Hello, I am using ASA8.0 software. I also tried to use 'downloadable ACL' attribute, this attribute does the job as its name says. But cisco-av-pair cannot. Is there another possible reason? Thanks.
... View more
Hi Sir, I have some doubts about the attribute in ACS: cisco-av-pair. I setup some ACLs in this attribute and hope this attribute can be sent from ACS to my PIX/ASA for future filtering usage if an user passes the first authentication attempt. I found that this attribute can not be installed in the PIX (when I checked the PIX using 'show access-list') even though the user passes the authentication. What is the reason?
... View more
I am not clear about the relationship between RA-interval and RA-lifetime. Is it true that RA will be sent every RA-interval to Client within RA-lifetime? So, when the RA-lifetime is expired, the RA-interval will not be functional any more. If this is ture, the problem is nothing to do with RA-interval. Instead, it is all about RA-lifetime. Am I right? By the way, I use cisco router to simulate the client. The configuration is done following the document http://docwiki.cisco.com/wiki/IPv6_ISATAP_configuration_example_with_a_Cisco_router_as_a_client Thank you for your quick response.
... View more
Hi Laurent, The thing is client has received the RA as a default route. The RA interval time and lifetime are set according to the rule (interval time Thank you
... View more
Thanks. The lifetime in this case is just notify the client that this route can be considered as a default route. The reason to ask the question is because it is related to the following issue. To setup a ISATAP tunnel, ISATAP server should send RA (a prefix) with a non-zero lifetime to the client, so that the client will treat this route as default route. Once the tunnel is built up, the default route pointing to server is available. But after the lifetime, the route disappears and never come back. How to figure this out?
... View more
The question is that why the "lifetime" for the "ipv6 nd ra" is set maximum 1800sec? It equals to just 30mins. If this timer is expired, how to renew the RA to the client? If the renewal is not possible, the client will loss the default route information forever. What is the solution for client not loss the default route (except the manual configuration)? Thank you
... View more