cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
582
Views
0
Helpful
9
Replies

AAA radius server with Cisco SWs, dynamic shell priviliages.

asdrewaqf
Level 1
Level 1

Hello Team,

       I need your assistance, I've trying to configure radius authentication with Cisco switch to be authenticated from the NPS server, as shown below I've created 2 network policies on the NPS radius server first policy for TLs with shell-priv=15 and the other one for half admin read-only with shell-priv=7

 

whenever anyone tries to access the switch it grants him access with shell-priv=15 even when it hits on the half-admin policy with shell-priv=7

 

can anyone assist me? do I have to configure something else or do I miss anything?

asdrewaqf_0-1709060499692.png

asdrewaqf_1-1709060551704.pngasdrewaqf_2-1709060703793.png

 

9 Replies 9

Can I see vty line config 

Also can I see 

Debug aaa authorization 

MHM

asdrewaqf
Level 1
Level 1

vty config 

asdrewaqf_0-1709061764588.pngasdrewaqf_1-1709062809773.png

 

It seem to me that radius push both priv, 

Add new user but without push service type and Access permission and try access using this new user 

MHM

sorry man, i think u confused as the provided SS, have 2 different IPs with 2 different users so i think u doubted that the radius has pushed 2 shell values 

So debug for two different IP not one IP? If yes then

Show privilege, İ think it is privilege 7 but it and privilege above one will appear with #

Do show privilege for both user and check exact privilege 

MHM

asdrewaqf
Level 1
Level 1

it shows 15, however the radius is sending shell-priv=7

Yes friend this issue I analyze it' what is in my mind is that

Service type 6 administrative and privilege 7 not work with each other admin is override the privilege 7' to check add new use with privilege 7 and service type User and check

MHM

Thank you, I'm still checking this issue, and haven't found a solution yet, but I just have a question is what I'm talking about applicable?

I mean have you ever seen this solution?

You can not add new users with service type user?

MHM

Review Cisco Networking for a $25 gift card