05-02-2017 10:26 AM - edited 03-11-2019 12:41 AM
I have several 3560's running 12.2 and a nexus 3064 running 6.0.
I have freeradius v2 runing on centos 6.
My problem is getting enable authentication to work for the 3560 switches. I can get enable to work only if I enter the enable password defined on the switch, but the radius itself will not grant it.
I have a freeradius user defined with auth-type=local, service-type=administrative-user and cisco-avpair=shell:priv-lvl=15
The nexus switch authenticates to freeradius and is granted entry with level 15. The 3560 is granted entry without level 15 (subsequent ena command required).
I tried a lot of variations to get this working to no avail. For instance I've added a $enab15$ user to freeradius.
I'm not sure if there is something else I could try or if this simply will not work in a mixed cisco environment.
Any help, etc appreciated.
Thanks
05-02-2017 10:12 PM
Have you got something like this:
aaa authorization exec default group radius
aaa authorization network default group radius
05-03-2017 12:26 PM
no, but I'll try it...thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide