cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
711
Views
0
Helpful
2
Replies

ACS3.2 with SSG-SESM

parawee.r
Level 1
Level 1

Hi guy,

I'm working on the SSG 12.3(4)t4 sesm 3.1 and ACS 3.2

after pass the authentication and already login the attribute is sent to the SESM but the debug massage is;

00:02:44: RADIUS: Received from id 21645/3 192.168.0.102:1812, Access-Accept, len 114

00:02:44: RADIUS: authenticator 5D 48 5E EA EC 3C 6E 28 - B6 17 83 A1 4A 28 05 32

00:02:44: RADIUS: Vendor, Cisco [26] 22

00:02:44: RADIUS: ssg-service-info [251] 16 "IInternet Gold"

00:02:44: RADIUS: Vendor, Cisco [26] 24

00:02:44: RADIUS: ssg-service-info [251] 18 "R0.0.0.0;0.0.0.0"

00:02:44: RADIUS: Service-Type [6] 6 Outbound [5]

00:02:44: RADIUS: Class [25] 42

00:02:44: RADIUS: 43 49 53 43 4F 41 43 53 3A 30 30 30 30 30 35 38 [CISCOACS:0000058]

00:02:44: RADIUS: 36 2F 63 30 61 38 30 30 30 64 2F 49 6E 74 65 72 [6/c0a8000d/Inter]

00:02:44: RADIUS: 6E 65 74 2D 47 6F 6C 64 [net-Gold]

00:02:44: RADIUS(00000000): Received from id 21645/3

00:02:44: RADIUS(00000000): Unique id not in use

00:02:44: RADIUS/DECODE(00000000): There is no RADIUS DB Some Radius attributes may not be stored

00:02:44: SSG-CTL-EVN: Creating radius packet

00:02:44: SSG-CTL-EVN: Response is good

the screen on the client doesn't show the profile or any login&logout.

Any recommencation to look for.

2 Replies 2

umedryk
Level 5
Level 5

Just one thing here. If you add the command "radius-server attribute nas-port extended" it should include the nas port type in the access request.

nuno.santos
Level 1
Level 1

Hi,

i'm implementing the same scenario with sesm/acs/ssg but i can't get a successfull authentication. After analyze traffic, sesm sends radius access request to ssg (with destination user ip address) and after that, ssg should send the validate request to ACS but it doesn't happen!!! Do you have any clue to help solve/clarify this?

Resuming, the redirection is being done with success except the authentication step.

Best Regards

Nuno