Group-lock does not work

Hello

I enabled the functionality of group-lock on a group of C2L VPN but the ASA does not add the tunnel-group-name value in the RADIUS packet sent to the server for authorization.

In the past, I used the function of locking-group several times without problem. This is the first time, it does not work and I wonder if it can depends on the old version of asa that I use (8.6.1(2)).

Here the conf and the asa debug all the RADIUS:

Configuration:

attributes of Group Policy Network_Users
value x.x.x.x DNS server
Ikev1 VPN-tunnel-Protocol
value of group-lock Network_Users
VLAN 24

Debug RADIUS all the:

RADIUS packet decode (authentication request)

--------------------------------------
Data of raw packets (length = 156)...
01 cb 00 9 c 97 84 6 d 33 f0 69 ee 8f 1 c 25 a2 fa |  ......m.3.i...%.
AB 08 a1 c6 0 01 a 78 30 31 35 35 36 32 33 02 12 |  ... xxxxxxxx...
14 80 52 4 a 72 0e e5 a1 69 d6 ee d3 d3 b9 67 0a |  .. RJr... i...g
05 06 8 b 20 00 06 06 00 00 00 02 07 06 00 00 c0 |  ... ............
00 01 0e 1e 2e 2e 35 39 37 31 35 39 2nd 32 32 30.  ... x.x.x.x
0f 1F 39 2e 2e 34 33 37 32 34 38 2 32 30 32 3d |  .. 94.37.248.202 =.
06 00 00 00 05 42 39 2e 0f 34 33 37 2nd 32 34 38 |  ..... B.94.37.248
2nd 32 30 32 04 06 16 05 21 1 a 22 00 00 00 09 ac |  . 202...! » ....
1 01 c 69 70 3A 6f 73 75 72 63 65 69 70 39 3d 2d |  .. IP:Source - ip = 9
2E 2e 34 33 37 32 34 38 2 32 30 32 |  4.37.248.202

Packet analyzed data...
RADIUS: Code = 1 (0x01)
RADIUS: Identifier = 203 (0xCB)
RADIUS: Length = 156 (0x009C)
RADIUS: Vector: 97846DA233F069EE8F1C25FAAB08A1C6
RADIUS: Type = 1 (0x01) - user name
RADIUS: Length = 10 (0x0A)
RADIUS: Value (String) =
78 30 31 35 35 36 32 33 |  xxxxxxxx
RADIUS: Type = 2 (0x02) username-password
RADIUS: Length = 18 (0x12)
RADIUS: Value (String) =
14 80 52 4 a 72 0e e5 a1 69 d6 ee d3 d3 b9 67 0a |  .. RJr... I have... g
RADIUS: Type = 5 (0x05) NAS-Port
RADIUS: Length = 6 (0x06)
RADIUS: Value (Hex) = 0x8B20C000
RADIUS: Type = 6 Type of Service (0x06)
RADIUS: Length = 6 (0x06)
RADIUS: Value (Hex) = 0x2
RADIUS: Type = 7 (0x07) Framed-Protocol
RADIUS: Length = 6 (0x06)
RADIUS: Value (Hex) = 0x1
RADIUS: Type = 30 (0x1E) Called-Station-Id
RADIUS: Length = 14 (0x0E)
RADIUS: Value (String) =
2nd 2nd 35 39 37 31 35 39 2nd 32 32 30.  x.x.x.x
RADIUS: Type = 31 (0x1F) Calling-Station-Id
RADIUS: Length = 15 (0x0F)
RADIUS: Value (String) =
39 2e 2e 34 33 37 32 34 38 2 32 30 32 |  94.37.248.202
RADIUS: Type = 61 (0x3D) NAS-Port-Type
RADIUS: Length = 6 (0x06)
RADIUS: Value (Hex) = 0x5
RADIUS: Type = 66 Tunnel-Client-Endpoint (0x42)
RADIUS: Length = 15 (0x0F)
RADIUS: Value (String) =
39 2e 2e 34 33 37 32 34 38 2 32 30 32 |  94.37.248.202
RADIUS: Type = 4 NAS-IP-Address (0x04)
RADIUS: Length = 6 (0x06)
RADIUS: Value (IP address) = 172.22.5.33 (0xAC160521)
RADIUS: Type = 26 (0x1A) vendor-specific
RADIUS: Length = 34 (0 x 22)
RADIUS: Vendor ID = 9 (0 x 00000009)
RADIUS: Type = 1 (0x01) Cisco-AV-pair
RADIUS: Length = 28 (0x1C)
RADIUS: Value (String) =
69 70 3A 6f 73 75 72 63 65 69 70 39 34 2nd 3d 2d is |  IP:Source - ip = 94.
2e 33 37 32 34 38 2 32 30 32 |  37.248.202
Send 172.22.39.1/1812 pkt
RADIUS_SENT:Server response time
Ray mkreq: 0x1a6
alloc_rip 0x00007ffec924aa48
new application 0x1a6--> 204 (0x00007ffec924aa48)
obtained the user 'xxxxxxxx '.
has obtained the password
add_req 0x00007ffec924aa48 session 0x1a6 204 id
RADIUS_DELETE
remove_req 0x00007ffec9249ec0 0x1a5 203 session id
free_rip 0x00007ffec9249ec0
RADIUS_REQUEST
RADIUS.c: rad_mkpkt
rad_mkpkt: ip:source - ip = 94.37.248.202

