<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 12.2(11)JA1 &amp; Admin Access via RADIUS/ACS3.2 in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/12-2-11-ja1-admin-access-via-radius-acs3-2/m-p/304508#M13440</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think this is a known issue, not sure if there's any work around but if the admin is configured in an internal database this will work fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 17 Dec 2003 16:20:22 GMT</pubDate>
    <dc:creator>thomas.chen</dc:creator>
    <dc:date>2003-12-17T16:20:22Z</dc:date>
    <item>
      <title>12.2(11)JA1 &amp; Admin Access via RADIUS/ACS3.2</title>
      <link>https://community.cisco.com/t5/wireless/12-2-11-ja1-admin-access-via-radius-acs3-2/m-p/304507#M13439</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the problem:&lt;/P&gt;&lt;P&gt;I am not able to authenticate the administrator for an aironet1200 AP with 12.2(11)JA1-Firmware over an external RADIUS-Server (Cisco ACS3.2).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the configuration:&lt;/P&gt;&lt;P&gt;Aironet1200:&lt;/P&gt;&lt;P&gt;1.	Security-&amp;gt;Admin Access-&amp;gt;Administrator Authenticated by:-&amp;gt;Authentication Server if not found in Local List&lt;/P&gt;&lt;P&gt;2.	Server Manager-&amp;gt; Current Server List -&amp;gt;RADIUS-&amp;gt;IP,shared-Secret,default Auth. And Acc-Ports, Admin Authentication&lt;/P&gt;&lt;P&gt;ACS 3.2:&lt;/P&gt;&lt;P&gt;1.	Network Configuration-&amp;gt;New AAA Client-&amp;gt; AAA Client IP Address, Shared Secret-&amp;gt; Authenticate Using=RADIUS (Cisco IOS/PIX)&lt;/P&gt;&lt;P&gt;2.	Interface Configuration-&amp;gt; RADIUS (Cisco IOS/PIX)-&amp;gt; [026/009/001] cisco-av-pair for User and Group&lt;/P&gt;&lt;P&gt;3.	User Setup-&amp;gt;Add User-&amp;gt;Username,Password-&amp;gt;[ 009\001] cisco-av-pair = aironet:admin-capability=write+ident+admin+firmware&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the symptoms:&lt;/P&gt;&lt;P&gt;1.	I cant login the Web-Interface. The login Dialog just does not disappear.&lt;/P&gt;&lt;P&gt;2.	I cant login telnet. The feedback:  % Authentication failed&lt;/P&gt;&lt;P&gt;3.	ACS says at Report and Activity-&amp;gt;Passed Authentication-&amp;gt;Authen O.K !!!&lt;/P&gt;&lt;P&gt;4.	The radius debugging on Aironet 12000 shows following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Mar  1 17:09:51.359: Radius: radius_port_info() success=1 radius_nas_port=1&lt;/P&gt;&lt;P&gt;*Mar  1 17:09:51.359: RADIUS: added cisco VSA 2 len 4 "tty2"&lt;/P&gt;&lt;P&gt;*Mar  1 17:09:51.360: RADIUS: Send to tty2 id 23 193.22.125.123:1645, Access-Req&lt;/P&gt;&lt;P&gt;uest, len 93&lt;/P&gt;&lt;P&gt;*Mar  1 17:09:51.360: RADIUS:  authenticator 1A 74 6C 37 29 55 BA 52 - 07 D6 A1&lt;/P&gt;&lt;P&gt;B8 D7 67 60 CF&lt;/P&gt;&lt;P&gt;*Mar  1 17:09:51.361: RADIUS:  NAS-IP-Address      [4]   6   193.22.125.124&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Mar  1 17:09:51.361: RADIUS:  NAS-Port            [5]   6   2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Mar  1 17:09:51.361: RADIUS:  Vendor, Cisco       [26]  12&lt;/P&gt;&lt;P&gt;*Mar  1 17:09:51.361: RADIUS:   cisco-nas-port     [2]   6   "tty2"&lt;/P&gt;&lt;P&gt;*Mar  1 17:09:51.361: RADIUS:  NAS-Port-Type       [61]  6   Virtual&lt;/P&gt;&lt;P&gt;       [5]&lt;/P&gt;&lt;P&gt;*Mar  1 17:09:51.361: RADIUS:  User-Name           [1]   10  "abrancat"&lt;/P&gt;&lt;P&gt;*Mar  1 17:09:51.361: RADIUS:  Calling-Station-Id  [31]  15  "193.22.125.41"&lt;/P&gt;&lt;P&gt;*Mar  1 17:09:51.361: RADIUS:  User-Password       [2]   18  *&lt;/P&gt;&lt;P&gt;*Mar  1 17:09:51.381: RADIUS: Received from id 23 193.22.125.123:1645, Access-Ac&lt;/P&gt;&lt;P&gt;cept, len 109&lt;/P&gt;&lt;P&gt;*Mar  1 17:09:51.381: RADIUS:  authenticator 5A 36 0F C0 33 71 22 A3 - 33 8E 2E&lt;/P&gt;&lt;P&gt;D3 1D A2 88 39&lt;/P&gt;&lt;P&gt;*Mar  1 17:09:51.381: RADIUS:  Vendor, Cisco       [26]  59&lt;/P&gt;&lt;P&gt;*Mar  1 17:09:51.381: RADIUS:   Cisco AVpair       [1]   53  "aironet:admin-capa&lt;/P&gt;&lt;P&gt;bility=write+ident+admin+firmware"&lt;/P&gt;&lt;P&gt;*Mar  1 17:09:51.382: RADIUS:  Class               [25]  30&lt;/P&gt;&lt;P&gt;*Mar  1 17:09:51.382: RADIUS:   43 49 53 43 4F 41 43 53 3A 30 30 30 30 30 39 30&lt;/P&gt;&lt;P&gt; [CISCOACS:0000090]&lt;/P&gt;&lt;P&gt;*Mar  1 17:09:51.383: RADIUS:   34 2F 63 31 31 36 37 64 37 63 2F 32&lt;/P&gt;&lt;P&gt; [4/c1167d7c/2]&lt;/P&gt;&lt;P&gt;*Mar  1 17:09:51.383: RADIUS: saved authorization data for user 8A9F74 at 90C254&lt;/P&gt;&lt;P&gt;*Mar  1 17:09:51.383: RADIUS: cisco AVPair "aironet:admin-capability=write+ident&lt;/P&gt;&lt;P&gt;+admin+firmware" not applied for shell &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What have I done wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Angelo Brancato&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 04 Jul 2021 16:13:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/12-2-11-ja1-admin-access-via-radius-acs3-2/m-p/304507#M13439</guid>
      <dc:creator>abrancat</dc:creator>
      <dc:date>2021-07-04T16:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: 12.2(11)JA1 &amp; Admin Access via RADIUS/ACS3.2</title>
      <link>https://community.cisco.com/t5/wireless/12-2-11-ja1-admin-access-via-radius-acs3-2/m-p/304508#M13440</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think this is a known issue, not sure if there's any work around but if the admin is configured in an internal database this will work fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Dec 2003 16:20:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/12-2-11-ja1-admin-access-via-radius-acs3-2/m-p/304508#M13440</guid>
      <dc:creator>thomas.chen</dc:creator>
      <dc:date>2003-12-17T16:20:22Z</dc:date>
    </item>
  </channel>
</rss>

