<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA AAA Authentication: adding radius server fails in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-aaa-authentication-adding-radius-server-fails/m-p/1257332#M763841</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's my aaa config:&lt;/P&gt;&lt;P&gt;aaa-server RADIUS1 protocol radius&lt;/P&gt;&lt;P&gt;aaa-server RADIUS1 host 172.30.10.24&lt;/P&gt;&lt;P&gt; key SuperSecretKey&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication enable console LOCAL&lt;/P&gt;&lt;P&gt;aaa authorization command LOCAL&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whenever I try to add the radius server to ssh console it fails:&lt;/P&gt;&lt;P&gt;asa1(config)# aaa authentication ssh console RADIUS1 LOCAL&lt;/P&gt;&lt;P&gt;Range already exists.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any hints?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 16:36:13 GMT</pubDate>
    <dc:creator>jcw009</dc:creator>
    <dc:date>2019-03-11T16:36:13Z</dc:date>
    <item>
      <title>ASA AAA Authentication: adding radius server fails</title>
      <link>https://community.cisco.com/t5/network-security/asa-aaa-authentication-adding-radius-server-fails/m-p/1257332#M763841</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's my aaa config:&lt;/P&gt;&lt;P&gt;aaa-server RADIUS1 protocol radius&lt;/P&gt;&lt;P&gt;aaa-server RADIUS1 host 172.30.10.24&lt;/P&gt;&lt;P&gt; key SuperSecretKey&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication enable console LOCAL&lt;/P&gt;&lt;P&gt;aaa authorization command LOCAL&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whenever I try to add the radius server to ssh console it fails:&lt;/P&gt;&lt;P&gt;asa1(config)# aaa authentication ssh console RADIUS1 LOCAL&lt;/P&gt;&lt;P&gt;Range already exists.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any hints?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:36:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-aaa-authentication-adding-radius-server-fails/m-p/1257332#M763841</guid>
      <dc:creator>jcw009</dc:creator>
      <dc:date>2019-03-11T16:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA AAA Authentication: adding radius server fails</title>
      <link>https://community.cisco.com/t5/network-security/asa-aaa-authentication-adding-radius-server-fails/m-p/1257333#M763842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First remove the existing config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then apply the new config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication ssh console RADIUS1 LOCAL &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 07:30:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-aaa-authentication-adding-radius-server-fails/m-p/1257333#M763842</guid>
      <dc:creator>Herbert Baerten</dc:creator>
      <dc:date>2009-11-05T07:30:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA AAA Authentication: adding radius server fails</title>
      <link>https://community.cisco.com/t5/network-security/asa-aaa-authentication-adding-radius-server-fails/m-p/1257334#M763845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If I do this, will it mean that anyone who can be authenticated on the radius server can log into the firewall?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 14:04:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-aaa-authentication-adding-radius-server-fails/m-p/1257334#M763845</guid>
      <dc:creator>jcw009</dc:creator>
      <dc:date>2009-11-05T14:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: ASA AAA Authentication: adding radius server fails</title>
      <link>https://community.cisco.com/t5/network-security/asa-aaa-authentication-adding-radius-server-fails/m-p/1257335#M763846</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Depending on what Radius server it is, you may or may not be able to configure it to accept/reject the authentication based on some parameters like the ip address of the radius client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But as far as the ASA is concerned, if the Radius server says it's ok, it lets the user in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I assumed that that is what you wanted, since you were trying to implement this command?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 14:15:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-aaa-authentication-adding-radius-server-fails/m-p/1257335#M763846</guid>
      <dc:creator>Herbert Baerten</dc:creator>
      <dc:date>2009-11-05T14:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA AAA Authentication: adding radius server fails</title>
      <link>https://community.cisco.com/t5/network-security/asa-aaa-authentication-adding-radius-server-fails/m-p/1257336#M763847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think what I was trying to do was use my radius box like a tacacs box. It doesn't seem like that would work. I'm using Windows 2003 IAS as a radius server to authenticate vpn clients, and don't want anyone who can vpn in login to the firewall. May have to look into setting up a tacas box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 15:24:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-aaa-authentication-adding-radius-server-fails/m-p/1257336#M763847</guid>
      <dc:creator>jcw009</dc:creator>
      <dc:date>2009-11-05T15:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: ASA AAA Authentication: adding radius server fails</title>
      <link>https://community.cisco.com/t5/network-security/asa-aaa-authentication-adding-radius-server-fails/m-p/1257337#M763848</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could pass back the IETF service-type attribute on the radius server. You can then use this to restrict the access for these users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is what is required for the &lt;/P&gt;&lt;P&gt;radius delivered service-type attribute to be enforced for CLI access:&lt;/P&gt;&lt;P&gt;        &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;       "aaa authorization exec authentication-server" must be enabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;       "aaa authentication enable console &lt;AUTH-SERVER&gt;" must be enabled.&lt;/AUTH-SERVER&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;       IETF RADIUS Service-Type attribute must be returned in the &lt;/P&gt;&lt;P&gt;access-accept packet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also note, make sure you are using a version of code with the fix for CSCsk89452&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are using local authentication instead of radius this can also be done with the following commands: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username &lt;NAME&gt; attributes&lt;/NAME&gt;&lt;/P&gt;&lt;P&gt;  service-type &amp;lt;(admin,nas-prompt,remote-access)&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-heather&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 18:25:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-aaa-authentication-adding-radius-server-fails/m-p/1257337#M763848</guid>
      <dc:creator>hdashnau</dc:creator>
      <dc:date>2009-11-05T18:25:36Z</dc:date>
    </item>
  </channel>
</rss>

