RADIUS authorization does not not for Nortel by ACS 5.3 switches

Hello

RADIUS authorization does not work on the Nortel switches, I configured the access policies relevant for the attributes RADIUS (attached screenshot)

Order get not executed due to the failure of authorization:

config cli password rwa

I do not see RADIUS authorization reports option, just to check if someone has understood how to set up these reports?

I made a capture of packages for packages of AAA of the nortel switch and found that the accounting request contains the cli command sent for authorization. (pcap file attached)

Kind regards

Akhtar

Akhtar,

This isn't how the authorization of RADIUS. Accept access and the av-pairs that are sent in the response is the permission for the session of the user. This isn't like Ganymede where each command is permitted with an authentication request separate with the command that the client is running.

When it comes to radius account management isn't too late in the process.

Thank you

Tarik admani

Tags: Cisco Security

Similar Questions

  • My Ipad air2 does not start.  Tried hold it together switch with on/off switch.  Apple logo appears for about 15 seconds and then turns off again.

    My Ipad air2 does not start.  Tried hold it together switch with on/off switch.  Apple logo appears for about 15 seconds and then turns off again.

    Is there another way to start the IPAD?

    Try the steps here:

    https://support.Apple.com/en-us/HT201412

  • Authorization does not not for books

    Last download KOBO using Reader for PC version 2.3.00.03130 says 'Unauthorized computer' previous books are very good. Tried meet and then authorizing again, but does not open same book. Suggestions?

    I have exactly the same problem. Any solution?

  • RADIUS authentication does not

    We currently have a switch - ms duncan, who has been put in place for GANYMEDE and works very well.  We have the same command on another switch - sw-SPARE parts and it does not work:

    !
    enable secret 5 $1$ lyQB$ OUFCNrTeluAVeH9R1Grjm0
    !
    username privilege 15 secret 5 netadmin $1$ urJC LbxLOoBdoG1064QFcjTRe1 $
    username admin privilege 15 secret 5 LGPp $1$$ QbOZQ8Ch2kpEj.tLKsp1m.
    !
    !
    AAA new-model
    !
    !
    AAA authentication login default group Ganymede + local
    authorization AAA console
    AAA authorization config-commands
    AAA authorization exec default group Ganymede + local
    AAA authorization commands 15 default group Ganymede + local
    orders accounting AAA 15 by default start-stop Ganymede group.
    !
    !
    !
    AAA - the id of the joint session
    !
    !
    single-connection host key 10.223.8.29 radius-server CiscoCisco
    RADIUS-server application made

    !

    Here's the Ganymede of ms-duncan debugging:

