09-27-2018 11:48 AM
Hi All,
I am having difficulty getting radius authentication to work with our Ciena 6500 optical chassis. Trying to do Radius with PAP. I have policy sets defined with TACACs and Radius. Tacacs works fine. I have a single policy that is suppossed to match network access protocol radius and from their authorize based on user and group, however I can't seem to get any hits on the policy. The radius live logs indicate it is hitting default which doesn't permit PAP. However the hit counters don't increment for the default catch all rule either at the bottom so I am not sure what I am hitting. If I can get the requests to hit the policy I created I think I should be good. The only condition for the policy is Network Access Protocol Radius. Is there something else I need to do to make this work? Or is there something else I may need to consider given they are not Cisco devices?
We currently have the Ciena devices successfully doing Radius Auth via Windows Network Policy Server without issue.
Solved! Go to Solution.
10-01-2018 07:03 AM
Hi,
You have configured Radius related policies under device admin policy sets,try to create the same policy under Policy->Policy sets & use Default network access in Allowed protocol.
09-27-2018 11:53 AM
09-27-2018 12:02 PM
09-27-2018 12:06 PM
09-30-2018 03:35 AM
You need to have an authentication rule covering PAP in the Allowed Protocols list.
09-30-2018 10:23 AM
Please attach the policy screenshot and the detailed radius log.
10-01-2018 05:55 AM
Attached policy screenshot. Note that the last two rules have shown 0 and 5 hits for weeks, so neither rule is getting hit. Also, the default device admin allowed protocols profile has pap radius allowed. Also below is the detailed auth report.
|
10-01-2018 06:00 AM
10-01-2018 07:03 AM
Hi,
You have configured Radius related policies under device admin policy sets,try to create the same policy under Policy->Policy sets & use Default network access in Allowed protocol.
10-01-2018 08:57 AM
Yes! Thanks that was my problem. Didn't realize they were separate. I am now hitting the policy. Now I need to tshoot authorization as I am not getting full admin rights in the Ciena GUI.
09-30-2018 12:27 PM
IF the default authentication policy does not include PAP, then you will either need to add it to the default or create a new authentication rule that does.
Note that authentication & authorization policy hits are not updated real-time. ISE updates the hit counters every 10 minutes or so. Use Livelog error messages to understand what rules are being hit and why.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide