I'm try to use auth-proxy on PIX515 (6.2.2) with IC-RADIUS (Livingston-compatible, Cisco dictionary downloaded) authentacation and I want assign per-user access-lists.
For example, I configure ACL#10 on PIX (access-list 10 permit ip any any), and in RADIUS configuration write: Filter-Id "acl=10" (PIX does not understand Cisco-AVPair attribute if use RADIUS (CSCdt50422)).
RADIUS logs and PIX debug has not any errors. In result PIX denyed any type traffics from a client PC (include icmp :) ).
If I remove any lines about access-lists from RADIUS configuration, any AAA work normal.