RADIUS packet decode (authentication request)

As mentioned previously, the package does not contain the ID 146 Tunnel-Group-Name typically added when the group-lock has been activated. I'm talking about this:

RADIUS: Type = 26 (0x1A) vendor-specific
RADIUS: Length = 32 (0x20)
RADIUS: Vendor ID = 3076 (0x00000C04)

RADIUS: Type = 146 (0 x 92) - Tunnel-group name
RADIUS: Length = 26 (0x1A)
RADIUS: Value (String) =
54 45 5f 4 c 56 50 4th 5f 49 6e 74 72 61 6 65 74 |  Network_Users
RADIUS: Type = 26 (0x1A) vendor-specific
RADIUS: Length = 12 (0x0C)
RADIUS: Vendor ID = 3076 (0x00000C04)
RADIUS: Type = 150 (0 x 96) Client-Type
RADIUS: Length = 6 (0x06)
RADIUS: Value (integer) = 1 (0x0001)

Thank you

Maurizio

I wonder if your problem is related to this bug:

CSCsw31922

Maybe upgrade to 8.6.1(5) or later will solve the problem.

--

Please do not forget to select a correct answer and rate useful posts

Tags: Cisco Security

Similar Questions

  • HP Pavilion Notebook 15-n225se: Cap lock does not work

    Hello everyone

    The cover lock does not work, or no led light upward.  She went to work, to work from time to time and now not al all.

    Because passwords often have caps there is problem enough.

    I got tired of doing a hard reboot, but the f10 key not give me access to the bios menu.

    I don't have an external key board to attach so cannot determine if it is a hardware or software problem.

    I'm now using the virtual keyboard that lights up successfully the cover lock.

    So I use the virtual key boad for the lids and the normal key Board for everything else.

    Only a short-term solution, however.

    If it is problem of contact with the cap lock key or is it a software problem?

    Because this is a business Computer to have out of action is a major problem... all I can do to solve this problem.

    Any suggestions please.

    Thank you very much

    Hi @Vegimite,

    Here is the link of how to open the keyboard on the screen to type: https://support.microsoft.com/en-us/help/10762/windows-use-on-screen-keyboard

    You may need it if the physical keyboard brings your boredom.

    You can also contact the HP support or a local repair shop to arrange a physical control for the LED issue caps lock.

    For HP, the following support link http://www.hp.com/contacthp allows to create a folder for your problem and contact HP. If you do not live in the United States / Canada, please click on the link http://www8.hp.com/us/en/contact-hp/ww-phone-assist.html to get contact information for your region.

  • applock and smart app lock does not work on 5.1.1

    Hello. I just upgraded to 5.1.1

    But applock and smart app lock does not work more that is very important to me.

    Who else has experienced the same problem? If you know a solution, let me know pleasr. Thank you

    @avacs

    It's a new update, application developers must check and fix this compatibility problems, not Sony. If the application has been developed by Sony, Sony should fix the problem.

  • Peer Networking Grouping Service does not work; How can I make it work?

    I use Windows 7 and trying to set up a home network I am unable. After you run the troubleshooter, the only problem is that the Peer Networking Grouping Service does not work. Messages to indicate there is no other problems other than Peer name resolution Protocol (PNRPsvc) Service or the Peer Neetworking Identity Manager (p2pimsvc) Service is not running.

    How can I solve this problem?

    Hello

    First delete the file idstore.sst from the following location: C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\PeerNetworking\idstore.sst and once you remove, restart the service Peer Networking grouping.

