<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: virtual telnet/downloadable access lists: acl authorization  in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/virtual-telnet-downloadable-access-lists-acl-authorization/m-p/340783#M432645</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try to disable authorization and see if this error stops&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 01 Mar 2005 17:10:55 GMT</pubDate>
    <dc:creator>umedryk</dc:creator>
    <dc:date>2005-03-01T17:10:55Z</dc:date>
    <item>
      <title>virtual telnet/downloadable access lists: acl authorization denied error</title>
      <link>https://community.cisco.com/t5/network-access-control/virtual-telnet-downloadable-access-lists-acl-authorization/m-p/340782#M432642</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;has someone else experienced the same "issue" as described below ?  And can someone (Cisco ?) tell whether this is by design, and if so, what the reasoning is behind this ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We use virtual telnet for user authentication, when users need to pass traffic through a PIX, and use downloadable access-lists after successful  authentication.&lt;/P&gt;&lt;P&gt;When a user authenticates himself, an error message appears in the virtual telnet window: "error: acl authorization denied".&lt;/P&gt;&lt;P&gt;And the PIX log shows:&lt;/P&gt;&lt;P&gt;109005: Authentication succeeded for user 'user1' from &amp;lt;workstation-IP&amp;gt;/2066 to &amp;lt;virtual-telnet-IP&amp;gt;/23 on interface inside&lt;/P&gt;&lt;P&gt;109015: Authorization denied (acl=#ACSACL#-IP-PIX_ACL-421492f3) for user 'user1' from &amp;lt;workstation-IP&amp;gt;/2066 to &amp;lt;virtual-telnet-IP&amp;gt;/23 on interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This error message disappears when we add telnet access for the virtual telnet-IP@ in the  downloadable access-list on the Cisco ACS.  I could not find any reference to this configuration quirk in any document.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, with or without the error, the user can use virtual telnet and everything permitted&lt;/P&gt;&lt;P&gt;in the downloadable acl without any problem (so why post an error message then ?).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:01:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/virtual-telnet-downloadable-access-lists-acl-authorization/m-p/340782#M432642</guid>
      <dc:creator>bbanier</dc:creator>
      <dc:date>2019-03-10T21:01:42Z</dc:date>
    </item>
    <item>
      <title>Re: virtual telnet/downloadable access lists: acl authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/virtual-telnet-downloadable-access-lists-acl-authorization/m-p/340783#M432645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try to disable authorization and see if this error stops&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Mar 2005 17:10:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/virtual-telnet-downloadable-access-lists-acl-authorization/m-p/340783#M432645</guid>
      <dc:creator>umedryk</dc:creator>
      <dc:date>2005-03-01T17:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: virtual telnet/downloadable access lists: acl authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/virtual-telnet-downloadable-access-lists-acl-authorization/m-p/340784#M432648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is exactly authorization that we want to use ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Mar 2005 21:32:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/virtual-telnet-downloadable-access-lists-acl-authorization/m-p/340784#M432648</guid>
      <dc:creator>bbanier</dc:creator>
      <dc:date>2005-03-09T21:32:14Z</dc:date>
    </item>
  </channel>
</rss>

