<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Please help trouble shooting RADIUS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/please-help-trouble-shooting-radius/m-p/254721#M435013</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This looks to be the problem:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;02:29:16: As33 AAA/AUTHOR/LCP: Processing AV timeout=9999999&lt;/P&gt;&lt;P&gt;02:29:16: As33 AAA/AUTHOR/LCP: timeout failed&lt;/P&gt;&lt;P&gt;02:29:16: As33 AAA/AUTHOR/LCP: Denied &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You're doing authorization (not just authentication) on your dialup users, not sure if you really want that or not.  If so, then you will have a session-timeout set in the Radius users profile, you can see the radius server replying with this:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;02:29:16: Attribute 6 6 00000002&lt;/P&gt;&lt;P&gt;02:29:16: Attribute 7 6 00000001&lt;/P&gt;&lt;P&gt;02:29:16: Attribute 27 6 0098967F&lt;/P&gt;&lt;P&gt;02:29:16: Attribute 28 6 0000000A &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which when decoded becomes:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;02:29:16: 	Service-Type	Framed&lt;/P&gt;&lt;P&gt;02:29:16: 	Framed-Protocol	PPP&lt;/P&gt;&lt;P&gt;02:29:16: 	Session-Timeout	9999999&lt;/P&gt;&lt;P&gt;02:29:16: 	Idle-Timeout	10 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would say the NAS/router doesn't like the Session-Timeout being so high, try lowering it and see what happens.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alternatively, if you don't really want to do authorization for your dialup users, then remove the line:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;aaa authorization network radius &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and the problem should also go away.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Jan 2004 05:05:05 GMT</pubDate>
    <dc:creator>gfullage</dc:creator>
    <dc:date>2004-01-06T05:05:05Z</dc:date>
    <item>
      <title>Please help trouble shooting RADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/please-help-trouble-shooting-radius/m-p/254720#M435012</link>
      <description>&lt;P&gt;I could telnet in to my Cisco 2620 using RADIUS authentication &lt;/P&gt;&lt;P&gt;"telnet 192.168.4.10 2033" (provide username/pass)&lt;/P&gt;&lt;P&gt;and then type AT which My modem reply with OK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I could also dial-in to the NAS with local user&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I could not dial-in using RADIUS user.&lt;/P&gt;&lt;P&gt;Please help me trouble shoot the problem. &lt;/P&gt;&lt;P&gt;I enclose the debug information and also the configuration I used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nguyen Nhat Binh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Username: test &lt;/P&gt;&lt;P&gt;Password: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco2620&amp;gt;ena &lt;/P&gt;&lt;P&gt;Password: &lt;/P&gt;&lt;P&gt;Cisco2620# &lt;/P&gt;&lt;P&gt;Cisco2620# &lt;/P&gt;&lt;P&gt;Cisco2620# &lt;/P&gt;&lt;P&gt;Cisco2620#terminal monitor &lt;/P&gt;&lt;P&gt;Cisco2620# &lt;/P&gt;&lt;P&gt;02:28:00: %LINK-3-UPDOWN: Interface Async33, changed state to up &lt;/P&gt;&lt;P&gt;02:28:00: As33 AAA/AUTHOR/FSM: (0): LCP succeeds trivially &lt;/P&gt;&lt;P&gt;02:28:24: %LINK-5-CHANGED: Interface Async33, changed state to reset &lt;/P&gt;&lt;P&gt;02:28:29: %LINK-3-UPDOWN: Interface Async33, changed state to down &lt;/P&gt;&lt;P&gt;02:28:35: %LINK-3-UPDOWN: Interface Async33, changed state to up &lt;/P&gt;&lt;P&gt;02:28:35: As33 AAA/AUTHOR/FSM: (0): LCP succeeds trivially &lt;/P&gt;&lt;P&gt;02:28:46: %LINK-5-CHANGED: Interface Async33, changed state to reset &lt;/P&gt;&lt;P&gt;02:28:51: %LINK-3-UPDOWN: Interface Async33, changed state to down &lt;/P&gt;&lt;P&gt;02:29:15: As33 AAA/AUTHOR/FSM: (0): LCP succeeds trivially &lt;/P&gt;&lt;P&gt;02:29:15: %LINK-3-UPDOWN: Interface Async33, changed state to up &lt;/P&gt;&lt;P&gt;02:29:16: AAA: parse name=Async33 idb type=10 tty=33 &lt;/P&gt;&lt;P&gt;02:29:16: AAA: name=Async33 flags=0x11 type=4 shelf=0 slot=0 adapter=0 port=33 c &lt;/P&gt;&lt;P&gt;hannel=0 &lt;/P&gt;&lt;P&gt;02:29:16: AAA/MEMORY: create_user (0x80CD711C) user='test' ruser='' port='Async3 &lt;/P&gt;&lt;P&gt;3' rem_addr='async' authen_type=CHAP service=PPP priv=1 &lt;/P&gt;&lt;P&gt;02:29:16: AAA/AUTHEN/START (327574709): port='Async33' list='' action=LOGIN serv &lt;/P&gt;&lt;P&gt;ice=PPP &lt;/P&gt;&lt;P&gt;02:29:16: AAA/AUTHEN/START (327574709): using "default" list &lt;/P&gt;&lt;P&gt;02:29:16: AAA/AUTHEN (327574709): status = UNKNOWN &lt;/P&gt;&lt;P&gt;02:29:16: AAA/AUTHEN/START (327574709): Method=radius (radius) &lt;/P&gt;&lt;P&gt;02:29:16: RADIUS: ustruct sharecount=1 &lt;/P&gt;&lt;P&gt;02:29:16: RADIUS: Initial Transmit Async33 id 89 192.168.4.141:1645, Access-Requ &lt;/P&gt;&lt;P&gt;est, len 75 &lt;/P&gt;&lt;P&gt;02:29:16: Attribute 4 6 C0A8040A &lt;/P&gt;&lt;P&gt;02:29:16: Attribute 5 6 00000021 &lt;/P&gt;&lt;P&gt;02:29:16: Attribute 61 6 00000000 &lt;/P&gt;&lt;P&gt;02:29:16: Attribute 1 6 74657374 &lt;/P&gt;&lt;P&gt;02:29:16: Attribute 3 19 27440611 &lt;/P&gt;&lt;P&gt;02:29:16: Attribute 6 6 00000002 &lt;/P&gt;&lt;P&gt;02:29:16: Attribute 7 6 00000001 &lt;/P&gt;&lt;P&gt;02:29:16: RADIUS: Received from id 89 192.168.4.141:1645, Access-Accept, len 44 &lt;/P&gt;&lt;P&gt;02:29:16: Attribute 6 6 00000002 &lt;/P&gt;&lt;P&gt;02:29:16: Attribute 7 6 00000001 &lt;/P&gt;&lt;P&gt;02:29:16: Attribute 27 6 0098967F &lt;/P&gt;&lt;P&gt;02:29:16: Attribute 28 6 0000000A &lt;/P&gt;&lt;P&gt;02:29:16: AAA/AUTHEN (327574709): status = PASS &lt;/P&gt;&lt;P&gt;02:29:16: As33 AAA/AUTHOR/LCP: Authorize LCP &lt;/P&gt;&lt;P&gt;02:29:16: As33 AAA/AUTHOR/LCP (1939832978): Port='Async33' list='' service=NET &lt;/P&gt;&lt;P&gt;02:29:16: AAA/AUTHOR/LCP: As33 (1939832978) user='test' &lt;/P&gt;&lt;P&gt;02:29:16: As33 AAA/AUTHOR/LCP (1939832978): send AV service=ppp &lt;/P&gt;&lt;P&gt;02:29:16: As33 AAA/AUTHOR/LCP (1939832978): send AV protocol=lcp &lt;/P&gt;&lt;P&gt;02:29:16: As33 AAA/AUTHOR/LCP (1939832978): found list "default" &lt;/P&gt;&lt;P&gt;02:29:16: As33 AAA/AUTHOR/LCP (1939832978): Method=radius (radius) &lt;/P&gt;&lt;P&gt;02:29:16: As33 AAA/AUTHOR (1939832978): Post authorization status = PASS_REPL &lt;/P&gt;&lt;P&gt;02:29:16: As33 AAA/AUTHOR/LCP: Processing AV service=ppp &lt;/P&gt;&lt;P&gt;02:29:16: As33 AAA/AUTHOR/LCP: Processing AV timeout=9999999 &lt;/P&gt;&lt;P&gt;02:29:16: As33 AAA/AUTHOR/LCP: timeout failed &lt;/P&gt;&lt;P&gt;02:29:16: As33 AAA/AUTHOR/LCP: Denied &lt;/P&gt;&lt;P&gt;02:29:16: AAA/MEMORY: free_user (0x80CD711C) user='test' ruser='' port='Async33' &lt;/P&gt;&lt;P&gt;rem_addr='async' authen_type=CHAP service=PPP priv=1 &lt;/P&gt;&lt;P&gt;02:29:18: As33 AAA/AUTHOR/FSM: (0): LCP succeeds trivially &lt;/P&gt;&lt;P&gt;02:29:20: %LINK-5-CHANGED: Interface