<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: on-for-login-auth attribute Cisco ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/on-for-login-auth-attribute-cisco-ise/m-p/5096216#M589354</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1683156"&gt;@Jason2005&lt;/a&gt;&amp;nbsp; most of these commands are described in the Cisco ISE wired prescriptive guide &lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Send the Service-Type attribute in the authentication packets, which is important for ISE to distinguish between the different authentication methods:&lt;/P&gt;
&lt;PRE&gt;c9300-Sw(config)#radius-server attribute 6 on-for-login-auth&lt;/PRE&gt;
&lt;P&gt;Send the IP address of an endpoint to the RADIUS server in the access request:&lt;/P&gt;
&lt;PRE&gt;c9300-Sw(config)#radius-server attribute 8 include-in-access-req&lt;/PRE&gt;
&lt;P&gt;Include the class attribute in an access request for network access authorization:&lt;/P&gt;
&lt;PRE&gt;c9300-Sw(config)#radius-server attribute 25 access-request include&lt;/PRE&gt;
&lt;P&gt;Define how a switch must detect a RADIUS server reachability failure:&lt;/P&gt;
&lt;PRE&gt;c9300-Sw(config)#radius-server dead-criteria time 10 tries 3&lt;/PRE&gt;
&lt;P class="codeblock"&gt;&lt;SPAN&gt;&lt;SPAN class="content"&gt;Specifies the number of seconds a switch waits for a reply to a RADIUS request before resending the request. The default is 5 seconds; the range is 1 to 1000.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="codeblock"&gt;&lt;SPAN&gt;Switch&lt;/SPAN&gt;(config)# &lt;KBD class="userinput"&gt;&lt;STRONG&gt;radius-server timeout 3&lt;/STRONG&gt;&lt;/KBD&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;SPAN class="content"&gt;&lt;SPAN&gt;Enables the network access server to recognize and use vendor-specific attributes as defined by RADIUS IETF attribute 26&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE&gt;Device(config)# radius-server vsa send&amp;nbsp;&lt;SPAN&gt; [&lt;SPAN class="synph"&gt;&lt;SPAN class="kwd"&gt;accounting&lt;/SPAN&gt;&lt;/SPAN&gt; | &lt;SPAN class="synph"&gt;&lt;SPAN class="kwd"&gt;authentication&lt;/SPAN&gt;&lt;/SPAN&gt;] &lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/en/US/docs/switches/lan/catalyst3850/software/release/3.2_0_se/multibook/configuration_guide/b_consolidated_config_guide_3850_chapter_0101111.html" target="_blank"&gt;https://www.cisco.com/en/US/docs/switches/lan/catalyst3850/software/release/3.2_0_se/multibook/configuration_guide/b_consolidated_config_guide_3850_chapter_0101111.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 09 May 2024 14:26:43 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2024-05-09T14:26:43Z</dc:date>
    <item>
      <title>on-for-login-auth attribute Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/on-for-login-auth-attribute-cisco-ise/m-p/5096205#M589352</link>
      <description>&lt;P&gt;Can someone explain to me each of these commands :&amp;nbsp;&lt;BR /&gt;SW2(config-radius-server)#radius-server attribute 6 on-for-login-auth&lt;BR /&gt;SW2(config)#radius-server attribute 8 include-in-access-req&lt;BR /&gt;SW2(config)#radius-server attribute 25 access-request include&lt;BR /&gt;SW2(config)#radius-server vsa send accounting&lt;BR /&gt;SW2(config)#radius-server vsa send authentication&lt;BR /&gt;SW2(config)#radius-server dead-criteria time 30 tries 3&lt;BR /&gt;SW2(config)#radius-server timeout 2&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 14:15:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-for-login-auth-attribute-cisco-ise/m-p/5096205#M589352</guid>
      <dc:creator>Jason2005</dc:creator>
      <dc:date>2024-05-09T14:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: on-for-login-auth attribute Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/on-for-login-auth-attribute-cisco-ise/m-p/5096216#M589354</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1683156"&gt;@Jason2005&lt;/a&gt;&amp;nbsp; most of these commands are described in the Cisco ISE wired prescriptive guide &lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_blank"&gt;https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Send the Service-Type attribute in the authentication packets, which is important for ISE to distinguish between the different authentication methods:&lt;/P&gt;
&lt;PRE&gt;c9300-Sw(config)#radius-server attribute 6 on-for-login-auth&lt;/PRE&gt;
&lt;P&gt;Send the IP address of an endpoint to the RADIUS server in the access request:&lt;/P&gt;
&lt;PRE&gt;c9300-Sw(config)#radius-server attribute 8 include-in-access-req&lt;/PRE&gt;
&lt;P&gt;Include the class attribute in an access request for network access authorization:&lt;/P&gt;
&lt;PRE&gt;c9300-Sw(config)#radius-server attribute 25 access-request include&lt;/PRE&gt;
&lt;P&gt;Define how a switch must detect a RADIUS server reachability failure:&lt;/P&gt;
&lt;PRE&gt;c9300-Sw(config)#radius-server dead-criteria time 10 tries 3&lt;/PRE&gt;
&lt;P class="codeblock"&gt;&lt;SPAN&gt;&lt;SPAN class="content"&gt;Specifies the number of seconds a switch waits for a reply to a RADIUS request before resending the request. The default is 5 seconds; the range is 1 to 1000.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE class="codeblock"&gt;&lt;SPAN&gt;Switch&lt;/SPAN&gt;(config)# &lt;KBD class="userinput"&gt;&lt;STRONG&gt;radius-server timeout 3&lt;/STRONG&gt;&lt;/KBD&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;SPAN class="content"&gt;&lt;SPAN&gt;Enables the network access server to recognize and use vendor-specific attributes as defined by RADIUS IETF attribute 26&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;PRE&gt;Device(config)# radius-server vsa send&amp;nbsp;&lt;SPAN&gt; [&lt;SPAN class="synph"&gt;&lt;SPAN class="kwd"&gt;accounting&lt;/SPAN&gt;&lt;/SPAN&gt; | &lt;SPAN class="synph"&gt;&lt;SPAN class="kwd"&gt;authentication&lt;/SPAN&gt;&lt;/SPAN&gt;] &lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.cisco.com/en/US/docs/switches/lan/catalyst3850/software/release/3.2_0_se/multibook/configuration_guide/b_consolidated_config_guide_3850_chapter_0101111.html" target="_blank"&gt;https://www.cisco.com/en/US/docs/switches/lan/catalyst3850/software/release/3.2_0_se/multibook/configuration_guide/b_consolidated_config_guide_3850_chapter_0101111.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 14:26:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-for-login-auth-attribute-cisco-ise/m-p/5096216#M589354</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-05-09T14:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: on-for-login-auth attribute Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/on-for-login-auth-attribute-cisco-ise/m-p/5096225#M589355</link>
      <description>&lt;P&gt;Does an attribute refers to a segment on a Packet ?&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 14:34:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-for-login-auth-attribute-cisco-ise/m-p/5096225#M589355</guid>
      <dc:creator>Jason2005</dc:creator>
      <dc:date>2024-05-09T14:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: on-for-login-auth attribute Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/on-for-login-auth-attribute-cisco-ise/m-p/5096233#M589356</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_radatt/configuration/xe-16/sec-usr-radatt-xe-16-book/sec-rad-ov-ietf-attr.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_radatt/configuration/xe-16/sec-usr-radatt-xe-16-book/sec-rad-ov-ietf-attr.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 May 2024 14:38:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/on-for-login-auth-attribute-cisco-ise/m-p/5096233#M589356</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-05-09T14:38:15Z</dc:date>
    </item>
  </channel>
</rss>

