<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA authorization - request never sent in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-request-never-sent/m-p/257953#M434135</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having a problem with AAA Authorization and Microsoft IAS.  I want to pass of authorization for network (PPP) access to MS IAS (radius).  At present it fails but it never makes a request to the IAS server.  I am running a packet sniffer and never see any packets from the Router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Debug as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.388: As65 AAA/AUTHOR/LCP: Authorize LCP&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.388: As65 AAA/AUTHOR/LCP (3152618189): Port='Async65' list='IAS' service=NET&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.388: AAA/AUTHOR/LCP: As65 (3152618189) user='testuser'&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.388: As65 AAA/AUTHOR/LCP (3152618189): send AV service=ppp&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.388: As65 AAA/AUTHOR/LCP (3152618189): send AV protocol=lcp&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.388: As65 AAA/AUTHOR/LCP (3152618189): found list "IAS"&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.392: As65 AAA/AUTHOR/LCP (3152618189): Method=radius (radius)&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.392: As65 AAA/AUTHOR (3152618189): Post authorization status = ERROR&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.392: As65 AAA/AUTHOR/LCP (3152618189): Method=NOT_SET&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.392: As65 AAA/AUTHOR/LCP (3152618189): no methods left to try&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.392: As65 AAA/AUTHOR (3152618189): Post authorization status = ERROR&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.392: As65 AAA/AUTHOR/LCP: Denied&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Relevant config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa group server radius default&lt;/P&gt;&lt;P&gt; server x.x.x.x auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius IAS&lt;/P&gt;&lt;P&gt; server x.x.x.x auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default group radius&lt;/P&gt;&lt;P&gt;aaa authentication login NONE none&lt;/P&gt;&lt;P&gt;aaa authentication login LINE line&lt;/P&gt;&lt;P&gt;aaa authentication login RADIUS group radius&lt;/P&gt;&lt;P&gt;aaa authentication ppp default local&lt;/P&gt;&lt;P&gt;aaa authorization network default group radius&lt;/P&gt;&lt;P&gt;aaa authorization network IAS group radius&lt;/P&gt;&lt;P&gt;aaa authorization network NO_AUTH none&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;radius-server host x.x.x.x auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt;radius-server retransmit 3&lt;/P&gt;&lt;P&gt;radius-server key xxxxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; ip address x.x.x.x 255.255.0.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Serial1/0:15&lt;/P&gt;&lt;P&gt; description Connected to xxxxx&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; encapsulation ppp&lt;/P&gt;&lt;P&gt; dialer pool-member 1&lt;/P&gt;&lt;P&gt; dialer pool-member 5&lt;/P&gt;&lt;P&gt; dialer pool-member 2&lt;/P&gt;&lt;P&gt; isdn switch-type primary-net5&lt;/P&gt;&lt;P&gt; isdn incoming-voice modem&lt;/P&gt;&lt;P&gt; ppp authentication pap&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Group-Async1&lt;/P&gt;&lt;P&gt; ip unnumbered Ethernet0/0&lt;/P&gt;&lt;P&gt; encapsulation ppp&lt;/P&gt;&lt;P&gt; ip tcp header-compression passive&lt;/P&gt;&lt;P&gt; no ip mroute-cache&lt;/P&gt;&lt;P&gt; dialer in-band&lt;/P&gt;&lt;P&gt; dialer idle-timeout 1800&lt;/P&gt;&lt;P&gt; dialer-group 2&lt;/P&gt;&lt;P&gt; async mode interactive&lt;/P&gt;&lt;P&gt; peer default ip address pool sales&lt;/P&gt;&lt;P&gt; no fair-queue&lt;/P&gt;&lt;P&gt; ppp authentication pap&lt;/P&gt;&lt;P&gt; ppp authorization IAS&lt;/P&gt;&lt;P&gt; ppp multilink&lt;/P&gt;&lt;P&gt; group-range 65 70 &lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 20:43:48 GMT</pubDate>
    <dc:creator>n.oneill</dc:creator>
    <dc:date>2019-03-10T20:43:48Z</dc:date>
    <item>
      <title>AAA authorization - request never sent</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-request-never-sent/m-p/257953#M434135</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having a problem with AAA Authorization and Microsoft IAS.  I want to pass of authorization for network (PPP) access to MS IAS (radius).  At present it fails but it never makes a request to the IAS server.  I am running a packet sniffer and never see any packets from the Router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Debug as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.388: As65 AAA/AUTHOR/LCP: Authorize LCP&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.388: As65 AAA/AUTHOR/LCP (3152618189): Port='Async65' list='IAS' service=NET&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.388: AAA/AUTHOR/LCP: As65 (3152618189) user='testuser'&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.388: As65 AAA/AUTHOR/LCP (3152618189): send AV service=ppp&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.388: As65 AAA/AUTHOR/LCP (3152618189): send AV protocol=lcp&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.388: As65 AAA/AUTHOR/LCP (3152618189): found list "IAS"&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.392: As65 AAA/AUTHOR/LCP (3152618189): Method=radius (radius)&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.392: As65 AAA/AUTHOR (3152618189): Post authorization status = ERROR&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.392: As65 AAA/AUTHOR/LCP (3152618189): Method=NOT_SET&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.392: As65 AAA/AUTHOR/LCP (3152618189): no methods left to try&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.392: As65 AAA/AUTHOR (3152618189): Post authorization status = ERROR&lt;/P&gt;&lt;P&gt;Jun 17 12:20:30.392: As65 AAA/AUTHOR/LCP: Denied&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Relevant config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa group server radius default&lt;/P&gt;&lt;P&gt; server x.x.x.x auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius IAS&lt;/P&gt;&lt;P&gt; server x.x.x.x auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default group radius&lt;/P&gt;&lt;P&gt;aaa authentication login NONE none&lt;/P&gt;&lt;P&gt;aaa authentication login LINE line&lt;/P&gt;&lt;P&gt;aaa authentication login RADIUS group radius&lt;/P&gt;&lt;P&gt;aaa authentication ppp default local&lt;/P&gt;&lt;P&gt;aaa authorization network default group radius&lt;/P&gt;&lt;P&gt;aaa authorization network IAS group radius&lt;/P&gt;&lt;P&gt;aaa authorization network NO_AUTH none&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;radius-server host x.x.x.x auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt;radius-server retransmit 3&lt;/P&gt;&lt;P&gt;radius-server key xxxxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; ip address x.x.x.x 255.255.0.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Serial1/0:15&lt;/P&gt;&lt;P&gt; description Connected to xxxxx&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; encapsulation ppp&lt;/P&gt;&lt;P&gt; dialer pool-member 1&lt;/P&gt;&lt;P&gt; dialer pool-member 5&lt;/P&gt;&lt;P&gt; dialer pool-member 2&lt;/P&gt;&lt;P&gt; isdn switch-type primary-net5&lt;/P&gt;&lt;P&gt; isdn incoming-voice modem&lt;/P&gt;&lt;P&gt; ppp authentication pap&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Group-Async1&lt;/P&gt;&lt;P&gt; ip unnumbered Ethernet0/0&lt;/P&gt;&lt;P&gt; encapsulation ppp&lt;/P&gt;&lt;P&gt; ip tcp header-compression passive&lt;/P&gt;&lt;P&gt; no ip mroute-cache&lt;/P&gt;&lt;P&gt; dialer in-band&lt;/P&gt;&lt;P&gt; dialer idle-timeout 1800&lt;/P&gt;&lt;P&gt; dialer-group 2&lt;/P&gt;&lt;P&gt; async mode interactive&lt;/P&gt;&lt;P&gt; peer default ip address pool sales&lt;/P&gt;&lt;P&gt; no fair-queue&lt;/P&gt;&lt;P&gt; ppp authentication pap&lt;/P&gt;&lt;P&gt; ppp authorization IAS&lt;/P&gt;&lt;P&gt; ppp multilink&lt;/P&gt;&lt;P&gt; group-range 65 70 &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 20:43:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization-request-never-sent/m-p/257953#M434135</guid>
      <dc:creator>n.oneill</dc:creator>
      <dc:date>2019-03-10T20:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authorization - request never sent</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-request-never-sent/m-p/257954#M434142</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe there is an inconsistency in the way that you have configured authorization. The Group-async interface defines an authorization method using:  "ppp authorization IAS". And you define a matching group for a particular server using:&lt;/P&gt;&lt;P&gt;"aaa group server radius IAS&lt;/P&gt;&lt;P&gt;server x.x.x.x auth-port 1645 acct-port 1646"&lt;/P&gt;&lt;P&gt;However the authorization you define in the aaa section for ppp is: "aaa authorization network IAS group radius" which does not point to a recognizable group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suggest that you change your configuration to be: aaa authorization network IAS group IAS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jun 2004 13:12:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization-request-never-sent/m-p/257954#M434142</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2004-06-17T13:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authorization - request never sent</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-request-never-sent/m-p/257955#M434148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply and I take your point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't think I needed the aaa server groups configured at all:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;gw1(config)#aaa authorization network IAS group ?&lt;/P&gt;&lt;P&gt;  WORD     Server-group name&lt;/P&gt;&lt;P&gt;  radius   Use list of all Radius hosts.&lt;/P&gt;&lt;P&gt;  tacacs+  Use list of all Tacacs+ hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So to my mind it should try all radius hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I added the line you suggested to use the aaa server group IAS but it still does exactly the same and never queries the aaa server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So any further suggestions would be gratefully received!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jun 2004 08:18:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization-request-never-sent/m-p/257955#M434148</guid>
