02-06-2012 05:05 PM - edited 03-10-2019 06:48 PM
Hello,
I was wondering if i should use the same RADIUS VSA attribute on ACS v5.1 to authenticate AAA clients as those i was using on my old ACS v3.3 server.
Exemple : under ACS v3.3 i was using RADIUS (Cisco Aironet) attribute to authenticate AP & WLC, should i do the same under ACS v5.1 ?
Best regards.
Solved! Go to Solution.
02-08-2012 10:52 AM
Hello,
When defining AAA client on the new ACS 5.x server you just select TACACS+ or RADIUS. We no longer define the RADIUS "vendor"/"VSA" when creating the AAA Client entry. All AAA client would be defined as RADIUS or TACACS+ only.
If you were using specific VSA Attributes then you need to send those attributes back configuring Authorization Profiles on the ACS 5.x. You will find the specific VSA attributes there. Refer to the following screenshots:
And here are the available attributes for the ACS for RADIUS Aironet:
NOTE: click images to enlarge.
If this was helpful please rate.
Regards
02-08-2012 10:52 AM
Hello,
When defining AAA client on the new ACS 5.x server you just select TACACS+ or RADIUS. We no longer define the RADIUS "vendor"/"VSA" when creating the AAA Client entry. All AAA client would be defined as RADIUS or TACACS+ only.
If you were using specific VSA Attributes then you need to send those attributes back configuring Authorization Profiles on the ACS 5.x. You will find the specific VSA attributes there. Refer to the following screenshots:
And here are the available attributes for the ACS for RADIUS Aironet:
NOTE: click images to enlarge.
If this was helpful please rate.
Regards
02-08-2012 01:58 PM
Hello Sir,
Thank you very much for your answer, i've tested RADIUS authentication without choosing an attribute and that worked fine.
Best regards.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide