<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multi-Vendor Authorization in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/multi-vendor-authorization/m-p/256200#M435262</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to use ACS 3.0 to perform authorization onto exec level on multiple vendors network equipment. I'm able to use the ACS server to authorize a user onto a cisco switch and set the exec priv level if there is no RADIUS attributes defined for any other vendor. However, once I add in the attributes for authorization and priv level on our Enterasys switches I loose the ability to access the cisco switches but can access the enterasys ones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see the following errors on the debug on the cisco box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1d05h: AAA: parse name=tty1 idb type=-1 tty=-1                                              &lt;/P&gt;&lt;P&gt;1d05h: AAA: name=tty1 flags=0x11 type=5 shelf=0 slot=0 adapter=0 port=1 channel=                                                                                &lt;/P&gt;&lt;P&gt;0 &lt;/P&gt;&lt;P&gt;1d05h: AAA/MEMORY: create_user (0x80CA24B4) user='' ruser='' port='tty1' rem_add                                                                                &lt;/P&gt;&lt;P&gt;r='10.133.152.144' authen_type=ASCII service=LOGIN priv=1                                                         &lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN/START (647308947): port='tty1' list='' action=LOGIN service=LO                                                                                &lt;/P&gt;&lt;P&gt;GIN   &lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN/START (647308947): using "default" list                                                         &lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN/START (647308947): Method=radius (radius)                                                           &lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN (647308947): status = GETUSER                                               &lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN/CONT (647308947): continue                                          &lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN (647308947): status = GETUSER                                               &lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN (647308947): Method=radius (radius)                                                     &lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN (647308947): status = GETPASS                                               &lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN/CONT (647308947): continue_login (user='webstm02')                                                                    &lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN (647308947): status = GETPASS                                               &lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN (647308947): Method=radius (radius)                                                     &lt;/P&gt;&lt;P&gt;1d05h: RADIUS: ustruct sharecount=1                                   &lt;/P&gt;&lt;P&gt;1d05h: RADIUS: Initial Transmit tty1 id 24 10.129.1.167:1812, Access-Request, le                                                                                &lt;/P&gt;&lt;P&gt;n 82    &lt;/P&gt;&lt;P&gt;1d05h:         Attribute 4 6 0A8108FE                                     &lt;/P&gt;&lt;P&gt;1d05h:         Attribute 5 6 0000000                                   &lt;/P&gt;&lt;P&gt;1d05h:         Attribute 61 6 00000005                                      &lt;/P&gt;&lt;P&gt;1d05h:         Attribute 1 10 77656273                                      &lt;/P&gt;&lt;P&gt;1d05h:         Attribute 31 16 31302E31                                       &lt;/P&gt;&lt;P&gt;1d05h:         Attribute 2 18 D597882A                                      &lt;/P&gt;&lt;P&gt;1d05h: RADIUS: Received from id 24 10.129.1.167:1812, Access-Accept, len 145                                                                            &lt;/P&gt;&lt;P&gt;1d05h:         Attribute 26 59 0000000901356169                                               &lt;/P&gt;&lt;P&gt;1d05h:         Attribute 26 25 0000000901137368                                               &lt;/P&gt;&lt;P&gt;1d05h:         Attribute 6 6 00000007                                     &lt;/P&gt;&lt;P&gt;1d05h:         Attribute 11 29 456E7465                                       &lt;/P&gt;&lt;P&gt;1d05h:         Attribute 8 6 FFFFFFFF                                     &lt;/P&gt;&lt;P&gt;1d05h: RADIUS: saved authorization data for user 80CA24B4 at 80CA25DC&lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN (647308947): status = PASS&lt;/P&gt;&lt;P&gt;1d05h: tty1 AAA/AUTHOR/EXEC (904302638): Port='tty1' list='' service=EXEC&lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHOR/EXEC: tty1 (904302638) user='webstm02'&lt;/P&gt;&lt;P&gt;1d05h: tty1 AAA/AUTHOR/EXEC (904302638): send AV service=shell&lt;/P&gt;&lt;P&gt;1d05h: tty1 AAA/AUTHOR/EXEC (904302638): send AV cmd*&lt;/P&gt;&lt;P&gt;1d05h: tty1 AAA/AUTHOR/EXEC (904302638): found list "default"&lt;/P&gt;&lt;P&gt;1d05h: tty1 AAA/AUTHOR/EXEC (904302638): Method=radius (radius)&lt;/P&gt;&lt;P&gt;1d05h: RADIUS: cisco AVPair "aironet:admin-capability=write+ident+admin+firmware&lt;/P&gt;&lt;P&gt;" not applied for shell&lt;/P&gt;&lt;P&gt;1d05h: RADIUS: Bad attribute (Inapplicable attribute): type 26 len 59 data 0x9&lt;/P&gt;&lt;P&gt;1d05h: RADIUS: cisco AVPair "shell:priv-lvl=15"&lt;/P&gt;&lt;P&gt;1d05h: RADIUS: Bad attribute (Inapplicable attribute): type 26 len 25 data 0x9&lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHOR (904302638): Post authorization status = PASS_ADD&lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHOR/EXEC: Processing AV service=shell&lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHOR/EXEC: Processing AV cmd*&lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHOR/EXEC: Processing AV priv-lvl=15&lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHOR/EXEC: Processing AV acl=Enterasys:version=1:mgmt=su&lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHOR/EXEC: received invalid access-class value 0. (Should be 1 - 19&lt;/P&gt;&lt;P&gt;9)&lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHOR/EXEC: acl Enterasys:version=1:mgmt=su does not exist.&lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHOR/EXEC: Authorization FAILED&lt;/P&gt;&lt;P&gt;1d05h: AAA/MEMORY: free_user (0x80CA24B4) user='webstm02' ruser='' port='tty1' r&lt;/P&gt;&lt;P&gt;em_addr='10.133.152.144' authen_type=ASCII service=LOGIN priv=1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any clues greatly appreciated.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 14:32:25 GMT</pubDate>
    <dc:creator>mark.webster</dc:creator>
    <dc:date>2019-03-10T14:32:25Z</dc:date>
    <item>
      <title>Multi-Vendor Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/multi-vendor-authorization/m-p/256200#M435262</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to use ACS 3.0 to perform authorization onto exec level on multiple vendors network equipment. I'm able to use the ACS server to authorize a user onto a cisco switch and set the exec priv level if there is no RADIUS attributes defined for any other vendor. However, once I add in the attributes for authorization and priv level on our Enterasys switches I loose the ability to access the cisco switches but can access the enterasys ones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see the following errors on the debug on the cisco box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1d05h: AAA: parse name=tty1 idb type=-1 tty=-1                                              &lt;/P&gt;&lt;P&gt;1d05h: AAA: name=tty1 flags=0x11 type=5 shelf=0 slot=0 adapter=0 port=1 channel=                                                                                &lt;/P&gt;&lt;P&gt;0 &lt;/P&gt;&lt;P&gt;1d05h: AAA/MEMORY: create_user (0x80CA24B4) user='' ruser='' port='tty1' rem_add                                                                                &lt;/P&gt;&lt;P&gt;r='10.133.152.144' authen_type=ASCII service=LOGIN priv=1                                                         &lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN/START (647308947): port='tty1' list='' action=LOGIN service=LO                                                                                &lt;/P&gt;&lt;P&gt;GIN   &lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN/START (647308947): using "default" list                                                         &lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN/START (647308947): Method=radius (radius)                                                           &lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN (647308947): status = GETUSER                                               &lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN/CONT (647308947): continue                                          &lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN (647308947): status = GETUSER                                               &lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN (647308947): Method=radius (radius)                                                     &lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN (647308947): status = GETPASS                                               &lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN/CONT (647308947): continue_login (user='webstm02')                                                                    &lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN (647308947): status = GETPASS                                               &lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN (647308947): Method=radius (radius)                                                     &lt;/P&gt;&lt;P&gt;1d05h: RADIUS: ustruct sharecount=1                                   &lt;/P&gt;&lt;P&gt;1d05h: RADIUS: Initial Transmit tty1 id 24 10.129.1.167:1812, Access-Request, le                                                                                &lt;/P&gt;&lt;P&gt;n 82    &lt;/P&gt;&lt;P&gt;1d05h:         Attribute 4 6 0A8108FE                                     &lt;/P&gt;&lt;P&gt;1d05h:         Attribute 5 6 0000000                                   &lt;/P&gt;&lt;P&gt;1d05h:         Attribute 61 6 00000005                                      &lt;/P&gt;&lt;P&gt;1d05h:         Attribute 1 10 77656273                                      &lt;/P&gt;&lt;P&gt;1d05h:         Attribute 31 16 31302E31                                       &lt;/P&gt;&lt;P&gt;1d05h:         Attribute 2 18 D597882A                                      &lt;/P&gt;&lt;P&gt;1d05h: RADIUS: Received from id 24 10.129.1.167:1812, Access-Accept, len 145                                                                            &lt;/P&gt;&lt;P&gt;1d05h:         Attribute 26 59 0000000901356169                                               &lt;/P&gt;&lt;P&gt;1d05h:         Attribute 26 25 0000000901137368                                               &lt;/P&gt;&lt;P&gt;1d05h:         Attribute 6 6 00000007                                     &lt;/P&gt;&lt;P&gt;1d05h:         Attribute 11 29 456E7465                                       &lt;/P&gt;&lt;P&gt;1d05h:         Attribute 8 6 FFFFFFFF                                     &lt;/P&gt;&lt;P&gt;1d05h: RADIUS: saved authorization data for user 80CA24B4 at 80CA25DC&lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHEN (647308947): status = PASS&lt;/P&gt;&lt;P&gt;1d05h: tty1 AAA/AUTHOR/EXEC (904302638): Port='tty1' list='' service=EXEC&lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHOR/EXEC: tty1 (904302638) user='webstm02'&lt;/P&gt;&lt;P&gt;1d05h: tty1 AAA/AUTHOR/EXEC (904302638): send AV service=shell&lt;/P&gt;&lt;P&gt;1d05h: tty1 AAA/AUTHOR/EXEC (904302638): send AV cmd*&lt;/P&gt;&lt;P&gt;1d05h: tty1 AAA/AUTHOR/EXEC (904302638): found list "default"&lt;/P&gt;&lt;P&gt;1d05h: tty1 AAA/AUTHOR/EXEC (904302638): Method=radius (radius)&lt;/P&gt;&lt;P&gt;1d05h: RADIUS: cisco AVPair "aironet:admin-capability=write+ident+admin+firmware&lt;/P&gt;&lt;P&gt;" not applied for shell&lt;/P&gt;&lt;P&gt;1d05h: RADIUS: Bad attribute (Inapplicable attribute): type 26 len 59 data 0x9&lt;/P&gt;&lt;P&gt;1d05h: RADIUS: cisco AVPair "shell:priv-lvl=15"&lt;/P&gt;&lt;P&gt;1d05h: RADIUS: Bad attribute (Inapplicable attribute): type 26 len 25 data 0x9&lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHOR (904302638): Post authorization status = PASS_ADD&lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHOR/EXEC: Processing AV service=shell&lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHOR/EXEC: Processing AV cmd*&lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHOR/EXEC: Processing AV priv-lvl=15&lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHOR/EXEC: Processing AV acl=Enterasys:version=1:mgmt=su&lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHOR/EXEC: received invalid access-class value 0. (Should be 1 - 19&lt;/P&gt;&lt;P&gt;9)&lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHOR/EXEC: acl Enterasys:version=1:mgmt=su does not exist.&lt;/P&gt;&lt;P&gt;1d05h: AAA/AUTHOR/EXEC: Authorization FAILED&lt;/P&gt;&lt;P&gt;1d05h: AAA/MEMORY: free_user (0x80CA24B4) user='webstm02' ruser='' port='tty1' r&lt;/P&gt;&lt;P&gt;em_addr='10.133.152.144' authen_type=ASCII service=LOGIN priv=1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any clues greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:32:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multi-vendor-authorization/m-p/256200#M435262</guid>
      <dc:creator>mark.webster</dc:creator>
      <dc:date>2019-03-10T14:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-Vendor Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/multi-vendor-authorization/m-p/256201#M435263</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Make sure you have properly configured the Authorization parameter in correct manner &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authorization Parameters&lt;/P&gt;&lt;P&gt;The following authentication server attribute value (AV) pair is returned to the access point for an&lt;/P&gt;&lt;P&gt;administrator login request:&lt;/P&gt;&lt;P&gt;This is RADIUS attribute #26, Cisco Vendor ID #9, type #1 --- string.&lt;/P&gt;&lt;P&gt;Cisco:Avpair = "aironet:admin-capability=write+snmp+ident+firmware+admin"&lt;/P&gt;&lt;P&gt;Any combination of capabilities are returned with this attribute, for example:&lt;/P&gt;&lt;P&gt;?	Cisco:Avpair = "aironet:admin-capability=ident+admin" &lt;/P&gt;&lt;P&gt;?	Cisco:Avpair = "aironet:admin-capability=admin" &lt;/P&gt;&lt;P&gt;The following is an example Livingston RADIUS server users file entry:&lt;/P&gt;&lt;P&gt;User password = "aironet"&lt;/P&gt;&lt;P&gt;Service-Type = Outbound&lt;/P&gt;&lt;P&gt;cisco-avpair = "aironet:admin-capability-ident+admin"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Oct 2003 20:50:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multi-vendor-authorization/m-p/256201#M435263</guid>
      <dc:creator>smalkeric</dc:creator>
      <dc:date>2003-10-29T20:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: Multi-Vendor Authorization</title>
      <link>https://community.cisco.com/t5/network-access-control/multi-vendor-authorization/m-p/256202#M435264</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm pretty sure I've got the aironet stuff right... The problem seems to be the cisco switches getting upset with the Enterasys attributes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way of getting them to ignore non-cisco attributes??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Oct 2003 09:55:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/multi-vendor-authorization/m-p/256202#M435264</guid>
      <dc:creator>mark.webster</dc:creator>
      <dc:date>2003-10-30T09:55:44Z</dc:date>
    </item>
  </channel>
</rss>

