SE2 RADIUS AAA with 3750E Version 12.2 (53)

Hi guys,.

I'm fighting with NPS AA configuration for our 3750 array... authentication and authorization

I tried almost every config I could find online, but the more I got out it is a simple authentication. What I need is quite simple:

We have several ad groups

1 - Admin

2 - Readonly with few privileges for ping, traceroute and show, telnet

I need my switches to recognize groups and assign the correct private. But it doesn't seem to be the case. Can someone show a clean config for the switch and NPS?

Thank you

P.S. I created and deleted most of my configs so if someone has something to clean and detail I would very much apreciate it.

Hello

This is the configuration I have on my IOS switch:

AAA authentication login default local radius group

AAA authentication enable default group enable RADIUS

RADIUS group AAA authorization exec default authenticated if

RADIUS-server host x.x.250.20 auth-port 1645 acct-port 1646 key xxxxxxx

I created two policies on the IAS (yours would be NPS). Both have Windows groups such as designating a ReadOnly condition and the other in the FullAccess group.

ReadOnly results return Service-Type NAS-Prompt

FullAccess results return Type of Administrative Service

When a user of ReadOnly access, I get:

User access audit

Username: priv1

Password:

Switch > en

Password:

% Authentication failure.

Switch >

Thus, the user is limited to the unpriviledged (>) mode controls.

When a user of FullAccess accessing:

User access audit

Username: priv15

Password:

Switch #.

I get directly affected to activate the Mode (#) due to the Administrative value of the attribute Type of service.

According to the role based there is a document on the Forum that refers to GANYMEDE + as well

https://supportforums.Cisco.com/docs/doc-15765

Kind regards.

Tags: Cisco Security

Similar Questions

  • AAA with RADIUS of ASA

    Hey everybody,

    I'm with RADIUS AAA configuration on our Firewall remote ASA.  It's pretty simple, but I have some firewall that does not work on.  I upgraded the IOS image on the ASA 5510 to ASA804-K8. BIN on each of them.  The weird part is some of them work and some of them do not work.

    I was wondering if anyone else has encountered this before and what information do you need to give me a reference to help.

    Thanks in advance,

    Kimberly

    Hi Kimberly,

    just curious: why 8.0.4 and not 8.0.5?

    What you use radius for? What is the radius server? You have configured all the ASAs of the radius servers? Did you use the right shared secret?

    Is there something different between the ASAs working and does lack those? Configuration, location in the network, etc.?

    If the above does not help, please post the config of ASA failure (or at least the relevant items and be sure to remove all sensitive data) and the output of:

    Debug RADIUS

    Debug aaa authentic

    Debug aaa 254 Commons

    You can test only the part of RADIUS with the command «test aaa-server authentication cli...» »

    HTH

    Herbert

  • No remote access after you activate the Radius AAA

    Hello

    I can't access our catalyst 4006 after activating the AAA for RADIUS. I have install IAS on our domain controller configuration / a catalyst as a Radius client and configured a remote access policy that points to an ad group to allow access to the switch. When I try to connect to catalyst by my user information in AD, it seems to crash after I type my password, asks for the password again, then says access denied. This happens both on the console and through a telnet session. I have included below the configuration of my AAA.

    What Miss me?

    Tim

    (Cisco IOS 12.2 v software (25) EWA14)

    AAA new-model

    !

    RADIUS-server host 10.100.x.x auth-port 1812 acct-port 1813 key xxxxxxxxxx

    Server RADIUS ports source-1645-1646

    !

    AAA Radius Server Group server RADIUS

    Server 10.100.x.x auth-port 1812 acct-port 1813

    !

    AAA authentication login default group local line Radius servers

    the AAA authentication enable default group, select Radius servers

    Authentication servers-Radius AAA dot1x default group

    Group AAA authorization exec default for authenticated if Radius servers

    Group AAA authorization network default Radius servers

    AAA dot1x default arrhythmic accounting Radius Servers group

    AAA accounting by default start-stop group Radius servers directly

    !

    line vty 0 4

    by default the authentication of connection

    Tim

    I think that the immediate problem is that the source address of your switch ussed is not address who is pregnant with Ray. The Radius Server is 10.100.182.250 and it is in the subnet of the interface vlan 182. If the address of the interface vlan 182 will be the source address of the Radius request. Difficulty which is to use the command of source ip range address and specify the address at which you want the switch to be used. Of course, in the short term, it would be easier to change the Radius Server to wait 10.100.182.2 as the address of the customer.

