<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic rel. 12.3 aaa authorization network in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/rel-12-3-aaa-authorization-network/m-p/300839#M434257</link>
    <description>&lt;P&gt;I have this configuration on my cisco 1700 router:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------&lt;/P&gt;&lt;P&gt;version 12.3&lt;/P&gt;&lt;P&gt;service timestamps debug datetime localtime&lt;/P&gt;&lt;P&gt;service timestamps log datetime localtime&lt;/P&gt;&lt;P&gt;service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname remote-aoud&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;clock timezone ITA 1&lt;/P&gt;&lt;P&gt;clock summer-time ITA recurring last Sun Mar 2:00 last Sun Oct 3:00&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ tac_admin&lt;/P&gt;&lt;P&gt; server 192.168.13.100&lt;/P&gt;&lt;P&gt; server 192.168.13.102&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius remote_access&lt;/P&gt;&lt;P&gt; server 192.168.13.100 auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt; server 192.168.13.102 auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default group tac_admin local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tac_admin enable&lt;/P&gt;&lt;P&gt;aaa authentication ppp default group remote_access local&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tac_admin local &lt;/P&gt;&lt;P&gt;aaa authorization network default group remote_access &lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;ip subnet-zero&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0&lt;/P&gt;&lt;P&gt; ip address 172.17.40.113 255.255.252.0&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; no cdp enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Async1&lt;/P&gt;&lt;P&gt; ip unnumbered FastEthernet0&lt;/P&gt;&lt;P&gt; encapsulation ppp&lt;/P&gt;&lt;P&gt; async mode interactive&lt;/P&gt;&lt;P&gt; peer default ip address 172.17.40.117&lt;/P&gt;&lt;P&gt; no keepalive&lt;/P&gt;&lt;P&gt; ppp authentication ms-chap&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip classless&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 172.17.40.1&lt;/P&gt;&lt;P&gt;radius-server host 192.168.13.100 auth-port 1645 acct-port 1646 key 7 ...&lt;/P&gt;&lt;P&gt;radius-server host 192.168.13.102 auth-port 1645 acct-port 1646 key 7 ...&lt;/P&gt;&lt;P&gt;radius-server deadtime 60&lt;/P&gt;&lt;P&gt;radius-server authorization permit missing Service-Type&lt;/P&gt;&lt;P&gt;radius-server vsa send accounting&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;line 1&lt;/P&gt;&lt;P&gt; flush-at-activation&lt;/P&gt;&lt;P&gt; modem InOut&lt;/P&gt;&lt;P&gt; transport input all&lt;/P&gt;&lt;P&gt; autoselect during-login&lt;/P&gt;&lt;P&gt; autoselect ppp&lt;/P&gt;&lt;P&gt; stopbits 1&lt;/P&gt;&lt;P&gt; speed 115200&lt;/P&gt;&lt;P&gt; flowcontrol hardware&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; exec-timeout 600 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no scheduler allocate&lt;/P&gt;&lt;P&gt;sntp server 172.17.40.1&lt;/P&gt;&lt;P&gt;sntp server 192.168.13.1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;-------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The users dialin are authenticate on a cisco acs 3.2&lt;/P&gt;&lt;P&gt;On acs 3.2 the user have check flag on ietf attributes 6 (framed) and 7 (ppp) for aaa authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This works ok with release 12.2 but whit release 13.3 if i uncheck flag on ietf attributes 6 and 7 the&lt;/P&gt;&lt;P&gt;user login always.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In fact the aaa authorization network not work !!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank&lt;/P&gt;&lt;P&gt;Ale&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 14:50:46 GMT</pubDate>
    <dc:creator>giga01</dc:creator>
    <dc:date>2019-03-10T14:50:46Z</dc:date>
    <item>
      <title>rel. 12.3 aaa authorization network</title>
      <link>https://community.cisco.com/t5/network-access-control/rel-12-3-aaa-authorization-network/m-p/300839#M434257</link>
      <description>&lt;P&gt;I have this configuration on my cisco 1700 router:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------&lt;/P&gt;&lt;P&gt;version 12.3&lt;/P&gt;&lt;P&gt;service timestamps debug datetime localtime&lt;/P&gt;&lt;P&gt;service timestamps log datetime localtime&lt;/P&gt;&lt;P&gt;service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname remote-aoud&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;clock timezone ITA 1&lt;/P&gt;&lt;P&gt;clock summer-time ITA recurring last Sun Mar 2:00 last Sun Oct 3:00&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ tac_admin&lt;/P&gt;&lt;P&gt; server 192.168.13.100&lt;/P&gt;&lt;P&gt; server 192.168.13.102&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius remote_access&lt;/P&gt;&lt;P&gt; server 192.168.13.100 auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt; server 192.168.13.102 auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default group tac_admin local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tac_admin enable&lt;/P&gt;&lt;P&gt;aaa authentication ppp default group remote_access local&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tac_admin local &lt;/P&gt;&lt;P&gt;aaa authorization network default group remote_access &lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;ip subnet-zero&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0&lt;/P&gt;&lt;P&gt; ip address 172.17.40.113 255.255.252.0&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; no cdp enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Async1&lt;/P&gt;&lt;P&gt; ip unnumbered FastEthernet0&lt;/P&gt;&lt;P&gt; encapsulation ppp&lt;/P&gt;&lt;P&gt; async mode interactive&lt;/P&gt;&lt;P&gt; peer default ip address 172.17.40.117&lt;/P&gt;&lt;P&gt; no keepalive&lt;/P&gt;&lt;P&gt; ppp authentication ms-chap&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip classless&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 172.17.40.1&lt;/P&gt;&lt;P&gt;radius-server host 192.168.13.100 auth-port 1645 acct-port 1646 key 7 ...&lt;/P&gt;&lt;P&gt;radius-server host 192.168.13.102 auth-port 1645 acct-port 1646 key 7 ...&lt;/P&gt;&lt;P&gt;radius-server deadtime 60&lt;/P&gt;&lt;P&gt;radius-server authorization permit missing Service-Type&lt;/P&gt;&lt;P&gt;radius-server vsa send accounting&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;line 1&lt;/P&gt;&lt;P&gt; flush-at-activation&lt;/P&gt;&lt;P&gt; modem InOut&lt;/P&gt;&lt;P&gt; transport input all&lt;/P&gt;&lt;P&gt; autoselect during-login&lt;/P&gt;&lt;P&gt; autoselect ppp&lt;/P&gt;&lt;P&gt; stopbits 1&lt;/P&gt;&lt;P&gt; speed 115200&lt;/P&gt;&lt;P&gt; flowcontrol hardware&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; exec-timeout 600 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no scheduler allocate&lt;/P&gt;&lt;P&gt;sntp server 172.17.40.1&lt;/P&gt;&lt;P&gt;sntp server 192.168.13.1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;-------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The users dialin are authenticate on a cisco acs 3.2&lt;/P&gt;&lt;P&gt;On acs 3.2 the user have check flag on ietf attributes 6 (framed) and 7 (ppp) for aaa authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This works ok with release 12.2 but whit release 13.3 if i uncheck flag on ietf attributes 6 and 7 the&lt;/P&gt;&lt;P&gt;user login always.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In fact the aaa authorization network not work !!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank&lt;/P&gt;&lt;P&gt;Ale&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:50:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/rel-12-3-aaa-authorization-network/m-p/300839#M434257</guid>
