<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Server Group Asking For Realm-id for RADIUS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/asa-server-group-asking-for-realm-id-for-radius/m-p/3357044#M550360</link>
    <description>Just a quick update in case anyone finds this. I upgraded ASDM/ASA yesterday. Now on 7.9(2) ASDM and 9.9(2). The realm-id has been removed from config and the "Edit AAA Server Group" gui.</description>
    <pubDate>Wed, 28 Mar 2018 20:24:46 GMT</pubDate>
    <dc:creator>briancarson</dc:creator>
    <dc:date>2018-03-28T20:24:46Z</dc:date>
    <item>
      <title>ASA Server Group Asking For Realm-id for RADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-server-group-asking-for-realm-id-for-radius/m-p/3325449#M550354</link>
      <description>&lt;P&gt;Hello all,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have an ASA 5512x running firmware 9.9(1). I am trying to add a RADIUS server group for authentication and I am being asked for a Realm-id. I have been using an older ASA 5510 for testing and I have never been prompted for this and I have not seen it on any of the documentation I have viewed. There is a configured LDAP server group already and the realm ID is set to 0. I just want to make sure I know what the realm ID does before I go any further.&amp;nbsp; Any help is appreciated!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 409px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/7222i657B80FD44B5DE66/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:44:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-server-group-asking-for-realm-id-for-radius/m-p/3325449#M550354</guid>
      <dc:creator>brandonbittinger</dc:creator>
      <dc:date>2020-02-21T18:44:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Server Group Asking For Realm-id for RADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-server-group-asking-for-realm-id-for-radius/m-p/3333044#M550355</link>
      <description>&lt;P&gt;Hi there, I just tried the 0 value for the Realm-id. Looks like this works. Starting aan SSH session with only Radius as authentication option works fine&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;
&lt;P&gt;Marcel&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Feb 2018 22:41:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-server-group-asking-for-realm-id-for-radius/m-p/3333044#M550355</guid>
      <dc:creator>Marcel70</dc:creator>
      <dc:date>2018-02-17T22:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Server Group Asking For Realm-id for RADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-server-group-asking-for-realm-id-for-radius/m-p/3350015#M550356</link>
      <description>&lt;P&gt;I've been looking for information about this field since it's not documented. In a post on the Japanese forum, it was explained that it was supported, but not being used. You cannot leave it blank. However, putting 0 does work and appears to be the only option when adding an AAA server.&lt;/P&gt;
&lt;P&gt;Here's the post, from June of 2017. It was required for my copy of ASA 9.9(1)/ASDM 7.9(1)151.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportforums.cisco.com/t5/tkb/articleprintpage/tkb-id/5041-docs-security/article-id/625" target="_blank"&gt;https://supportforums.cisco.com/t5/tkb/articleprintpage/tkb-id/5041-docs-security/article-id/625&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;-I realize this is old, but thought I'd add to it for people searching for documentation like myself.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 17:05:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-server-group-asking-for-realm-id-for-radius/m-p/3350015#M550356</guid>
      <dc:creator>briancarson</dc:creator>
      <dc:date>2018-03-16T17:05:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Server Group Asking For Realm-id for RADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-server-group-asking-for-realm-id-for-radius/m-p/3350217#M550357</link>
      <description>&lt;P&gt;Interesting. I had only associated realms with Firepower previously. The ASA release notes, configuration guide and command reference are silent on this option. I do see it from the cli on an ASA running 9.9(1).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;ccielab-asa(config-aaa-server-group)# aaa-server test1 protocol ldap    
ccielab-asa(config-aaa-server-group)# ?

AAA server configuration commands:
  exit                 Exit from aaa-server group configuration mode
  help                 Help for AAA server configuration commands
  max-failed-attempts  Specify the maximum number of failures that will be
                       allowed for any server in the group before that server
                       is deactivated
  no                   Remove an item from aaa-server group configuration
  reactivation-mode    Specify the method by which failed servers are
                       reactivated
  realm-id             Enter this keyword to specify the internal realm id
ccielab-asa(config-aaa-server-group)# realm-id ?

aaa-server-group mode commands/options:
  &amp;lt;0-65535&amp;gt;  Internal realm id
ccielab-asa(config-aaa-server-group)# end      
ccielab-asa# sh ver | i bin
System image file is "disk0:/asa991-smp-k8.bin"
ccielab-asa#&lt;/PRE&gt;</description>
      <pubDate>Sat, 17 Mar 2018 13:05:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-server-group-asking-for-realm-id-for-radius/m-p/3350217#M550357</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-03-17T13:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Server Group Asking For Realm-id for RADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-server-group-asking-for-realm-id-for-radius/m-p/3350253#M550358</link>
      <description>Hi  briancarson,&lt;BR /&gt;&lt;BR /&gt;actually that was my though :). It good to share so other can find it and&lt;BR /&gt;do not have to search very long. Thx for sharing.&lt;BR /&gt;&lt;BR /&gt;Cheers&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sat, 17 Mar 2018 16:18:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-server-group-asking-for-realm-id-for-radius/m-p/3350253#M550358</guid>
      <dc:creator>Marcel70</dc:creator>
      <dc:date>2018-03-17T16:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Server Group Asking For Realm-id for RADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-server-group-asking-for-realm-id-for-radius/m-p/3350965#M550359</link>
      <description>&lt;P&gt;On further exploring, one additional item to note. There is no mention/record of the parameter in the 'show running' in either CLI or ASDM.&lt;/P&gt;
&lt;P&gt;I am unsure if this is the first version (ASDM) it has appeared. The realm-id field is numeric, 0-&lt;SPAN class="cwcot"&gt;65535. You cannot save without a number in this field and you can add multiple server groups with the identical value.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="cwcot"&gt;I suppose this could be implemented in a future version expanding cross-realm authentication for Radius servers? Not something I'll need to worry about for the foreseeable future.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;edit: I stand corrected. I checked 'show start' and it is there. Right under the aaa-server protocol entry.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 16:04:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-server-group-asking-for-realm-id-for-radius/m-p/3350965#M550359</guid>
      <dc:creator>briancarson</dc:creator>
      <dc:date>2018-03-19T16:04:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Server Group Asking For Realm-id for RADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-server-group-asking-for-realm-id-for-radius/m-p/3357044#M550360</link>
      <description>Just a quick update in case anyone finds this. I upgraded ASDM/ASA yesterday. Now on 7.9(2) ASDM and 9.9(2). The realm-id has been removed from config and the "Edit AAA Server Group" gui.</description>
      <pubDate>Wed, 28 Mar 2018 20:24:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-server-group-asking-for-realm-id-for-radius/m-p/3357044#M550360</guid>
      <dc:creator>briancarson</dc:creator>
      <dc:date>2018-03-28T20:24:46Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Server Group Asking For Realm-id for RADIUS</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-server-group-asking-for-realm-id-for-radius/m-p/3357439#M550361</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/457643"&gt;@briancarson&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the update. I see the same on my lab system as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Interestingly Cisco didn't mention fixing this problem in the release notes.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Mar 2018 12:22:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-server-group-asking-for-realm-id-for-radius/m-p/3357439#M550361</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-03-29T12:22:17Z</dc:date>
    </item>
  </channel>
</rss>