    MS duncan #.
    11w5d: MORE: authentication request treatment 344 AAA queues
    11w5d: MORE: treatment demand beginning 344 authentication id
    11w5d: MORE: authentication start package created for 344 (reed.vendor)
    11w5d: MORE: using the 10.223.8.29 Server
    11w5d: HIGHER (00000158) / 0/IDLE / 4383A 40: obtained immediately connect on the new 0
    11w5d: HIGHER (00000158) / 0/WRITING / 4383A 40: started 5 sec timeout
    11w5d: HIGHER (00000158) 0 / / WRITING: has written 47 bytes any request
    11w5d: HIGHER (00000158) 0 / / READ: read all header 12-byte (wait 16 bytes)
    11w5d: HIGHER (00000158) 0 / / READ: read all the reply 28 bytes
    11w5d: HIGHER (00000158) / 0 / 4383A 40: the package of treatment response
    11w5d: MORE: received the authentic GET_PASSWORD response status (8)
    11w5d: MORE: authentication request treatment 344 AAA queues
    11w5d: MORE: treatment of authentication continue id 344 of demand
    11w5d: MORE: authentication continue package generated for 344
    11w5d: HIGHER (00000158) / 0/WRITING / 4383CA 8: started 5 sec timeout
    11w5d: HIGHER (00000158) 0 / / WRITING: wrote bytes 25 requests
    11w5d: HIGHER (00000158) 0 / / READ: read all 12 byte header (allow 6 bytes)
    11w5d: HIGHER (00000158) 0 / / READ: read all the reply 18 bytes
    11w5d: HIGHER (00000158) / 0 / 4383CA 8: the package of treatment response
    11w5d: MORE: received the status of response authentic PASS (2)
    11w5d: MORE: queues application of AAA 344 for transformation
    11w5d: HIGHER: processing of the application for authorization id 344
    11w5d: MORE: Protocol is set to None. Jump
    11w5d: MORE: sending service AV = shell
    11w5d: MORE: sending AV cmd *.
    11w5d: MORE: application created for 344 (reed.vendor)
    11w5d: MORE: previously set server group Ganymede 10.223.8.29 +.
    11w5d: HIGHER (00000158) / 0/IDLE/4384698: got immediately connect on the new 0
    11w5d: HIGHER (00000158) / 0/WRITING/4384698: started 5 sec timeout
    11w5d: HIGHER (00000158) 0 / / WRITING: wrote bytes 66 requests
    11w5d: HIGHER (00000158) 0 / / READ: read all header 12-byte (wait 18 bytes)
    11w5d: HIGHER (00000158) 0 / / READ: read all the answer 30 bytes
    11w5d: HIGHER (00000158) / 0/4384698: the package of treatment response
    11w5d: MORE: handled AV priv-lvl = 15
    11w5d: MORE: received permission to answer for 344: PASS
    MS duncan #.

    Here's the Ganymede of debugging of sw-SPARE PARTS:

    SW-SPARE #.
    17:17:49.477 Feb 2: MORE: Queuing AAA request authentication 42 for the treatment
    17:17:49.477 Feb 2: MORE: treatment demand beginning 42 authentication id
    17:17:49.477 Feb 2: MORE: authentication start package created for 42()
    17:17:49.477 Feb 2: MORE: using the 10.223.8.29 Server
    17:17:49.482 Feb 2: HIGHER (0000002 A) / 452B47C/NB_WAIT/0: started 5 sec timeout
    17:17:49.482 Feb 2: HIGHER (0000002 A) / 0/NB_WAIT: 36 bytes written requests
    17:17:49.482 Feb 2: MORE: block everything by reading the header pak
    17:17:49.487 Feb 2: HIGHER (0000002 A) / 0/452B47C: the package of treatment response
    17:17:58.437 Feb 2: MORE: Queuing AAA request authentication 42 for the treatment
    17:17:58.437 Feb 2: MORE: treatment demand beginning 42 authentication id
    17:17:58.437 Feb 2: MORE: authentication start package created for 42()
    17:17:58.437 Feb 2: MORE: using the 10.223.8.29 Server
    17:17:58.437 Feb 2: HIGHER (0000002 A) / 4165F60/NB_WAIT/0: started 5 sec timeout
    17:17:58.437 Feb 2: HIGHER (0000002 A) / 0/NB_WAIT: 36 bytes written requests
    17:17:58.437 Feb 2: MORE: block everything by reading the header pak
    17:17:58.442 Feb 2: HIGHER (0000002 A) / 0/4165F60: the package of treatment response
    SW-SPARE #.

    It seems that the problem is that there is no user name in the package of beginning of authentication for the sw-spare:

    17:17:49.477 Feb 2: MORE: authentication start package created for 42()

    What should we do to solve this problem and get GANYMEDE work on sw-SPARE parts?

    You can add another statement to the configuration:

    property intellectual Ganymede source interface vlan1

    The order is to specify an interface / IP for all GANYMEDE + outgoing packets.

