<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radius login-service=50 for SSH access in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/radius-login-service-50-for-ssh-access/m-p/3465131#M539651</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do we have any workaround, because my customer would like to replace ISE by NPS just due to this issue ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Christophe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 17 Mar 2016 08:01:29 GMT</pubDate>
    <dc:creator>csarrazi</dc:creator>
    <dc:date>2016-03-17T08:01:29Z</dc:date>
    <item>
      <title>Radius login-service=50 for SSH access</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-login-service-50-for-ssh-access/m-p/3465129#M539561</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some HP switches (S3600) require the radius server to return login-service=50 for SSH access, even if it is not in the IETF standard, some Radius servers (FreeRadius, NPS) permit to customize IETF attribute.&lt;/P&gt;&lt;P&gt;How could we solve this issue with ISE, do we have any way to add login-service=50 in the IETF library ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance for your answer&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Christophe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Mar 2016 14:34:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-login-service-50-for-ssh-access/m-p/3465129#M539561</guid>
      <dc:creator>csarrazi</dc:creator>
      <dc:date>2016-03-16T14:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: Radius login-service=50 for SSH access</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-login-service-50-for-ssh-access/m-p/3465130#M539626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This does not seem supported at the moment. [ Dict &amp;gt; RADIUS &amp;gt; IETF &amp;gt; Login-Service (15)] is system pre-defined and not allowed for customization. I will forward your request to those more familiar with 3rd-party support.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Mar 2016 16:21:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-login-service-50-for-ssh-access/m-p/3465130#M539626</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-03-16T16:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: Radius login-service=50 for SSH access</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-login-service-50-for-ssh-access/m-p/3465131#M539651</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do we have any workaround, because my customer would like to replace ISE by NPS just due to this issue ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Christophe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2016 08:01:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-login-service-50-for-ssh-access/m-p/3465131#M539651</guid>
      <dc:creator>csarrazi</dc:creator>
      <dc:date>2016-03-17T08:01:29Z</dc:date>
    </item>
    <item>
      <title>Re: Radius login-service=50 for SSH access</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-login-service-50-for-ssh-access/m-p/3465132#M539673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My customer and I hit this issue as well with Cisco Secure ACS 5.6.&amp;nbsp; Started TAC ticket 680982850 to get more info.&amp;nbsp; They also indicated the IETF RADIUS attributes cannot be extended to include "50."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have just finished reading IETF RFC 2865, which covers how these radius attributes work.&amp;nbsp; My judgement: it would be *nice* if Cisco allowed us to extend Login-Service to include "50", but RFC 2865 is a standard.&amp;nbsp; It can be extended with Vendor Specified Attributes, but type code 15 (Login-Service) only has nine values defined, and 50 for SSH is not one of them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HP seems to be the ridiculous one here.&amp;nbsp; I blame them for this snafu.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My customer and I will look at using TACACS+ to authenticate SSH users.&amp;nbsp; I will post back here when the test is complete.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone else found a better solution?&amp;nbsp; I seems odd that I need a Cisco-specific technology like TACACS on my HP switches!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Sep 2016 14:30:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-login-service-50-for-ssh-access/m-p/3465132#M539673</guid>
      <dc:creator>danmassa</dc:creator>
      <dc:date>2016-09-26T14:30:33Z</dc:date>
    </item>
    <item>
      <title>Re: Radius login-service=50 for SSH access</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-login-service-50-for-ssh-access/m-p/3465133#M539685</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just put in the TACACS config on the HP Comware-based switch to authenticate SSH users.&amp;nbsp; That seems to do the trick.&amp;nbsp; It authenticates me and allows me to enter system-view mode (Comware's version of CONFIG TERMINAL.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This was a crazy ride.&amp;nbsp; HP should not have used Login-Service=50.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am using Comware 5.&amp;nbsp; I think Comware 7 introduced a new scheme for Role Based Access Control (RBAC.)&amp;nbsp; I wonder if the new RBAC requires Login-Service=50 for SSH.&amp;nbsp; I can't check it out; it would blow even more time on something that should have been simple.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone else tries the new RBAC, please post here.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Sep 2016 15:11:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-login-service-50-for-ssh-access/m-p/3465133#M539685</guid>
      <dc:creator>danmassa</dc:creator>
      <dc:date>2016-09-26T15:11:48Z</dc:date>
    </item>
  </channel>
</rss>