Async33, changed state to reset &lt;/P&gt;&lt;P&gt;02:29:25: %LINK-3-UPDOWN: Interface Async33, changed state to down &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;************************************************************* &lt;/P&gt;&lt;P&gt;! Cisco2620.cfg - Cisco router configuration file &lt;/P&gt;&lt;P&gt;! Automatically created by Cisco ConfigMaker v2.6 Build 6 &lt;/P&gt;&lt;P&gt;! Wednesday, December 31, 2003, 01:58:10 PM &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;! Hostname: Cisco2620 &lt;/P&gt;&lt;P&gt;! Model: 2620 &lt;/P&gt;&lt;P&gt;! ************************************************************* &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;service timestamps debug uptime &lt;/P&gt;&lt;P&gt;service timestamps log uptime &lt;/P&gt;&lt;P&gt;service password-encryption &lt;/P&gt;&lt;P&gt;no service tcp-small-servers &lt;/P&gt;&lt;P&gt;no service udp-small-servers &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;hostname Cisco2620 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;enable password xxxxx &lt;/P&gt;&lt;P&gt;username dong password xxxx &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;no ip name-server &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;ip subnet-zero &lt;/P&gt;&lt;P&gt;no ip domain-lookup &lt;/P&gt;&lt;P&gt;ip routing &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;interface FastEthernet 0/0 &lt;/P&gt;&lt;P&gt;no shutdown &lt;/P&gt;&lt;P&gt;description connected to EthernetLAN &lt;/P&gt;&lt;P&gt;ip address 192.168.4.10 255.255.255.0 &lt;/P&gt;&lt;P&gt;no keepalive &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;interface Async 33 &lt;/P&gt;&lt;P&gt;no shutdown &lt;/P&gt;&lt;P&gt;description connected to Dial-inPCs(modem) &lt;/P&gt;&lt;P&gt;ip unnumbered FastEthernet 0/0 &lt;/P&gt;&lt;P&gt;ip tcp header-compression passive &lt;/P&gt;&lt;P&gt;encapsulation ppp &lt;/P&gt;&lt;P&gt;async mode dedicated &lt;/P&gt;&lt;P&gt;! group-range 33 33 &lt;/P&gt;&lt;P&gt;ppp authentication chap pap &lt;/P&gt;&lt;P&gt;no cdp enable &lt;/P&gt;&lt;P&gt;peer default ip address pool Cisco2620-Group-1 &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;router rip &lt;/P&gt;&lt;P&gt;version 2 &lt;/P&gt;&lt;P&gt;network 192.168.4.0 &lt;/P&gt;&lt;P&gt;no auto-summary &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;ip local pool Cisco2620-Group-1 10.10.10.10 10.10.10.10 &lt;/P&gt;&lt;P&gt;ip classless &lt;/P&gt;&lt;P&gt;no ip http server &lt;/P&gt;&lt;P&gt;snmp-server community public RO &lt;/P&gt;&lt;P&gt;no snmp-server location &lt;/P&gt;&lt;P&gt;no snmp-server contact &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;line console 0 &lt;/P&gt;&lt;P&gt;exec-timeout 0 0 &lt;/P&gt;&lt;P&gt;password a &lt;/P&gt;&lt;P&gt;login &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;line vty 0 4 &lt;/P&gt;&lt;P&gt;password xxxx &lt;/P&gt;&lt;P&gt;login &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;line 33 &lt;/P&gt;&lt;P&gt;exec &lt;/P&gt;&lt;P&gt;autoselect ppp &lt;/P&gt;&lt;P&gt;autoselect during-login &lt;/P&gt;&lt;P&gt;login local &lt;/P&gt;&lt;P&gt;modem InOut &lt;/P&gt;&lt;P&gt;transport input all &lt;/P&gt;&lt;P&gt;stopbits 1 &lt;/P&gt;&lt;P&gt;speed 38400 &lt;/P&gt;&lt;P&gt;flowcontrol hardware &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model &lt;/P&gt;&lt;P&gt;aaa authentication login default radius local &lt;/P&gt;&lt;P&gt;aaa authentication login no_radius enable &lt;/P&gt;&lt;P&gt;aaa authentication