    ~ Jousset

  • Facebook, Gmail and MétéoMédia works does not for me with the last update, even in safe mode

    That pretty much sums up it. Since yesterday, with the most recent update, firefox does not display correctly these sites. Someone else posted a question similar to this topic. It has been marked as resolved, but there is no solution posted. Here's his question: https://support.mozilla.org/en-US/questions/963125 I have the same problem as him with fb. In addition to the problem with fb, Gmail doesn't end loading. And MétéoMédia do not display the weather forecast. I'm sure that many other sites are affected as well.

    All sites work properly in Seamonkey, which I use once again, now. I went to oldapps download v. 22 of ff, but whatever the most recent update changed only came when I installed v.22. The problem persists. I could uninstall it completely and then new installation v.22, I guess, but I'm afraid that my browsing history, sessions, passwords, etc., would be affected, and I don't want to find all the files and support first. It's a hassle. Since the sites work in Seamonkey, I'm guessing that's not the fact that I have updated flash at the same time. I don't know how much these sites use flash, either. But if it's a problem of flash, I tell myself I should have the same problem in Seamonkey, and I did not.

    I wish that you guys would have an easy option to restore your updates because it's pretty darn annoying when they cause problems. Usually, they are not lethal problems, however, and the browser still works. Now ff does not work for some sites I use most often.

    Hello

    Many issues of the site can be caused by corrupted cookies or cache. To try to solve these problems, the first step is to clear cookies and cache.
    Note: This will be you temporarily disconnect all sites, you're connected to.
    To clear the cache and cookies to do the following:

    1. Go to Firefox > history > clear recent history or (if no Firefox button is displayed) go to tools > clear recent history.
    2. Under "Time range to clear", select "all".
    3. Now, click the arrow next to details to toggle the active details list.
    4. In the list of details, see the Cache and Cookies and uncheck everything.
    5. Now click the clear now button.

    More information can be found in article to clear your cache, history, and other personal information in Firefox .

    __________________________________________________________________

    Also, some Firefox problems can be solved by performing a clean reinstall. This means that you remove Firefox program files, and then reinstall Firefox. Please follow these steps:

    Note: You can print these steps or consult them in another browser.

    1. Download the latest version of Firefox from http://www.mozilla.org office and save the installer to your computer.
    2. Once the download is complete, close all Firefox Windows (click on quit in the file menu or Firefox).
    3. Remove the Firefox installation folder, which is located in one of these locations, by default:
      • Windows:

        • C:\Program Files\Mozilla Firefox
        • C:\Program Files (x 86) \Mozilla Firefox
      • Mac: Delete Firefox in the Applications folder.
      • Linux: If you have installed Firefox with the distribution-based package manager, you must use the same way to uninstall: see Install Firefox on Linux. If you have downloaded and installed the binary package from the Firefox download page, simply remove the folder firefox in your home directory.
    4. Now, go ahead and reinstall Firefox:
      1. Double-click on the downloaded Setup file and go through the steps in the installation wizard.
      2. Once the wizard is completed, click to open Firefox directly after clicking the Finish button.

    This will remove not essential info unless you check the box "delete all my personal data too.

    Please report back to see if this helped you!

    Thank you.

  • Satellite A100: webcam works does not for windows live messenger on Vista

    I recently lost my picture when working for video calls in windows live messenger, the sound of two ways and I can see them, but no one can see me.
    I also bought an external webcam, and it does not work either.

    When I go to Device Manager it says that the two cams don't work properly.
    I tried to update the drivers but they are up-to-date.
    I wonder if it's a problem of Windows live or Toshiba.
    I use Windows Vista Home Premium and the new version of messenger.

    > I also bought an external webcam and it doesn t work either.
    > When I go to Device Manager it says that the two cams don't work properly

    For me, it looks like a windows system problem.
    Usually two webcams operate independently from each other and so I don t think that it is a webcam driver problem I think that it s windows or windows live messenger problem
    Maybe something confused keys registry or files may be some updates to update or similar

    In your case, I recommend you to uninstall the software of webcam software, internal external webcam and the windows live messenger.
    Then, you must clean the BONES and the registry tool like CCLeaner cleaning, for example. It the free tool.

    After this, reinstall the Chicony webcam software and test functionality without installation of windows live messenger.
    If the webcam will be functions then you could install the windows live messenger again.

  • Want Dv6 - 7300st: finger print works does not for Windows 10

    Hello

    I've updated 10 64-BIT windows. then after I find, validity wbf ddk driver does not. It engages and works in the background

    Please help me driver for windows 10 64-BIT

    Hi @mahmutbasar,

    There is no newer driver for Windows 10 fingerprint sensor. It seems that the old driver is not compatible with the Windows 10 either. So, if the fingerprint work in previous windows, it's a matter of software with Windows 10.

  • ITunes 9.1 works does not for Windows Vista

    I've recently updated itunes 9.1 and when I click to open the program, nothing happens

    It is open in the process in the Task Manager

    I tried to uninstall, download of the installer on the itunes site and still does not work

    I am running Windows Vista

    Help would be greatly appreciated, thanks

    Hi all

    You can watch on the Apple site for troubleshooting iTunes and Windows Vista.

    http://www.Apple.com/support/iTunes/

    The article watch is titled: iTunes for Windows Vista or 7: Troubleshooting unexpected quits unexpectedly, freezes, or launch issues

    I hope this helps.

    Sincerely,

    Marilyn
    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think

  • Webcam works does not for windows 8

    Hello

    Yesterday I installed GoogleVoiceandVideoSetup to use Gtalk WebCam but after installing it, my webcam does not work.
    It doesn't show any picture, can someone help me on this.
    Kind regards
    Gaurav Dey

    I found the solution: -.

    I went to the Device Manager. Rode to the previous setting, and after that I re-installed the latest drivers and it works for me.
    :)
  • Lights up does not, for anything!

    I'm doing a cool video with some models of a video game, one of them is a giant robot and I imported into the 3-d element with it's diffuse texture so that I could composite it inside the after-effects.

    The only problem is that lights does not work on anything WHATSOEVER, except ambient lights that makes everything more clear. The model turns black when the light is activated (point, point, and parallel)

    It's very weird, the rendering mode is set to classic 3D and draft mode is off.

    Is there something I need to keep in mind when adding lights that I missed browsing Google for an answer?

    THX

    I solved the problem. 3D of the element normals were not be shaded because I had only broadcasts a texture, so I had to check the box "Auto-normales" to get the lights to work with the model.

  • Compact/shrink *.vmdk does NOT (for Ubuntu guestOS)

    I have a Ubuntu guestOS installation running on a Win7 hostOS.

    The corresponding *.vmdk file has a size of about 8.5 GB (!).

    When I start the virtual machine and enter in a terminal:

    DF h

    then I can see that the partition contains only 3.9 GB (= 'used').

    So he has a lot of space that can be compacted/shrunk.

    I leave the guestOS and go to the menu:

    Machine settings VMware-> hardware-> drive-> utilities-> Compact

    and began an operation of "compact".

    Much to my surprise the *.vmdk file is subsequently (or almost) big as before.

    If compacting doesn't seem DO NOT work.

    Why?

    A defragmentation does not help.

    Some with VmWare Player.

    And even with the command cmdline

    VMware - vdiskmanager.exe - k Ubuntu.vmdk

    If not, how can I compact shrink the *.vmdk?

    Matt

    Assuming that the VMware virtual disk is not previously affected and the file system is ext4, you will need to manually prepare to be narrowed.

    In the virtual machine, in a Terminal, become root and then copy and paste the following command, as is and then press ENTER:

    dd if=/dev/zero of=wipefile bs=1024x1024; rm wipefile
    

    Wait for the prompt to return, then press stop the virtual computer, then the settings of the Virtual Machine for the hard drive to select the Compact command from the utility button.

  • BlackBerry Smartphones QWERT keyboard does not for text messages.

