<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco-AVPair multiple attributes in a string in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-avpair-multiple-attributes-in-a-string/m-p/2360820#M89082</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you have a tacacs solution you can move this integration over to there. However you will need to doublecheck all attributes and profiles to make sure the same users isnt gaining full access to any other device if TACACS is used as your centralized administration authority.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 31 Dec 2013 07:39:37 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2013-12-31T07:39:37Z</dc:date>
    <item>
      <title>Cisco-AVPair multiple attributes in a string</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-avpair-multiple-attributes-in-a-string/m-p/2360817#M89076</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm deploing auth-proxy services on my ISR 1861. I'm using a Cloudessa public RADIUS Service.&lt;/P&gt;&lt;P&gt;It works fine. I'have only one problem. It seems that in group policies i can define only one string attribute Cisco-AVPair string.&lt;/P&gt;&lt;P&gt;I try to explain better .. I can choice all RFC and Vendor well known attributes ... i can select multiple&amp;nbsp; types attribute (Session-Timeout, Service-Type, and so on ...) and i can insert the desired value for each of these attributes ... attributes are correctely sent to Router (debug radius). If i insert Cisco-AVPair attribute i can insert a string with attribute in single line ... for example auth-proxy:priv-lvl=15 (mandatory) ... but i can't add another&amp;nbsp; Cisco-AVPair attribute string to add ACL ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;auth-proxy:proxyacl#1=deny ip any 62.149.128.40&lt;/P&gt;&lt;P&gt;auth-proxy:proxyacl#2=permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so the question is ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to insert in a single&amp;nbsp; Cisco-AVPair attribute string for example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;auth-proxy:priv-lvl=15 &lt;/P&gt;&lt;P&gt;auth-proxy:proxyacl#1=deny ip any 62.149.128.40&lt;/P&gt;&lt;P&gt;auth-proxy:proxyacl#2=permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in order to instruct the router to use it ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'v tried using &amp;lt;R&amp;gt; or \r ... comma&amp;nbsp; and space with and without double quotes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;auth-proxy:priv-lvl=15&amp;lt;R&amp;gt;auth-proxy:proxyacl#1=deny ip any 62.149.128.40&lt;/P&gt;&lt;P&gt;"auth-proxy:priv-lvl=15" &amp;lt;R&amp;gt;a "uth-proxy:proxyacl#1=deny ip any 62.149.128.40"&lt;/P&gt;&lt;P&gt;auth-proxy:priv-lvl=15,auth-proxy:proxyacl#1=deny ip any 62.149.128.40&lt;/P&gt;&lt;P&gt;"auth-proxy:priv-lvl=15";auth-proxy:proxyacl#1=deny ip any 62.149.128.40"&lt;/P&gt;&lt;P&gt;... and so on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but nothing it seems to works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've opened a tocket to Cloudessa and i'm awaitng for a response ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;someone can help me ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is it possibile define multiple attributes in ona string ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:13:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-avpair-multiple-attributes-in-a-string/m-p/2360817#M89076</guid>
      <dc:creator>gdelpanta</dc:creator>
      <dc:date>2019-03-11T04:13:23Z</dc:date>
    </item>
    <item>
      <title>Cisco-AVPair multiple attributes in a string</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-avpair-multiple-attributes-in-a-string/m-p/2360818#M89077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks as if the radius dictionary for the cisco-av-pair should support multiple attributes, there is even an example on how to acheive this in the guide (a little dated ACS 4.0).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.0/user/guide/ad.html#wp168530"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.0/user/guide/ad.html#wp168530&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In most of my designs for auth-proxy I have had to enter each cisco-av-pair with each proxy-acl#1...statement so it seems to me as if there maybe a bug in your radius solution not allowing as many cisco-av-pair in your authorization profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Dec 2013 06:25:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-avpair-multiple-attributes-in-a-string/m-p/2360818#M89077</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-12-31T06:25:20Z</dc:date>
    </item>
    <item>
      <title>Cisco-AVPair multiple attributes in a string</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-avpair-multiple-attributes-in-a-string/m-p/2360819#M89078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;Thank you ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are right ... it's a for sure a Radius limitation. I've already wirtten to Cloudessa support ... i written to Cisco Support Forum too wishing for a workaround or a way to insert multiple AV row in a single entry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If multiple AV Pair in a single strin entry and Caloudessa doesn't fix i'm stucked ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cloudessa is the only free Radius as Service found in Internet ... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Dec 2013 07:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-avpair-multiple-attributes-in-a-string/m-p/2360819#M89078</guid>
      <dc:creator>gdelpanta</dc:creator>
      <dc:date>2013-12-31T07:29:15Z</dc:date>
    </item>
    <item>
      <title>Cisco-AVPair multiple attributes in a string</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-avpair-multiple-attributes-in-a-string/m-p/2360820#M89082</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you have a tacacs solution you can move this integration over to there. However you will need to doublecheck all attributes and profiles to make sure the same users isnt gaining full access to any other device if TACACS is used as your centralized administration authority.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Dec 2013 07:39:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-avpair-multiple-attributes-in-a-string/m-p/2360820#M89082</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2013-12-31T07:39:37Z</dc:date>
    </item>
    <item>
      <title>Reply attribute should use a</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-avpair-multiple-attributes-in-a-string/m-p/2360821#M89083</link>
      <description>&lt;P&gt;Reply attribute should use a += operator for additional avpairs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;

&lt;PRE style="border: 0px; font-family: 'Courier 10 Pitch', Courier, monospace; margin-bottom: 1.625em; outline-width: 0px; padding: 0.75em 1.625em; vertical-align: baseline; font-stretch: normal; line-height: 1.5; overflow: auto; color: rgb(55, 55, 55); background: rgb(244, 244, 244);"&gt;
admin           Cleartext-Password := 1234QWer
                Service-Type = Administrative-User,
                Cisco-AVPair = "shell:roles=network-admin",
                Cisco-AVPair += "shell:priv-lvl=15"

ops             Cleartext-Password := 1234QWer
                Service-Type = NAS-Prompt-User,
                Cisco-AVPair = "shell:roles=network-operator",
                Cisco-AVPair += "shell:priv-lvl=1"

tom             Auth-Type := System
                Service-Type = Administrative-User,
                Cisco-AVPair = "shell:roles=network-admin",
                Cisco-AVPair += "shell:priv-lvl=15"&lt;/PRE&gt;

&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From&amp;nbsp;http://www.layerzero.nl/blog/2013/05/using-freeradius-with-cisco-devices/&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Nov 2014 00:52:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-avpair-multiple-attributes-in-a-string/m-p/2360821#M89083</guid>
      <dc:creator>adolcabr</dc:creator>
      <dc:date>2014-11-19T00:52:18Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-avpair-multiple-attributes-in-a-string/m-p/2360822#M89084</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Did you manage to send multiple &amp;nbsp;AV pairs from cloudessa to cisco eqipement?&lt;/P&gt;
&lt;P&gt;I am facing the same issue with proxy acl.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Branimir Turk&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2016 12:58:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-avpair-multiple-attributes-in-a-string/m-p/2360822#M89084</guid>
      <dc:creator>Branimir Turk</dc:creator>
      <dc:date>2016-02-09T12:58:52Z</dc:date>
    </item>
  </channel>
</rss>