ppp default if-needed radius &lt;/P&gt;&lt;P&gt;aaa authorization network radius &lt;/P&gt;&lt;P&gt;aaa accounting exec start-stop radius &lt;/P&gt;&lt;P&gt;aaa accounting network start-stop radius &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;radius-server host 192.168.4.11 auth-port 1645 acct-port 1646 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;radius-server key ubtq&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:37:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/please-help-trouble-shooting-radius/m-p/254720#M435012</guid>
      <dc:creator>nguyenbinh</dc:creator>
      <dc:date>2019-03-10T14:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: Please help trouble shooting RADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/please-help-trouble-shooting-radius/m-p/254721#M435013</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This looks to be the problem:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;02:29:16: As33 AAA/AUTHOR/LCP: Processing AV timeout=9999999&lt;/P&gt;&lt;P&gt;02:29:16: As33 AAA/AUTHOR/LCP: timeout failed&lt;/P&gt;&lt;P&gt;02:29:16: As33 AAA/AUTHOR/LCP: Denied &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You're doing authorization (not just authentication) on your dialup users, not sure if you really want that or not.  If so, then you will have a session-timeout set in the Radius users profile, you can see the radius server replying with this:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;02:29:16: Attribute 6 6 00000002&lt;/P&gt;&lt;P&gt;02:29:16: Attribute 7 6 00000001&lt;/P&gt;&lt;P&gt;02:29:16: Attribute 27 6 0098967F&lt;/P&gt;&lt;P&gt;02:29:16: Attribute 28 6 0000000A &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which when decoded becomes:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;02:29:16: 	Service-Type	Framed&lt;/P&gt;&lt;P&gt;02:29:16: 	Framed-Protocol	PPP&lt;/P&gt;&lt;P&gt;02:29:16: 	Session-Timeout	9999999&lt;/P&gt;&lt;P&gt;02:29:16: 	Idle-Timeout	10 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would say the NAS/router doesn't like the Session-Timeout being so high, try lowering it and see what happens.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alternatively, if you don't really want to do authorization for your dialup users, then remove the line:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;aaa authorization network radius &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and the problem should also go away.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jan 2004 05:05:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/please-help-trouble-shooting-radius/m-p/254721#M435013</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2004-01-06T05:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: Please help trouble shooting RADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/please-help-trouble-shooting-radius/m-p/254722#M435014</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you alot for your support, I resolved the problem. Actually, I do not need authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wish you all the best for a new year.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jan 2004 07:14:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/please-help-trouble-shooting-radius/m-p/254722#M435014</guid>
      <dc:creator>nguyenbinh</dc:creator>
      <dc:date>2004-01-06T07:14:45Z</dc:date>
    </item>
  </channel>
</rss>

