaattila</dc:creator>
    <dc:date>2008-07-23T08:39:01Z</dc:date>
    <item>
      <title>Radius User Defined Vendor (VSA) issue</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-user-defined-vendor-vsa-issue/m-p/535908#M426736</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Software Version: &lt;/P&gt;&lt;P&gt;CiscoSecure ACS for Windows 2000/NT&lt;/P&gt;&lt;P&gt;Release 3.0(3) Build 6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've created the ini file below and added it using csutil -addUDV 8 laurel-vsa.ini (tried other slots too). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[User Defined Vendor]&lt;/P&gt;&lt;P&gt;Name=Laurel&lt;/P&gt;&lt;P&gt;IETF Code=5395&lt;/P&gt;&lt;P&gt;VSA 1=Laurel-Login-Local-User-Name&lt;/P&gt;&lt;P&gt;VSA 2=Laurel-Login-Allowed-Commands&lt;/P&gt;&lt;P&gt;VSA 3=Laurel-Login-Denied-Commands&lt;/P&gt;&lt;P&gt;VSA 4=Laurel-Login-Allow-Config&lt;/P&gt;&lt;P&gt;VSA 5=Laurel-Login-Deny-Config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Laurel-Login-Local-User-Name]&lt;/P&gt;&lt;P&gt;Type=STRING&lt;/P&gt;&lt;P&gt;Profile=OUT&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;[Laurel-Login-Allowed-Commands]&lt;/P&gt;&lt;P&gt;Type=STRING&lt;/P&gt;&lt;P&gt;Profile=OUT&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;[Laurel-Login-Denied-Commands]&lt;/P&gt;&lt;P&gt;Type=STRING&lt;/P&gt;&lt;P&gt;Profile=OUT&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;[Laurel-Login-Allow-Config]&lt;/P&gt;&lt;P&gt;Type=STRING&lt;/P&gt;&lt;P&gt;Profile=OUT&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;[Laurel-Login-Deny-Config]&lt;/P&gt;&lt;P&gt;Type=STRING&lt;/P&gt;&lt;P&gt;Profile=OUT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C:\Program Files\CiscoSecure ACS v3.0\Utils&amp;gt;csutil -addUDV 8 laurel-vsa.ini&lt;/P&gt;&lt;P&gt;CSUtil v3.0(3.6), Copyright 1997-2002, Cisco Systems Inc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Adding or removing vendors requires ACS services to be re-started.&lt;/P&gt;&lt;P&gt;Please make sure regedit is not running as it can prevent registry&lt;/P&gt;&lt;P&gt;backup/restore operations&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you sure you want to proceed? (y/n)y&lt;/P&gt;&lt;P&gt;Parsing [.\laurel-vsa.ini] for addition at UDV slot [8]&lt;/P&gt;&lt;P&gt;Stopping any running services&lt;/P&gt;&lt;P&gt;Creating backup of current config&lt;/P&gt;&lt;P&gt;Adding Vendor [Laurel] added as [RADIUS (Laurel)]&lt;/P&gt;&lt;P&gt;Adding VSA [Laurel-Login-Local-User-Name]&lt;/P&gt;&lt;P&gt;Adding VSA [Laurel-Login-Allowed-Commands]&lt;/P&gt;&lt;P&gt;Adding VSA [Laurel-Login-Denied-Commands]&lt;/P&gt;&lt;P&gt;Adding VSA [Laurel-Login-Allow-Config]&lt;/P&gt;&lt;P&gt;Adding VSA [Laurel-Login-Deny-Config]&lt;/P&gt;&lt;P&gt;Done&lt;/P&gt;&lt;P&gt;Checking new configuration...&lt;/P&gt;&lt;P&gt;New configuration OK&lt;/P&gt;&lt;P&gt;Re-starting stopped services&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C:\Program Files\CiscoSecure ACS v3.0\Utils&amp;gt;csutil -listUDV&lt;/P&gt;&lt;P&gt;CSUtil v3.0(3.6), Copyright 1997-2002, Cisco Systems Inc&lt;/P&gt;&lt;P&gt;UDV 0 - Unassigned&lt;/P&gt;&lt;P&gt;UDV 1 - Unassigned&lt;/P&gt;&lt;P&gt;UDV 2 - Unassigned&lt;/P&gt;&lt;P&gt;UDV 3 - Unassigned&lt;/P&gt;&lt;P&gt;UDV 4 - Unassigned&lt;/P&gt;&lt;P&gt;UDV 5 - Unassigned&lt;/P&gt;&lt;P&gt;UDV 6 - Unassigned&lt;/P&gt;&lt;P&gt;UDV 7 - Unassigned&lt;/P&gt;&lt;P&gt;UDV 8 - RADIUS (Laurel)&lt;/P&gt;&lt;P&gt;UDV 9 - Unassigned&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All this shows that it has worked ok. However, when I look in the Interface Confirguration section on the GUI, its not there, so I can't use it. Is there something I'm missing, is it a bug with this version of ACS? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cant upgrade at this time as we're planning to migrate to the Cisco Secure Access Control Server Solution Engine 4.0. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for your help, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lee Hecken&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:41:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-user-defined-vendor-vsa-issue/m-p/535908#M426736</guid>
