02-08-2011 04:40 PM - edited 03-10-2019 05:48 PM
Hi team,
We have ACS 5.2.0.26 installed and objects were migrated from ACS 4.2
I have configured device admin access using for some devices RADIUS, for other TACACS+.
For TACACS+ device admin works fine, but for RADIUS I've got strange error:
RADIUS Request dropped : 11033 Selected Service type is not Network Access
STEPS:
11001 Received RADIUS Access-Request |
11017 RADIUS created a new session |
Evaluating Service Selection Policy |
15004 Matched rule |
15012 Selected Access Service - Admin Access |
11033 Selected Service type is not Network Access |
Cisco-AVPairs: | |
Other Attributes: | ACSVersion=acs-5.2.0.26-B.3075 ConfigVersionId=8 Device Port=1645 RadiusPacketType=AccessRequest Protocol=Radius Service-Type=Login Device IP Address=1.150.90.190 |
Best regards,
Rafis
Solved! Go to Solution.
02-08-2011 05:43 PM
We can not use device administration policy for radius in ACS 5.
For ‘Administration of device via radIus’ you need to use Network Access service.
RADIUS >>>> Network Access service in ACS 5.1. Please switch the service selection rule to network access.
This is a bit misleading so don't be surprized:)
Rgds, Jatin
Do rate helpful posts-
02-08-2011 05:39 PM
I found solution:
We need to change:
RADIUS-IETF:Service-Type match Login
To:
RADIUS-IETF:Service-Type match Administrative
11-29-2013 06:50 AM
Yeah, I also had this issue... It´s actually pretty easy to solve!
For ‘Administration of device via radIus’ you need to use Network Access service.
Go to
Access Policies > | Access Services > | Service Selection Rules |
Check your RADIUS rule. You should have Network Access as the Service Type. Note that this cannot be modified, so delete the existing rule and create a new one with the same Identity and Authorization config.
Thats it, works as a charm
02-08-2011 05:43 PM
We can not use device administration policy for radius in ACS 5.
For ‘Administration of device via radIus’ you need to use Network Access service.
RADIUS >>>> Network Access service in ACS 5.1. Please switch the service selection rule to network access.
This is a bit misleading so don't be surprized:)
Rgds, Jatin
Do rate helpful posts-
02-28-2011 03:59 PM
Yes it confusing...
So I did additional policy for network access for RADIUS with custom attributes and now it is working
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide