<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello;  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/access-list-for-aaa-radius-help-please/m-p/2783085#M173673</link>
    <description>&lt;P&gt;Hello;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What happens if you remove authorization? Are you able to get in?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Mike.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 04 Jan 2016 20:49:32 GMT</pubDate>
    <dc:creator>Maykol Rojas</dc:creator>
    <dc:date>2016-01-04T20:49:32Z</dc:date>
    <item>
      <title>Access-list for AAA radius? help please!</title>
      <link>https://community.cisco.com/t5/network-security/access-list-for-aaa-radius-help-please/m-p/2783084#M173672</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I'm trying to SSH into a vty line on my router that is sitting on the OUTSIDE interface of an ASA. I have tried from the actual router and a PC inside the ASA to and i'm getting the same "Open" message and go to enter the password but when i enter the password and hit enter it does nothing and just times out.&lt;/P&gt;
&lt;P&gt;Will post the relevant config for router and ASA below:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;hostname Router3&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;enable secret 5 $1$mERr$hx5rVt7rPNoS4wqbXKX7m0&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;aaa new-model&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;aaa authentication login loginlist group radius&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;aaa authorization exec authorlist group radius&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;username bob privilege 15 secret 5 $1$mERr$hx5rVt7rPNoS4wqbXKX7m0&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ip ssh version 2&lt;/P&gt;
&lt;P&gt;ip domain-name ROUTER3&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;interface FastEthernet0/0&lt;/P&gt;
&lt;P&gt;ip address 172.16.30.1 255.255.255.0&lt;/P&gt;
&lt;P&gt;duplex auto&lt;/P&gt;
&lt;P&gt;speed auto&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;ip classless&lt;/P&gt;
&lt;P&gt;ip route 10.30.0.0 255.255.255.0 172.16.30.2&lt;/P&gt;
&lt;P&gt;ip route 0.0.0.0 0.0.0.0 172.16.30.2&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;ip flow-export version 9&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;radius-server host 10.30.0.10 auth-port 1645 key Secret&lt;/P&gt;
&lt;P&gt;radius-server key Secret&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;line con 0&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;line aux 0&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;line vty 0 4&lt;/P&gt;
&lt;P&gt;login authentication loginlist&lt;/P&gt;
&lt;P&gt;transport input ssh&lt;/P&gt;
&lt;P&gt;line vty 5&lt;/P&gt;
&lt;P&gt;transport input ssh&lt;/P&gt;
&lt;P&gt;line vty 6 15&lt;/P&gt;
&lt;P&gt;transport input ssh&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;end&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;_______________________________________________________________________________________________________________&lt;/P&gt;
&lt;P&gt;Firewall ASA&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;hostname ASA2&lt;/P&gt;
&lt;P&gt;names&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface Ethernet0/0&lt;/P&gt;
&lt;P&gt;switchport access vlan 2&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface Ethernet0/1&lt;/P&gt;
&lt;P&gt;switchport access vlan 30&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface Ethernet0/2&lt;/P&gt;
&lt;P&gt;switchport access vlan 30&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;interface Vlan1&lt;/P&gt;
&lt;P&gt;no nameif&lt;/P&gt;
&lt;P&gt;security-level 100&lt;/P&gt;
&lt;P&gt;no ip address&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface Vlan2&lt;/P&gt;
&lt;P&gt;nameif outside&lt;/P&gt;
&lt;P&gt;security-level 0&lt;/P&gt;
&lt;P&gt;ip address 172.16.30.2 255.255.255.0&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface Vlan30&lt;/P&gt;
&lt;P&gt;nameif inside&lt;/P&gt;
&lt;P&gt;security-level 100&lt;/P&gt;
&lt;P&gt;ip address 10.30.0.1 255.255.255.0&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;webvpn&lt;/P&gt;
&lt;P&gt;enable outside&lt;/P&gt;
&lt;P&gt;enable inside&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;route outside 0.0.0.0 0.0.0.0 172.16.30.1 1&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;access-list VPN_1 extended permit icmp 10.30.0.0 255.255.255.0 10.20.0.0 255.255.255.0&lt;/P&gt;
&lt;P&gt;access-list test extended permit icmp 10.20.0.0 255.255.255.0 10.30.0.0 255.255.255.0&lt;/P&gt;
&lt;P&gt;access-list test extended permit icmp host 172.16.30.1 host 10.30.0.10&lt;/P&gt;
&lt;P&gt;access-list aaa extended permit udp any 10.30.0.0 255.255.255.0 eq 1645&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;access-group aaa in interface outside&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;group-policy webvpn internal&lt;/P&gt;
&lt;P&gt;group-policy webvpn attributes&lt;/P&gt;
&lt;P&gt;vpn-tunnel-protocol ssl-clientless&lt;/P&gt;
&lt;P&gt;webvpn&lt;/P&gt;
&lt;P&gt;url-list value test1&lt;/P&gt;
&lt;P&gt;username bob password 4IncP7vTjpaba2aF encrypted&lt;/P&gt;
&lt;P&gt;username bob attributes&lt;/P&gt;
&lt;P&gt;vpn-group-policy webvpn&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;class-map inspect&lt;/P&gt;
&lt;P&gt;match default-inspection-traffic&lt;/P&gt;
&lt;P&gt;class-map test&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;policy-map global&lt;/P&gt;
&lt;P&gt;class inspect&lt;/P&gt;
&lt;P&gt;inspect icmp&lt;/P&gt;
&lt;P&gt;class test&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;service-policy global global&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;telnet timeout 5&lt;/P&gt;
&lt;P&gt;ssh timeout 5&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;___________________________________________________________________________&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also, the details in packet tracer on the radius server are:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;client name = R1 &amp;nbsp; client ip= 172.16.30.1 &amp;nbsp;service type=radius &amp;nbsp;key=Secret &amp;nbsp;port=1645&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;username= tim &amp;nbsp;password= pass&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:05:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-for-aaa-radius-help-please/m-p/2783084#M173672</guid>
      <dc:creator>robbo79871</dc:creator>
      <dc:date>2019-03-12T07:05:27Z</dc:date>
    </item>
    <item>
      <title>Hello; </title>
      <link>https://community.cisco.com/t5/network-security/access-list-for-aaa-radius-help-please/m-p/2783085#M173673</link>
      <description>&lt;P&gt;Hello;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What happens if you remove authorization? Are you able to get in?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Mike.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jan 2016 20:49:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-for-aaa-radius-help-please/m-p/2783085#M173673</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2016-01-04T20:49:32Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/access-list-for-aaa-radius-help-please/m-p/2783086#M173676</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;No it still doesnt let me, i have changed the access lists arounf a bit to see if anything works. I am now able to ping from the outside router to the AAA server but cannot SSH into the router from an inside PC and get the radius authentication to work also.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are the new updates:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;object network asa_inside_address&lt;/P&gt;
&lt;P&gt;subnet 10.30.0.1 255.255.255.255&lt;/P&gt;
&lt;P&gt;object network inside_network&lt;/P&gt;
&lt;P&gt;subnet 10.30.0.0 255.255.255.0&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;access-list website_outside extended permit icmp any object asa_inside_address&lt;/P&gt;
&lt;P&gt;access-list website_outside extended permit udp any 10.30.0.0 255.255.255.0 eq 1645&lt;/P&gt;
&lt;P&gt;access-list website_outside extended permit icmp any object inside_network&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;access-group website_outside in interface outside&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;I must be missing something cant see what?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2016 00:17:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-list-for-aaa-radius-help-please/m-p/2783086#M173676</guid>
      <dc:creator>robbo79871</dc:creator>
      <dc:date>2016-01-05T00:17:20Z</dc:date>
    </item>
  </channel>
</rss>

