<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radius IETF ACS 3.3 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374467#M439420</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You would add these with VSA (Vendor Specific Attributes) that can be added to ACS using CSUtil or RDBMS Sync (since ACS 3.1).&lt;/P&gt;&lt;P&gt;Notice that for ACS SE/Appliance the only method is RDBMS Sync.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, consult the ACS 3.2 appliance user guide for info about using RDBMS Synch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some links:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Topic about RDBMS support for VSA import:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/user/sad.htm#451579" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/user/sad.htm#451579&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Beginning of RDBMS feature doc:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/user/sad.htm#451426" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/user/sad.htm#451426&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Synch. codes appendix:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/user/ag.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/user/ag.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Table with relevant action codes:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/user/ag.htm#1372" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/user/ag.htm#1372&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Action codes 350 through 355 support custom VSA definition and config.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 13 Dec 2004 00:55:06 GMT</pubDate>
    <dc:creator>gfullage</dc:creator>
    <dc:date>2004-12-13T00:55:06Z</dc:date>
    <item>
      <title>Radius IETF ACS 3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374466#M439405</link>
      <description>&lt;P&gt;Hi to everybody.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why i can't see all the radius attribute from the interface configuration html page ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to set the primary-dns-server (radius attribute number 135) and the secondary-dns-server (radius attribute number 136) radius attribute, but i see only the attribut up to the 91.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thans a lot&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 20:55:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374466#M439405</guid>
      <dc:creator>m.alghisi</dc:creator>
      <dc:date>2019-03-10T20:55:36Z</dc:date>
    </item>
    <item>
      <title>Re: Radius IETF ACS 3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374467#M439420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You would add these with VSA (Vendor Specific Attributes) that can be added to ACS using CSUtil or RDBMS Sync (since ACS 3.1).&lt;/P&gt;&lt;P&gt;Notice that for ACS SE/Appliance the only method is RDBMS Sync.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, consult the ACS 3.2 appliance user guide for info about using RDBMS Synch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some links:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Topic about RDBMS support for VSA import:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/user/sad.htm#451579" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/user/sad.htm#451579&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Beginning of RDBMS feature doc:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/user/sad.htm#451426" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/user/sad.htm#451426&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Synch. codes appendix:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/user/ag.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/user/ag.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Table with relevant action codes:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/user/ag.htm#1372" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/access/acs_soft/csacsapp/user/ag.htm#1372&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Action codes 350 through 355 support custom VSA definition and config.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Dec 2004 00:55:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374467#M439420</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2004-12-13T00:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: Radius IETF ACS 3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374468#M439439</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot, as soon as possibile i will try to test the VSA import.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Dec 2004 09:22:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374468#M439439</guid>
      <dc:creator>m.alghisi</dc:creator>
      <dc:date>2004-12-13T09:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: Radius IETF ACS 3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374469#M439460</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Marco, I read your post. I have the same question and I follow the attacched suggestion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The RDBMS operation ended with success, but I have not reach the results? I didn't see the new parameters ( "135 Primary-DNS-Server" and "136 Secondary-DNS-Server") in the configuration screen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Had you reach the same results? If not, could you explain me how do you resolve the issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Aug 2005 08:05:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374469#M439460</guid>
      <dc:creator>fabrizio.roggerini</dc:creator>
      <dc:date>2005-08-30T08:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: Radius IETF ACS 3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374470#M439471</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Attribute 135 and 136 are part of the base attribute range and not part of a vendor specific set, and as thus can not be defind via the customizable dictionary mechanism.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In ACS 3.3 it seems there is a bug, since these attributes are defined against an Ascend NAS type.  But on attempting to view these attributes inside the Ascend dictionary they don't appear to show up&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Closer inspection of the Windows registry shows these items to be present.  So this leaves me to thinking there is a bug in CiscoSecure. Possibly the list of Ascend supported attributes has grown too large for the GUI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ive managed to come up with a  work around if you are feeling happy to hack the registry is this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming you are using ACS 3.3 download the attached registry file and double click on it ( open it in notepad if you want to see what it does ).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now restart CSADMIN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;net stop CSADMIN&lt;/P&gt;&lt;P&gt;net start CSADMIN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now navigate Interface Configuration -&amp;gt; RADIUS IETF&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should see Attribute 135,136 and the bottom select them for group or user configuration and hit submit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you should then see them in any group or user configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Sep 2005 13:20:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374470#M439471</guid>