      <dc:creator>giga01</dc:creator>
      <dc:date>2019-03-10T14:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: rel. 12.3 aaa authorization network</title>
      <link>https://community.cisco.com/t5/network-access-control/rel-12-3-aaa-authorization-network/m-p/300840#M434259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Ale,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your configuration seems right, but we don´t say nothing whithout debugs. Please, enable debug aaa authorization and debug tacacs, try make one connection and post logs in this thread.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;kratz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 May 2004 20:01:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/rel-12-3-aaa-authorization-network/m-p/300840#M434259</guid>
      <dc:creator>d.kratz</dc:creator>
      <dc:date>2004-05-30T20:01:10Z</dc:date>
    </item>
    <item>
      <title>Re: rel. 12.3 aaa authorization network</title>
      <link>https://community.cisco.com/t5/network-access-control/rel-12-3-aaa-authorization-network/m-p/300841#M434260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Kratz,&lt;/P&gt;&lt;P&gt;This is debug output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;remote-aoud#&lt;/P&gt;&lt;P&gt;00:06:07: AAA/BIND(00000003): Bind i/f Async1 &lt;/P&gt;&lt;P&gt;00:06:09: %LINK-3-UPDOWN: Interface Async1, changed state to up&lt;/P&gt;&lt;P&gt;00:06:09: RADIUS/ENCODE(00000003):Orig. component type = EXEC&lt;/P&gt;&lt;P&gt;00:06:09: RADIUS:  AAA Unsupported Attr: interface         [153] 6   &lt;/P&gt;&lt;P&gt;00:06:09: RADIUS:   41 73 79 6E                                      [Asyn]&lt;/P&gt;&lt;P&gt;00:06:09: RADIUS(00000003): Storing nasport 1 in rad_db&lt;/P&gt;&lt;P&gt;00:06:09: RADIUS(00000003): Config NAS IP: 0.0.0.0&lt;/P&gt;&lt;P&gt;00:06:09: RADIUS/ENCODE(00000003): acct_session_id: 3&lt;/P&gt;&lt;P&gt;00:06:09: RADIUS(00000003): sending&lt;/P&gt;&lt;P&gt;00:06:09: RADIUS/ENCODE: Best Local IP-Address 192.168.13.113 for Radius-Server 192.168.13.100&lt;/P&gt;&lt;P&gt;00:06:09: RADIUS(00000003): Send Access-Request to 192.168.13.100:1645 id 1645/2, len 143&lt;/P&gt;&lt;P&gt;00:06:09: RADIUS:  authenticator F8 75 D5 95 91 74 55 71 - 00 00 00 00 00 00 00 00&lt;/P&gt;&lt;P&gt;00:06:09: RADIUS:  Framed-Protocol     [7]   6   PPP                       [1]&lt;/P&gt;&lt;P&gt;00:06:09: RADIUS:  User-Name           [1]   12  "CASA\marco"&lt;/P&gt;&lt;P&gt;00:06:09: RADIUS:  Vendor, Microsoft   [26]  16  &lt;/P&gt;&lt;P&gt;00:06:09: RADIUS:   MSCHAP_Challenge   [11]  10  &lt;/P&gt;&lt;P&gt;00:06:09: RADIUS:   F8 75 D5 95 91 74 55 71                          [?u???tUq]&lt;/P&gt;&lt;P&gt;00:06:09: RADIUS:  Vendor, Microsoft   [26]  58  &lt;/P&gt;&lt;P&gt;00:06:09: RADIUS:   MS-CHAP-Response   [1]   52  *&lt;/P&gt;&lt;P&gt;00:06:09: RADIUS:  NAS-Port-Type       [61]  6   Async                     [0]&lt;/P&gt;&lt;P&gt;00:06:09: RADIUS:  Calling-Station-Id  [31]  7   "async"&lt;/P&gt;&lt;P&gt;00:06:09: RADIUS:  NAS-Port            [5]   6   1                         &lt;/P&gt;&lt;P&gt;00:06:09: RADIUS:  Service-Type        [6]   6   Framed                    [2]&lt;/P&gt;&lt;P&gt;00:06:09: RADIUS:  NAS-IP-Address      [4]   6   192.168.13.113            &lt;/P&gt;&lt;P&gt;00:06:09: RADIUS: Received from id 1645/2 192.168.13.100:1645, Access-Accept, len 62&lt;/P&gt;&lt;P&gt;00:06:09: RADIUS:  authenticator E9 99 94 43 EB 4B 74 33 - F7 87 03 F6 64 F2 0E D6&lt;/P&gt;&lt;P&gt;00:06:09: RADIUS:  Session-Timeout     [27]  6   180                       &lt;/P&gt;&lt;P&gt;00:06:09: RADIUS:  Framed-IP-Address   [8]   6   255.255.255.255           &lt;/P&gt;&lt;P&gt;00:06:09: RADIUS:  Class               [25]  30  &lt;/P&gt;&lt;P&gt;00:06:09: RADIUS:   43 49 53 43 4F 41 43 53 3A 30 30 30 30 30 66 63  [CISCOACS:00000fc]&lt;/P&gt;&lt;P&gt;00:06:09: RADIUS:   61 2F 63 30 61 38 30 64 37 31 2F 31              [a/c0a80d71/1]&lt;/P&gt;&lt;P&gt;00:06:09: RADIUS(00000003): Received from id 1645/2&lt;/P&gt;&lt;P&gt;00:06:09: As1 PPP/AAA: Check Attr: timeout: Peruser&lt;/P&gt;&lt;P&gt;00:06:10: As1 PPP/AAA: Check Attr: addr&lt;/P&gt;&lt;P&gt;00:06:10: As1 AAA/AUTHOR/LCP: Process Author&lt;/P&gt;&lt;P&gt;00:06:10: As1 AAA/AUTHOR/LCP: Process Attr: timeout&lt;/P&gt;&lt;P&gt;00:06:10: AAA/AUTHOR: Processing PerUser AV timeout&lt;/P&gt;&lt;P&gt;00:06:10: As1 AAA/AUTHOR/IPCP: FSM authorization not needed&lt;/P&gt;&lt;P&gt;00:06:10: As1 AAA/AUTHOR/FSM: We can start IPCP&lt;/P&gt;&lt;P&gt;00:06:10: As1 AAA/AUTHOR/IPCP: Start.  Her address 0.0.0.0, we want 192.168.13.170&lt;/P&gt;&lt;P&gt;00:06:10: As1 AAA/AUTHOR/IPCP: No remote address; FIP = Use peer provided address&lt;/P&gt;&lt;P&gt;00:06:10: As1 AAA/AUTHOR/IPCP: Processing AV addr&lt;/P&gt;&lt;P&gt;00:06:10: As1 AAA/AUTHOR/IPCP: Authorization succeeded&lt;/P&gt;&lt;P&gt;00:06:10: As1 AAA/AUTHOR/IPCP: Done.  Her address 0.0.0.0, we want 192.168.13.170&lt;/P&gt;&lt;P&gt;00:06:10: As1 AAA/AUTHOR/IPCP: no author-info for primary dns&lt;/P&gt;&lt;P&gt;00:06:10: As1 AAA/AUTHOR/IPCP: no author-info for primary wins&lt;/P&gt;&lt;P&gt;00:06:10: As1 AAA/AUTHOR/IPCP: no author-info for seconday dns&lt;/P&gt;&lt;P&gt;00:06:10: As1 AAA/AUTHOR/IPCP: no author-info for seconday wins&lt;/P&gt;&lt;P&gt;00:06:10: As1 AAA/AUTHOR/IPCP: no author-info for primary dns&lt;/P&gt;&lt;P&gt;00:06:10: As1 AAA/AUTHOR/IPCP: no author-info for seconday dns&lt;/P&gt;&lt;P&gt;00:06:10: As1 AAA/AUTHOR/IPCP: no author-info for primary dns&lt;/P&gt;&lt;P&gt;00:06:10: As1 AAA/AUTHOR/IPCP: no author-info for seconday dns&lt;/P&gt;&lt;P&gt;00:06:11: %LINEPROTO-5-UPDOWN: Line protocol on Interface Async1, changed state to up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you see the authorization network fail in fact. The user is not permitted from the acs user configuration to connect , but the connection is established .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I add jpeg with acs user configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Ale&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 May 2004 10:58:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/rel-12-3-aaa-authorization-network/m-p/300841#M434260</guid>
      <dc:creator>giga01</dc:creator>
      <dc:date>2004-05-31T10:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: rel. 12.3 aaa authorization network</title>
      <link>https://community.cisco.com/t5/network-access-control/rel-12-3-aaa-authorization-network/m-p/300842#M434261</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have resolved !!!&lt;/P&gt;&lt;P&gt;I must insert :&lt;/P&gt;&lt;P&gt;radius-server attribute 6 mandatory&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in my configuration with 12.3 ios release and all work well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards&lt;/P&gt;&lt;P&gt;Ale&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 May 2004 14:11:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/rel-12-3-aaa-authorization-network/m-p/300842#M434261</guid>
      <dc:creator>giga01</dc:creator>
      <dc:date>2004-05-31T14:11:59Z</dc:date>
    </item>
  </channel>
</rss>