    Follow the steps to restart the service:

    a. click Start, type Services.msc in the search box and press enter.

    (b) in the Services window, search for Peer Networking Grouping.

    c. make a right click the service: peer networking grouping and click restart.

    Also, see the following Microsoft articles:

    Establishment of a network domestic:
    http://Windows.Microsoft.com/en-us/Windows7/setting-up-a-home-network

    Why can't I create a homegroup? :
    http://Windows.Microsoft.com/en-us/Windows7/why-cant-I-create-a-HomeGroup

    Hope the information is useful.

  • My touchpad lock does not work, even if the orange light is on, indicating locked buffer. Probook4420s.

    My touchpad lock does not work, even if the orange light is on, indicating locked buffer. Probook4420s.  Windows 7 32 bit.

    Hello

    If the amber light is on the TouchPad itself, try double tapping

    If that is not activate, try uninstalling the device driver course Synaptics pointing, then restart the computer and download and install the driver from the link below.

    http://h20000.www2.hp.com/bizsupport/TechSupport/SoftwareDescription.jsp?lang=en&cc=us&prodTypeId=321957&prodSeriesId=4145435&prodNameId=4145436&swEnvOID=4052&swLang=13&mode=2&taskId=135&swItem=ob-86824-1

    Kind regards

    DP - K

  • How can I fix it? message is peer networking group service does not work

    When I connect, I can get online.   When my wife logs on the same computer, it is and error and cannot get online.  I get a message in addition to ppeer service networking group does not work that States cannot access service Group Policy client and see the system event log.  Is there a way to fix this?

    Hi thadkresho,

    Thanks for posting your query in Microsoft Communities. The problem description, I understand that your wife is not able to connect on the same computer. Provide the following information for a better understanding of the issue:

    ·         Did you do changes on the computer before the show?

    ·         You use a third-party security software?

    ·         What version of the operating system is installed on the computer?

    ·         If it works much earlier?

    Follow these methods.

    Method 1: Follow these steps:

    Step 1: Start the computer in safe mode with network and check if the problem persists.

    Startup options (including safe mode)

    Step 2: If the problem does not persist in safe mode with networking, perform a clean boot to see if there is a software conflict as the clean boot helps eliminate software conflicts.

    Note: After completing the steps in the clean boot troubleshooting, follow step 3 from the link to start the computer to a Normal startupmode.

    Method 2: Temporarily disable the security software .

    Note: Antivirus software can help protect your computer against viruses and other security threats. In most cases, you should not disable your antivirus software. If you do not disable temporarily to install other software, you must reactivate as soon as you are finished. If you are connected to the Internet or a network during the time that your antivirus software is disabled, your computer is vulnerable to attacks.

    Method 3: Follow the steps in the article.

    Windows wireless and wired network connection problems

    Let us know if you need more assistance.

    Thank you.

  • Domain group policy does not work on a station

    Hello

    Been the last week reading everything that is available on the internet.

    Win 2008 R2 Standard

    Group Policy created and linked to an OU - ministere1

    in the AD, the container has users in it that the policy should apply to.

    everything works fine on PC1 for User1

    everything works fine on PC1 for User2

    does not work on PC2 or for User1 or 2

    RPC is enabled

    Domain controller - use the default

    gpupdate/force - shows update is successful

    Gpresult /R shows the groups appropriate for user 1 and 2 but can be applied strategy local politics

    is there something I need to turn it on to use the distributed domain GPO?

    BTW.

    politics is Frank - maps a network as a reader folder (checked the privileges and as said before - this works fine on PC1 but not on PC2)

    Both PC's are Win 7 64 bit Pro

    When you try to test the strategy side server it shows RPC server not available

    RSoP will also show access denied on PC2

    If you have any solution for this problem - please help

    In this case, Peter

    Hello

    Post your question in the TechNet Server Forums, as your question kindly is beyond the scope of these Forums.

    http://social.technet.Microsoft.com/forums/WindowsServer/en-us/home?category=WindowsServer

    See you soon.

  • indicator of Caps lock does not work

    My caps lock indicator windows stopped working a while ago and then I turned on toggle keys .but it has also stopped working. I am using windows 7 ultimate.the characteristic toggle key is on but it still does not work, I tried to put it and the but its still not working.i also tired ms fix the app but it did not find the problem. I would have preferred using ToggleKeys indicator, but both will do the job.