    My keyboard does not appear when I switch my phone when I check my e-mail or text messages. If I use my browser or anything else needing a keyboard, it works fine. Anyone who has an idea on what could be the cause?

    Excellent! Batt-pop reboots are as restart a PC - a healthy thing!

  • Hotel Web does not for formmail cgi script. What should I use instead, and how to run it?

    Hello

    I'm close tothey done with my new site of clslow and just found out that his webhotel does not offer the simple cgi-script I usually use

    Any suggestions that I can use instead (I guess PHP and it's Greek to me...), but how do I do it?

    Address on the site and the actual page is here: http://www.kennelmannequins.se/ToftaBilII/servicebokning.html (it is in Swedish, so don't be scared if you don't understand the language)

    I hope you can help me!

    Carolin

    Try NateMail or ProcessForm from the link below. Both come with a simple step by step pdf, set up the guide.

    The two are old enough but will get the job done.

    http://www.MindPalette.com/archives/ProcessForm/

  • Satellite A660 - program does not for a mili-second

    Hello

    Sometimes, the program I use flashes in mode of non-resonsive.

    For a milli-second the program stops or the image of the desktop appears and then disappears again.
    Sometimes it happens only once, but in some programs, it happens constantly and they are impossible to use.

    I have an A660 running Windows 7, 32-bit with an i7 from intel.
    I loaded all the latest updates to the graphics card and drivers.

    Does anyone else have this problem?

    Thank you

    Hi mate

    It's ok.
    You will always notice a delay while loading some applications or software.
    This happens because the software loads into RAM.
    It depends also processes that are running in the background.
    Background processes can insist on the CPU and this can affect the performance of the application or may cause some short delays

    To improve this, I recommend cleanning the OS using CCleaner and disable certain porocesses that are not really important to you.
    You can do it is msconfig

  • CSS border-radius rule does not work in IE9

    Hi all.

    I wonder if anyone has a CSS border-radius rule to work with release of RoboHelp's WebHelp/WebHelp Pro in IE9?

    I have tried to create a new, empty project and have used some simple built-in CSS (no external CSS is called), namely:

    < style type = "text/css" >

    div {}

    border-radius: 15px;

    background-color: #f00;

    }

    < / style >

    and then, in the <>body, all this:

    < div >

    < p > Hello world. < /p >

    < / div >

    The result is exactly as expected when viewed as Safari, Chrome and Firefox, but IE9 stubbornly refuses to display curved corners on the div. The same code works perfectly in IE9 when I write it in Dreamweaver.

    I thought that I might have met around the problem when I found a site which proposes to add the following code to the head of <>:

    < meta http-equiv = "X-UA-Compatible" content = "IE = 9" / >

    It seemed to work when previewing the theme with the "Show selected item" button (it looks like a pair of glasses), but when the WebHelp output has been generated, the rounded corners were still left in IE9. The same is true when the output with WebHelp Pro.
    So, is the process of release of RoboHelp do something to remove the application of the rule of border-radius in IE9? By specifying values individual border-radius for each side of the div did not help either.
    I use RoboHelp 9.0.1.232.

    Hello

    Just did a quick test and it's certainly a bug in IE9. It seems that when you use frameset, the top frame rendering mode is used for all of the images below. Given that the appearance of WebHelp file still use the game of HTML 4 frames, the IE9 rendering mode is on quicks mode or something.

    Solution: Add the meta tag for IE not only your topics, but all of the htm files mode in your output. Try my rendered IE script tags: http://www.wvanweelden.eu/robohelp/scripts/ierendertags. This will add tags to all htm files in your output. Voila, the boundary curves are now visible in IE9.

    A note: I have no idea what standard mode of IE will be at the table of the contents/index/search/etc. of the WebHelp. I don't know if IE9 is already supported by Adobe so be sure to test your WebHelp.

    Take a bow

    Willam

Maybe you are looking for