cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
650
Views
0
Helpful
1
Replies

How to handle Cisco AVPair Attributes

hbroich
Level 1
Level 1

Hello,

i have a little Problem, so I hope you can help me.

I have an external Radius Server and an ASA5520 which submits the IP-address and the address of the DNA-Server to the registering client (with cisco-avpair = ip:addr=x.y.z.w)

How can I submit the corresponding network mask also (ip:netmask= ?)?

Best Regards

Hartmut B.

1 Reply 1

darpotter
Level 5
Level 5

Hi

This depend on which Radius server you're using. If its ACS then.... ACS will send the cisco-av-pair automagically if

1) the aaa client is defined as Cisco IOS

2) you use the ip assignment setting at group/user level

Unfortunately it wont send a netmask as well. So in the group page just scroll down until you see the "RADIUS Cisco IOS" section then locate the cisco-av-pair and just enter

"ip:netmask=foobar"

right in the text entry box.

Then submit + restart and it should all work.

Darran