cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1501
Views
0
Helpful
7
Replies

ISE 1.3 - How to add login-service = ssh into ietf radius attributes

Thibault BRISSE
Level 1
Level 1

Hello,

 

I have to configure AAA on HP 6125 (c7000 enclosure) with ISE for SSH and TELNET access.

It works for TELNET but not for SSH.

 

Attributes sent in access-accept for TELNET are the following:

  • Huawei-Exec-Privilege = 3
  • login-Service = 0

0 is for TELNET. 

 

The problem is that SSH value is not available by default and you have to add it into the IETF dictionnary. I made it with Microsoft NPS and it works perfectly.

Unfortunatly it seems not possible with Cisco ISE. Please could you help me ?

 

Regards,

 

Thibault

7 Replies 7

jan.nielsen
Level 7
Level 7

Just to be sure, are you saying that for SSH when you use NPS, you just set login-service to something else, and then SSH works ?

Yes you are right.

I edited c:\windows\system32\ias\dnary.xml and add the following value to login-service attribute:

<StandardValue>
    <Name>ssh</Name>
    <Value>50</Value>
   </StandardValue>

Unfortunaly it is not possible to add this value in ISE.

Regards,

 

Thibault

 

 

As far as i can tell, we can't change the built-in dictionaries, so im not sure to do this. Also the value "50", is not a standard value for the Login-Service" IETF radius attribute according to IANA

https://www.iana.org/assignments/radius-types/radius-types.xml#radius-types-8

fdelrio
Level 1
Level 1

Hello, 

Have you find any solution to your problem since 2 month ?

Because even if 50 is not standard, it's what the equipment need :-(

 

Regards,

 

Franck

Hello,

 

We use ISE for cisco devices and Microsoft NPS for HP devices.

ISE is configured as a radius proxy to simplify radius settings on HP and Cisco devices.

 

Regards

Thanks

That's a bad news.

Roger Base
Level 1
Level 1

I know this is old discussion. But how do you enable radius login-service 15 attribute in Cisco IOS to send to ISE?