    Microsoft does not have any indicator, only the ToggleKeys.  Windows itself has never had such a feature.  You must use another program on your old computer, perhaps a program you downloaded from the Internet or a program that your computer manufacturer preinstalled for you.  Sony installs keyboard for example indicators and I think Dell has on some of their computers.  But he has never been a built-in feature.

    You can try a small program like this:

    http://www.AddictiveTips.com/Windows-tips/capnotifier-get-system-tray-notifications-for-caps-lock-on-off/

    Gives you a little Popup like this:

  • Number lock does not work under windows 8.1

    I have an Acer laptop Aspire E1-522 using windows 8.1.  When that I start, the keypad works because I can log on the computer by using the keypad.  Once I am 'welcomed' trying to enter data on the Microsoft Office program (Word, Access, Excel, Notepad etc.) the keypad does not work.

    Every search I did leads me to some company trying to sell me programs to solve the problem.

    Word and Excel displays Num Lock indicators in the lower status bar?

    You must right click on the color bar to activate it (right click on where the red dot is, and then turn on Num Lock).

    After that, Excel will tell you if the NUMLOCK is considered by the program, with a power indicator near the left:

  • Light of CAPS LOCK does not work

    Hello dear guys,

    Had a problem today - some keys on the keyboard do not work properly.

    I opened the hood of the laptop (Pavilion G6 2241sa) and saw that the keyboard cable was loose. I reconnected properly, closed the lid and turned on the laptop. Now, all the keys work well, BUT the CAps Lock light doesn't work well. Key works, but when I press on it - will light, but as soon as I release the button - the light turns off. Light is not. Also, when the real function of the caps lock is on, when I press another button, the light on the surface of the NumLock key but it is dim.

    I recheched cable keyboard again - everything is fine, but seeing locking caps does not stay when you press.

    I don't practice typing for the last 3 months for a few hours a day, so I guess that it also affects the life expectancy of my keyboard.

    Would appreciate any insights on this light lock thanks a lot, lives

    Thank you for your response. But the General solutions do not work here, I'm afraid.

    My inner voice tells me that it is the problem of specif inside wiring that cannot be fixed, perhaps only by the replacement of the entire keyboard or keyboard cable.

    I appreciated your help in any case. My keyboard works, light Verr Maj is not so important, that's why I will end this matter as resolved. Cheers, lives

  • In FF5.0 this tab groups feature does not work: ' once you have created your first group, the of the tab group button will be added to the right end of the Strip to tabs to give you a one-click way to return to your groups.»

    The phrase in quotes in my question is instructions under "what are the groups of tabs? (Redirected from "what is Panorama?")

    If this button does not appear then you can drag it out of range of the tool bar on the tab toolbar customization window yourself.

    Open the Customize via "view > toolbars > customize" or "Firefox > Options > toolbars."

  • Method BitmapData lock does not work.

    import flash.display.BitmapData;

    Import 12345678910111213import;

    import flash.geom.Rectangle;

    var bmd:BitmapData = new BitmapData (100, 100, false, 0xFF0000);

    var bitmap: Bitmap = new Bitmap (bmd);

    addChild (bitmap);

    BMD. Lock();

    for (var i: uint = 0; i < 50; i ++)

    {

    for (var j: uint = 0; j < 50; j ++)

    {

    bmd.setPixel (i + 25, j + 25, Math.Random () * 0xFFFFFF);

    }

    }

    I don't don't see random colors in the red centre of rect, but I see it. What I've done wrong?

    Mr.Shumi wrote:

    I have not worked with before bitmap

    but you tell him to show here the random colors

    Math.Random () * 0xFFFFFF

    Yes

    bmd.setPixel (i + 25, j + 25, Math.Random () * 0xFFFFFF);

    random sets pixels in its bitmapdata

    However the previous call to

    BMD. Lock()

    We hear content on the bitmapdata should change, but the bitmap object should not be updated until that bmd.unlock () is called (which, in this example, it is not)

    Lucky: I'm looking into it, and I don't see why it wouldn't I'll try and get back to you unnecessarily, it should work

  • Search iPhone settings for "Auto-Lock" does not work

    Hello

    Does anyone know why the Auto-Lock setting is not to be found when you use the search at the top of the main settings page.

    From time to time, when I'm on a conference call, I like to set the auto-lock on 'Never', so I can leave the visible main phone screen to mute/one-mute the call without having to unlock the phone. I have the memory of a goldfish, so I do not remember that it is in the section "Viewing and brightness" and that is why I use the search at the top of the main settings page field. I would normally enter 'Auto', and it would be "Auto-Lock" for me.

    Since the release of iOS10, the la recherche search can't find this definition more although it still is in the section "viewing and brightness.

    The search for other settings seems to work, but it seems that it is just this one, but I have not actually tried too.

    Any ideas on what is happening and how I could get to find the Auto-Lock in the future?

    Thank you

    B1GPappaSmurf wrote:

    Any ideas on what is happening and how I could get to find the Auto-Lock in the future?

    Seems to be a bug, so nothing you can do but remember where the parameter is and report the bug:

    http://www.Apple.com/feedback/iPhone.html

  • my shift lock does not work. Why?

    Hey, I have a logitech keyboard (which comes with a mouse but I don't use it and it has been great so far)
    the model is: s520.

    I turned on the computer this morning and noticed these problems:

    1 each time I pressed 1 it would be type 1].
    2. whenever I tried to activate the caps lock by pressing on it, it won't work. letters would still be captured down in tiny letters.

    at the moment the first problem has been resolved without special efforts on my behalf, it was solved by iteself.

    and the problem of locking caps always guard bothers me.

    I have windows 7 Home premium 32-bit
    installed in English
    my browser is google chrome, updated.

    Thank you!

    Hello

    ·         Have you tried to check and different keyboard if you are faced with the similar question?

    Try following the methods provided below and see if it helps:

    Method 1:

    I suggest that you type, then check in Notepad, if it works also to try the keyboard on the screen and check if you are facing a similar question.

    Type without using the keyboard (on-screen keyboard)

    http://Windows.Microsoft.com/en-us/Windows7/type-without-using-the-keyboard-on-screen-keyboard

    Method 2:

    You can try to check and the boot if the problem persists. To see how to perform the clean boot click on the link below and follow the steps in the Kb article.

    http://support.Microsoft.com/kb/929135

    Note: After using the boot is a way to solve your problem step 7 follow-up to reset the computer to start as usual.

    Method 3:

    Try to uninstall the drivers and reinstall them with the latest drivers from the link provided below and check if it works. Refer also to the procedure described in the link:

    http://www.Logitech.com/en-roeu/433/145?WT.z_sp=image

    If the problem persists I also suggest you to contact the manufacturer of the keyboard and check for assistance.

    I hope this helps.

  • Characteristic group Pickup does not work when phones adds a group in BE3k

    Hi all

    I have a blast with pilot number 300 group, there are two members Ext. 600 and ext.601 in this group of breath.   I added these two extensions of the Group call pickup and select "Audio and Visual Alert.  I also have a spare Ext. 602 phone.

    When I composed between extensions ext.600, 601 and 602, group pick up characteristic woking and I can see 'call pickup available' on the phone screen and hear the audio alert. But when I dial the hunt group pilot number 300 of spare phone ext.602, ext.600 and Ext. 601 sound but I can't call indicators collection on display. I also tried "Opickup" on the phone but I got "no available for pick up call" no message on the screen. ""

    Any ideas why and how to solve this problem?

    Hi Billy

    This is not supported. This support is added for the next version.

    Thank you

Maybe you are looking for

  • Could not detect my IX2 of PC

    My IX2 is connected to my router. I can detect and connect to all computers, laptops and mobile devices on the network accept to a certain PC. The problematic PC is the only one connected directly (by cable) to the router, all the rest are via Wi - F

  • Wavy jagged singal of 9237 at no load condition

    Dear forum users and employees of OR,. I would be grateful to you if you can solve my problem. My specimen is a simple piece of plastic 1 0.25 inch rectangular cross section with a length of 8 inches. I'm trying to measure the deformation (with the h

  • Need help to restore backup files

    I had to change to XP Pro to XP home.  Pro, I backed up all my files on external hard drive, but now I can not install the BKF homepage file... Help

  • Fax basic Trouble Shooting steps

    Here are a few things to keep in mind before troubleshooting. If you have DSL, or help you to telephone service by a cable company or VOIP(Voice Over Internet Protocol), such as Vonage, you have digital lines.  Digital lines are not bad, but they are

  • HP Pavilion Media Center m8160 Win7 upgrade?

    Will be my HP Pavilion Media Center m8160, running 32-bit win7, run a 64-bit version of Win8? My flag has an E4400 clocked at 2 Mhz.? I've already upgraded the card wirelessly with a compatible W8.