      <dc:creator>andrewclymer</dc:creator>
      <dc:date>2005-09-16T13:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: Radius IETF ACS 3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374471#M439485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Having just rechecked my 3.3 it appears they were showing up in Ascend.  So you shouldn't have to do the registry hack&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Simply go to Interface Configuration -&amp;gt; Ascend and enable attribute 135 and 136.  They should then appear in the group configuration assuming you are using an Ascend compatible device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;E.g Cisco IOS/PIX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Sep 2005 13:49:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374471#M439485</guid>
      <dc:creator>andrewclymer</dc:creator>
      <dc:date>2005-09-16T13:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: Radius IETF ACS 3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374472#M439494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These are not regarded as IETF attributes but Ascend&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to have a Ascend or Compatible Access Device configured in Network Configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;E.g. Vendor = Ascend or Cisco IOS/PIX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And then go to Interface configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And select Ascend&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should then see 135 and 136 enable them and then they should be present on the group/user config screens&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Sep 2005 14:46:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374472#M439494</guid>
      <dc:creator>andrewclymer</dc:creator>
      <dc:date>2005-09-16T14:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: Radius IETF ACS 3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374473#M439503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This problem stinks. I have tried the RDBMS for IETF 135 and 136 (Primary DNS and Secondary) and it simply doesn't work. I read in places that the solution is ascend but the thing is I need to use framed routes (IETF) aswell. Is this issue a bug in ACS 3.3 or am I doing something wrong. Why this option wouldn't be included by default eludes me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Sep 2007 04:40:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374473#M439503</guid>
      <dc:creator>dodgybrother</dc:creator>
      <dc:date>2007-09-27T04:40:58Z</dc:date>
    </item>
    <item>
      <title>Re: Radius IETF ACS 3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374474#M439510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it that the config doesnt show up.. or that the attributes do not get sent to the device?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS tries to intelligently (ahem) filter inappropriate attributes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Therefore, if you have Ascend attributes defined in a group, but the device is defined as Cisco... ACS may well filter out the Ascend attributes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Easily tested, in the ACS network config set the RADIUS client to be Ascend and re-test.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Oct 2007 09:15:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374474#M439510</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2007-10-02T09:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: Radius IETF ACS 3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374475#M439514</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yeah tried setting as ascend and even nortel but it doesn't work for them either. Essentially where the RDBMS is falling over is with the sync. I get a parse error because it doesn't recognise the attribute and that is because I do not know the correct vendor ID for IETF...which I thought was default or at worst 9 (CISCO). Attached is my current CSV file to enable 135 and 136 (IETF). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2007 01:06:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374475#M439514</guid>
      <dc:creator>dodgybrother</dc:creator>
      <dc:date>2007-10-04T01:06:15Z</dc:date>
    </item>
    <item>
      <title>Re: Radius IETF ACS 3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374476#M439518</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ah, I see the mistake.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These are NOT VSAs. Way back (before VSAs) Ascend simply "stole" a huge chunk of standard attribute numbers for their own purposes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So use the non-vsa attribute settings actions, eg just like you would for setting something like Session-Timeout and it should  be ok.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2007 05:40:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374476#M439518</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2007-10-05T05:40:33Z</dc:date>
    </item>
    <item>
      <title>Re: Radius IETF ACS 3.3</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374477#M439521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;could you please tell me where to find the "non-vsa" attribute for DNS. Essentially as you describe it the attribute I am after was "stolen" by Ascend and I can't use that? So this still comes back to my point of how do I assign DNS from the Radius when it won't allow me to specify it anywhere? Please help me this is a major flaw with this device.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Dec 2007 04:23:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-ietf-acs-3-3/m-p/374477#M439521</guid>
      <dc:creator>dodgybrother</dc:creator>
      <dc:date>2007-12-12T04:23:43Z</dc:date>
    </item>
  </channel>
</rss>

