cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1440
Views
0
Helpful
1
Replies

CSR1000v iVRF RADIUS attribute

flq06
Level 1
Level 1

Hello,

 

I've successfully setup the basis of SSLVPN on CSR1000v.

 

I'm using the "webvpn:addr-pool" to assign IPs to the clients which works great.

 

However I need to put users in specific VRFs based on the RADIUS policy.

 

I tried using the "webvpn:user-vpn-group" attribute but it seems deprecated:

 

*Apr 11 19:17:07.138: CRYPTO-SSL-AAA: addr-pool: Processing AV

*Apr 11 19:17:07.138: CRYPTO-SSL-AAA: Address pool test

*Apr 11 19:17:07.138: CRYPTO-SSL-AAA: user-vpn-group: Processing AV

*Apr 11 19:17:07.138: CRYPTO-SSL-AAA: Unsupported AV Pair

 

Any idea what AVPair to use for VRF?

 

Thanks,

1 Reply 1

The recommended cisco-avpair is ip:vrf-id. IOS-XE will read it and act
accordingly
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: