<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Netmask assignment via ACS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/netmask-assignment-via-acs/m-p/268995#M434530</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is not a dynamic way to assign a specific mask. The only way would be to assign static addressess to clients. If you are worried about the routing of a particular subnet then you could use a subnet which as a default has the mask you require. The RAS/VPN device can then route/proxy the connection to any network the client needs to connects too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 May 2004 08:11:12 GMT</pubDate>
    <dc:creator>wsherlock</dc:creator>
    <dc:date>2004-05-06T08:11:12Z</dc:date>
    <item>
      <title>Netmask assignment via ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/netmask-assignment-via-acs/m-p/268989#M434524</link>
      <description>&lt;P&gt;Is there a way to assign a netmask to a VPN client that connects itself to the network via a VPN concentrator?&lt;/P&gt;&lt;P&gt;The assignment of the IP address is not a problem but we always get a 8-Bit address. That's not what we want. I don't see a menu in ACS where the netmask can be determined. Radius attribute [9] does not work. We use radius and we have defined the IP adresses in an address pool on the ACS server.&lt;/P&gt;&lt;P&gt;Thanks. Thomas.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:45:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/netmask-assignment-via-acs/m-p/268989#M434524</guid>
      <dc:creator>6tschraml</dc:creator>
      <dc:date>2019-03-10T14:45:31Z</dc:date>
    </item>
    <item>
      <title>Re: Netmask assignment via ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/netmask-assignment-via-acs/m-p/268990#M434525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thomas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is nothing available that I am aware of to assign a netwmask value.  I believe this is actaully a limitation of the concentrator rather than the ACS server.  Even if assigning addresses from a pool on the concentrator itself, you do not have the option of assigning the mask (I believe it actually defaults to a 32 bit mask in this case).  Most times, the subnet mask is not very important as the concentrator will proxy arp for any devices that are connected to it.  Can you elaborate a bit more on why this would be a problem?  Are you trying to use an address space within your current network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Apr 2004 15:52:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/netmask-assignment-via-acs/m-p/268990#M434525</guid>
      <dc:creator>scoclayton</dc:creator>
      <dc:date>2004-04-26T15:52:26Z</dc:date>
    </item>
    <item>
      <title>Re: Netmask assignment via ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/netmask-assignment-via-acs/m-p/268991#M434526</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Scott,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having a similar problem. We are trying to assign IP addresses from a pool on the concentrator and have a class B range. Within our current network we have VLSM. The client defaults to a 255.255.0.0 subnet mask. I am not sure if this i a problem becasue I am having some problems in connecting the client properly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 May 2004 18:11:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/netmask-assignment-via-acs/m-p/268991#M434526</guid>
      <dc:creator />
      <dc:date>2004-05-04T18:11:59Z</dc:date>
    </item>
    <item>
      <title>Re: Netmask assignment via ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/netmask-assignment-via-acs/m-p/268992#M434527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;... in fact we don't have problems with reachability. But the fact that the concentrator assigns netmasks and we don't know why and from which resource, makes me nervous.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 May 2004 07:16:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/netmask-assignment-via-acs/m-p/268992#M434527</guid>
      <dc:creator>6tschraml</dc:creator>
      <dc:date>2004-05-05T07:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: Netmask assignment via ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/netmask-assignment-via-acs/m-p/268993#M434528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The reason you are assigned a netmask from the concentrator is that it treats it the same as PPP. The default for this is to issue the default mask for the subnet class. For example 10.0.0.1 will always have the mask 255.0.0.0 and 192.168.0.1 will have the mask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 May 2004 13:07:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/netmask-assignment-via-acs/m-p/268993#M434528</guid>
      <dc:creator>wsherlock</dc:creator>
      <dc:date>2004-05-05T13:07:16Z</dc:date>
    </item>
    <item>
      <title>Re: Netmask assignment via ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/netmask-assignment-via-acs/m-p/268994#M434529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have the same problem.  In our case, we are trying to assign a 10.203 address to the VPN clients.  However, ACS is giving out a /8 subnet mask.  This is a problem because it will think the entire 10.0.0.0 address space is local - not to mention other routing problem we will have with other subnets int eh 10.203 range.  I don't understand why you can't just assing a specific mask for these IP Pools.  Is there a command line option?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 May 2004 20:10:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/netmask-assignment-via-acs/m-p/268994#M434529</guid>
      <dc:creator>timpotter</dc:creator>
      <dc:date>2004-05-05T20:10:39Z</dc:date>
    </item>
    <item>
      <title>Re: Netmask assignment via ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/netmask-assignment-via-acs/m-p/268995#M434530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is not a dynamic way to assign a specific mask. The only way would be to assign static addressess to clients. If you are worried about the routing of a particular subnet then you could use a subnet which as a default has the mask you require. The RAS/VPN device can then route/proxy the connection to any network the client needs to connects too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 May 2004 08:11:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/netmask-assignment-via-acs/m-p/268995#M434530</guid>
      <dc:creator>wsherlock</dc:creator>
      <dc:date>2004-05-06T08:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: Netmask assignment via ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/netmask-assignment-via-acs/m-p/268996#M434531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have the same trouble, ACS gives me a 8bit netmask when I want a 24bit one.&lt;/P&gt;&lt;P&gt;We saw something strange with VPN3000 and Radius : when we configure VPN3000 to give to the client a class C IP, in the VPN client's log, there is the attribute INTERNAL_IPV4_NETMASK with value 255.255.255.0 that is transmit to the client. If we use a class A (or B) IP, this attribute is not sent...&lt;/P&gt;&lt;P&gt;Does someone have an idea about that? And why not a solution to our netmask trouble?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Jul 2004 12:58:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/netmask-assignment-via-acs/m-p/268996#M434531</guid>
      <dc:creator>gauthraj</dc:creator>
      <dc:date>2004-07-09T12:58:47Z</dc:date>
    </item>
    <item>
      <title>Re: Netmask assignment via ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/netmask-assignment-via-acs/m-p/268997#M434532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We solved this problem.. You have to upgrade ACS to version 3.3, this allows ACS to send Framed-IP-Netmask attribute to VPN 3000. So you can configure your netmask as you want.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Jul 2004 08:35:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/netmask-assignment-via-acs/m-p/268997#M434532</guid>
      <dc:creator>gauthraj</dc:creator>
      <dc:date>2004-07-15T08:35:24Z</dc:date>
    </item>
    <item>
      <title>Re: Netmask assignment via ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/netmask-assignment-via-acs/m-p/268998#M434533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for the mystake, it is the VPN3000 software that you have to upgrade to version 4.1.5 &lt;/P&gt;&lt;P&gt;ACS doesn't need to be upgrade (for this trouble)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Jul 2004 10:59:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/netmask-assignment-via-acs/m-p/268998#M434533</guid>
      <dc:creator>gauthraj</dc:creator>
      <dc:date>2004-07-15T10:59:19Z</dc:date>
    </item>
  </channel>
</rss>

