<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Prime 2.2 and ACS5.6 - Radius authentication - Login issues in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/prime-2-2-and-acs5-6-radius-authentication-login-issues/m-p/2725281#M57242</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone had any luck setting up Prime to use Radius authentication for administration users against ACS5.6?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the moment the ACS is returning successful authentication '11002 Returned RADIUS Access-Accept' on an attempted Prime login although Prime returns incorrect username/password / access denied.&lt;/P&gt;&lt;P&gt;Two schools of though based on previous posts / online searches;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Within the Access Service &amp;gt; Allowed Protocols tab &amp;gt; 'Send as User-Name in RADIUS Access-Accept' radio buttons&lt;/P&gt;&lt;P&gt;Currently set as the 'Principal User Name', which as I understand provides the certificate name, would 'RADIUS Access-Request User-Name' make more sense?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. RADIUS attribute requirement&amp;nbsp;&lt;/P&gt;&lt;P&gt;Post located but this refers to TACACS+ attributes - exporting task lists&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportforums.cisco.com/discussion/12394496/cisco-prime-radius-users&amp;nbsp;" target="_blank"&gt;https://supportforums.cisco.com/discussion/12394496/cisco-prime-radius-users&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Would a similar task need to be completed for RADIUS?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 06:07:58 GMT</pubDate>
    <dc:creator>3iron</dc:creator>
    <dc:date>2019-03-11T06:07:58Z</dc:date>
    <item>
      <title>Prime 2.2 and ACS5.6 - Radius authentication - Login issues</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-2-2-and-acs5-6-radius-authentication-login-issues/m-p/2725281#M57242</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone had any luck setting up Prime to use Radius authentication for administration users against ACS5.6?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the moment the ACS is returning successful authentication '11002 Returned RADIUS Access-Accept' on an attempted Prime login although Prime returns incorrect username/password / access denied.&lt;/P&gt;&lt;P&gt;Two schools of though based on previous posts / online searches;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Within the Access Service &amp;gt; Allowed Protocols tab &amp;gt; 'Send as User-Name in RADIUS Access-Accept' radio buttons&lt;/P&gt;&lt;P&gt;Currently set as the 'Principal User Name', which as I understand provides the certificate name, would 'RADIUS Access-Request User-Name' make more sense?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. RADIUS attribute requirement&amp;nbsp;&lt;/P&gt;&lt;P&gt;Post located but this refers to TACACS+ attributes - exporting task lists&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportforums.cisco.com/discussion/12394496/cisco-prime-radius-users&amp;nbsp;" target="_blank"&gt;https://supportforums.cisco.com/discussion/12394496/cisco-prime-radius-users&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Would a similar task need to be completed for RADIUS?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:07:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-2-2-and-acs5-6-radius-authentication-login-issues/m-p/2725281#M57242</guid>
      <dc:creator>3iron</dc:creator>
      <dc:date>2019-03-11T06:07:58Z</dc:date>
    </item>
    <item>
      <title>You will need to send </title>
      <link>https://community.cisco.com/t5/network-access-control/prime-2-2-and-acs5-6-radius-authentication-login-issues/m-p/2725282#M57245</link>
      <description>&lt;P&gt;You will need to send&amp;nbsp; attributes for radius authentication to work. For example for super user permissions to the root virtual domain you need the following:&lt;/P&gt;&lt;P&gt;cisco-av-pair = NCS:role0=Super Users&lt;/P&gt;&lt;P&gt;cisco-av-pair = NCS:virtual-domain0=ROOT-DOMAIN&lt;/P&gt;&lt;P&gt;In the user group list you'll see next to each&amp;nbsp; group you'll see task list links. Usually you only need to put in the role and the virtual domain.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2015 09:12:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-2-2-and-acs5-6-radius-authentication-login-issues/m-p/2725282#M57245</guid>
      <dc:creator>M. Wisely</dc:creator>
      <dc:date>2015-10-07T09:12:57Z</dc:date>
    </item>
    <item>
      <title> Hi Martin,Thanks for the</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-2-2-and-acs5-6-radius-authentication-login-issues/m-p/2725283#M57246</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Martin,&lt;/P&gt;&lt;P&gt;Thanks for the comment - that makes sense - I have created a new authorisation profile with the values specified, will update tomorrow once completed some further testing.&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Wed, 07 Oct 2015 15:36:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-2-2-and-acs5-6-radius-authentication-login-issues/m-p/2725283#M57246</guid>
      <dc:creator>3iron</dc:creator>
      <dc:date>2015-10-07T15:36:56Z</dc:date>
    </item>
    <item>
      <title>Testing and working a treat</title>
      <link>https://community.cisco.com/t5/network-access-control/prime-2-2-and-acs5-6-radius-authentication-login-issues/m-p/2725284#M57247</link>
      <description>&lt;P&gt;Testing and working a treat!&lt;/P&gt;&lt;P&gt;Can see the two additional attributes in the ACS Reporting and Monitoring logs passing to Prime.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 10:03:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/prime-2-2-and-acs5-6-radius-authentication-login-issues/m-p/2725284#M57247</guid>
      <dc:creator>3iron</dc:creator>
      <dc:date>2015-10-08T10:03:10Z</dc:date>
    </item>
  </channel>
</rss>

