<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help with Auth-Proxy in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/help-with-auth-proxy/m-p/590895#M427396</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had the same problem. You can try to change the custom attribute from&lt;/P&gt;&lt;P&gt; proxyacl#1="permit tcp any host 198.133.219.27"  &lt;/P&gt;&lt;P&gt;to&lt;/P&gt;&lt;P&gt;proxyacl#1=permit ip any host 198.133.219.27&lt;/P&gt;&lt;P&gt;If that succeeds, you can begin finetuning the access--list until it does what it is supposed to do.&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Eduardo &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 23 Apr 2006 02:40:46 GMT</pubDate>
    <dc:creator>e-alvarez</dc:creator>
    <dc:date>2006-04-23T02:40:46Z</dc:date>
    <item>
      <title>Help with Auth-Proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/help-with-auth-proxy/m-p/590894#M427393</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to do Auth-Proxy with a Cisco router running 12.4(7) and Secure ACS Solution Engine 3.3.3.11.&lt;/P&gt;&lt;P&gt;The router is configured as&lt;/P&gt;&lt;P&gt;+++++++++++++++++++++&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ aus-nac-group-tacacs&lt;/P&gt;&lt;P&gt; server-private 10.190.99.26 key xx&lt;/P&gt;&lt;P&gt; ip tacacs source-interface GigabitEthernet0/0.99&lt;/P&gt;&lt;P&gt;aaa authentication login default group aus-nac-group-tacacs&lt;/P&gt;&lt;P&gt;aaa authentication login telnet group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication eou default group aus-nac-group&lt;/P&gt;&lt;P&gt;aaa authorization exec default group aus-nac-group-tacacs &lt;/P&gt;&lt;P&gt;aaa authorization exec telnet group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization commands 1 telnet group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 telnet group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization auth-proxy default group aus-nac-group-tacacs &lt;/P&gt;&lt;P&gt;aaa accounting exec default stop-only group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default stop-only group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization auth-proxy default group aus-nac-group-tacacs &lt;/P&gt;&lt;P&gt;ip auth-proxy name test-auth telnet inactivity-time 5 list nac-test-trigger_acl&lt;/P&gt;&lt;P&gt;++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the secure ACS a new service is defined as "auth-proxy".&lt;/P&gt;&lt;P&gt;In the user-profile the auth-proxy box is checked and Custom-Attributes are defined as&lt;/P&gt;&lt;P&gt;+++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;priv-lvl=15&lt;/P&gt;&lt;P&gt;proxyacl#1="permit tcp any host 198.133.219.27"&lt;/P&gt;&lt;P&gt;+++++++++++++++++++++++++++++&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However when user initiates a connection, the user authentication succeeds but Authorization fails and the following message is shown on ACS&lt;/P&gt;&lt;P&gt;++++++++++++++&lt;/P&gt;&lt;P&gt;Service denied &lt;/P&gt;&lt;P&gt;service=auth-proxy protocol=ip &lt;/P&gt;&lt;P&gt;++++++++++++++&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea what could be going wrong here ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Naman&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:33:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/help-with-auth-proxy/m-p/590894#M427393</guid>
      <dc:creator>mnlatif</dc:creator>
      <dc:date>2019-03-10T21:33:10Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Auth-Proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/help-with-auth-proxy/m-p/590895#M427396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had the same problem. You can try to change the custom attribute from&lt;/P&gt;&lt;P&gt; proxyacl#1="permit tcp any host 198.133.219.27"  &lt;/P&gt;&lt;P&gt;to&lt;/P&gt;&lt;P&gt;proxyacl#1=permit ip any host 198.133.219.27&lt;/P&gt;&lt;P&gt;If that succeeds, you can begin finetuning the access--list until it does what it is supposed to do.&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Eduardo &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 23 Apr 2006 02:40:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/help-with-auth-proxy/m-p/590895#M427396</guid>
      <dc:creator>e-alvarez</dc:creator>
      <dc:date>2006-04-23T02:40:46Z</dc:date>
    </item>
    <item>
      <title>Re: Help with Auth-Proxy</title>
      <link>https://community.cisco.com/t5/network-access-control/help-with-auth-proxy/m-p/590896#M427398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will give it a shot. Though exactly the same ACL format works when i use RADIUS protocol instead of TACACS+..!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Naman&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Apr 2006 12:22:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/help-with-auth-proxy/m-p/590896#M427398</guid>
      <dc:creator>mnlatif</dc:creator>
      <dc:date>2006-04-25T12:22:58Z</dc:date>
    </item>
  </channel>
</rss>