      <dc:creator>n.oneill</dc:creator>
      <dc:date>2004-06-18T08:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authorization - request never sent</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-request-never-sent/m-p/257956#M434150</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you made progress on this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is still not working, am I correct in understanding that authentication works correctly and that the problem is in authorization?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is still not working, would you post the current contents of the config and a fresh debug output?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jun 2004 17:45:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization-request-never-sent/m-p/257956#M434150</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2004-06-25T17:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authorization - request never sent</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-request-never-sent/m-p/257957#M434152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunatly, still not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config and debug attached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Jul 2004 08:16:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization-request-never-sent/m-p/257957#M434152</guid>
      <dc:creator>n.oneill</dc:creator>
      <dc:date>2004-07-01T08:16:57Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authorization - request never sent</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-request-never-sent/m-p/257958#M434155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have looked at the additional information that you sent and have these responses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The debug shows pretty clearly that it recognizes that it should try radius for authorization, it does not show any communication with a radius server (even though debug radius is turned on), there is "Post authorization status = ERROR", and it says no more methods and authorization fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My best guess at this point is that there is a problem communicating with the radius server. The part of configuration that you posted did not include the server definition. I suggest that you look closely at that, and perhaps post it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any data about communication with the radius server? What is the output of show radius statistics? If it were me, I might try debug ip packet with an access list which identifies any ip packet with the radius server address as the source or destination as a way to determine whether there is any communication:&lt;/P&gt;&lt;P&gt;debug ip packet 199&lt;/P&gt;&lt;P&gt;access-list 199 permit ip host &lt;SERVER_ADDRESS&gt; any&lt;/SERVER_ADDRESS&gt;&lt;/P&gt;&lt;P&gt;access-list 199 permit ip any host &lt;SERVER_ADDRESS&gt;&lt;/SERVER_ADDRESS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure why you are doing authentication locally but authorization via radius. I would have expected if the user is defined in radius that you would use radius for both. But I am not sure that this necessarily is related to the problem that you are having.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Jul 2004 11:51:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization-request-never-sent/m-p/257958#M434155</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2004-07-01T11:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authorization - request never sent</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-request-never-sent/m-p/257959#M434158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's working now!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See the following post:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.1dd5e6c3/39#selected_message" target="_blank"&gt;http://forums.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.1dd5e6c3/39#selected_message&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I managed to work it out before Zulfi posted but what he is saying is correct of course.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jul 2004 08:07:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization-request-never-sent/m-p/257959#M434158</guid>
      <dc:creator>n.oneill</dc:creator>
      <dc:date>2004-07-02T08:07:22Z</dc:date>
    </item>
  </channel>
</rss>