      <dc:creator>heckenl</dc:creator>
      <dc:date>2019-03-10T21:41:27Z</dc:date>
    </item>
    <item>
      <title>Re: Radius User Defined Vendor (VSA) issue</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-user-defined-vendor-vsa-issue/m-p/535909#M426739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All you need do is physically re-start the CSAdmin service:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;net stop csadmin&lt;/P&gt;&lt;P&gt;net start csadmin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You'll see the new VSAs. ACS isnt very good at reflecting changes to its "meta config" without csadmin re-starts. This might be documented somewhere in the depths of the user guide &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Darran&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Aug 2006 13:25:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-user-defined-vendor-vsa-issue/m-p/535909#M426739</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2006-08-02T13:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: Radius User Defined Vendor (VSA) issue</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-user-defined-vendor-vsa-issue/m-p/535910#M426742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply Darran, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACS server has beed reload since adding the VSAs, however I tried the above just to make sure. Same issue, still not showing under Interface Configuration, just the standard enteries. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any further suggestions? Do you have an ini file I can try that you've used that does show up?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Lee&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Aug 2006 13:56:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-user-defined-vendor-vsa-issue/m-p/535910#M426742</guid>
      <dc:creator>heckenl</dc:creator>
      <dc:date>2006-08-02T13:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: Radius User Defined Vendor (VSA) issue</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-user-defined-vendor-vsa-issue/m-p/535911#M426745</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Fixed it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The new VSA doesnt show up in the Interface Configuration section until after you've set it as the 'authenticate using' method for a AAA client! Then you can select which properties you want to use in the user or group sections. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds,&lt;/P&gt;&lt;P&gt;Lee&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Aug 2006 14:12:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-user-defined-vendor-vsa-issue/m-p/535911#M426745</guid>
      <dc:creator>heckenl</dc:creator>
      <dc:date>2006-08-02T14:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: Radius User Defined Vendor (VSA) issue</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-user-defined-vendor-vsa-issue/m-p/535912#M426751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok, I can add UDVs with new vendors. But how can I add new Cisco VSAs? I tried the csutil.exe -addUDV, but I receive a message that "Vendor with IETF code 9 already defined".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to have the ACS to recognize and report the accountig info sent by a vocie gw.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Attila&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jul 2008 08:39:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-user-defined-vendor-vsa-issue/m-p/535912#M426751</guid>
      <dc:creator>gaattila</dc:creator>
      <dc:date>2008-07-23T08:39:01Z</dc:date>
    </item>
  </channel>
</rss>