    HTH

    Rick

  • Problem with iPhone and iPad ios10 connect with iTunes version 12.2.2

    Yesterday, I upgraded my iPhone and iPad to ios10 successfully. However, when I try to connect to my Macbook OSX version 10.7.5 running with iTunes version 12.2.2.25 it gave me this error "iTunes could not connect to the iPad because an invalid response was received from the device." I got the same error when I connect my iPhone as well.

    Now I can't restore my iPad or iPhone in low-grade IOS because iTunes can not see my devices.

    Someone at - it this experience after upgrade to ios10?

    Hi Had3s,

    I understand that after updating to iOS 10, your MacBook is more recognized in iTunes. I know it's important to be able to sync your iPhone with iTunes, so I'm happy to help you.

    Read this article that covers some common troubleshooting for this issue:
    If iTunes does not recognize your iPhone, iPad or iPod - Apple Support

    Note that the likely cause here is an older version of iTunes. Since iOS 10 is still new, it is important to have the latest version of iTunes installed. Currently, it is 12.5.1, that requires OS X 10.9.5 or later version must be installed:
    iTunes - download iTunes - Apple

    Since you currently have OS X installed 10.7.5, you'll want to update to OS X as well. You can see more info on how to upgrade to the latest version of Mac OS X here:
    Update of OS X El Capitan - Apple Support

    Thank you for using communities Support from Apple. See you soon!

  • CCleaner shows a plugin in firefox without the name of the program or the Publisher and with a version number of '0', and it can be disabled or deleted.

    CCleaner shows a plugin in Firefox without the name of the program or the Publisher and with a version number of '0', and it can be disabled or deleted. It is a plugin for Firefox by default, and if so, what do I do? It does not appear in my list of Firefox addons in Firefox and a malware scan does not detect.

    It is possible that the profile has become corrupted, and you can try to start a new profile.

  • My old themes do not work with this version of FF.

    On the latest upgrades FF bit the themes available considerably decreased and now the majority of my registered themes said "not compatible with this version of FF. Whyzat?

    You are using a beta version and not the current stable version.
    Beta version using decreases your chances of having complete (full) themes compatible because the next version can use toolbar buttons that have not been used in the current version and a theme must include the icons of all the toolbar buttons to work properly and be compatible.

  • How can I update with a version without losing any data?

    I have a ZTE open regularly update with custom versions. Whenever I do this, I lose all my data on the phone, like contacts, applications installed in the store of market parameters (including wireless and send the parameters).

    All these data and recovery each time settings is extremely annoying. Is there a way to not lose in the process or to save them and repristining them later?

    Hi Enrico,.

    I know that for import/export of contacts, you can use the following commands:

    • to export contacts (excerpt):
    adb pull /data/local/indexedDB/chrome db
    

    This will store all the data of your device in a folder (in this case, called db) that is created when you opened your shell.

    • to restore (push) back of the unit:
    adb push db /data/local/indexedDB/chrome
    

    Following Github repository offers other tools and scripts for flashing, restore and backup of Gaia:

    I just tried to backup/restore a few times in the past, but it did not work as expected. Feel free to test them with caution. =)

    Thank you!!

    -Ralph

  • How can I configure Thunderbird to open with the last box to the letters that I used as it did with earlier versions?

    I use OS 10.9.2 on a Macbook Pro with Thunderbird 24.4.0. Unfortunately, it opens with "Local folder" and I can't change that. My previous Thunderbird version 3.1.20 would always open to the last mailbox I was using.

    I transferred my old computer profile and everything seems to work very well

    I set the preferences in the same way that I did it with the version 3.2.10, but no matter what I do, it always ends up opening to local folders.

    Any suggestions?

    Thank you

    Allen

    https://addons.Mozilla.org/en-us/Thunderbird/addon/FolderPane-tools/?src=search

  • How to return to the previous version? A new is not compatible with my version of OSX.

    I'm running 10.4.11 and had 3.6.something of Firefox. I installed the update of Firefox, assuming that, if it was not compatible with my version of OSX, it wouldn't install. First, huge mistake. I need to go back to my previous version. I have no system resources to upgrade the version of the OS.

    Just choose your language like for example if you want the English of the United States, see

    http://download.CDN.Mozilla.NET/pub/mozilla.org/Firefox/releases/3.6.28/Mac/en-us/Firefox%203.6.28.dmg

    If you meet the requirements of equipment in addition to an Intel processor, you may be able to upgrade to 10.6.x

  • Firefox worked, today has not started with the error the version of this file is not compatible with the version of windows you are using.

    Computer is Windows 7 Ultimate 64 bit. Firefox has work fine for over a year on this computer. Nothing has been changed or updated updated except Windows update indicates that it installed updates on August 19. I had computer week before because only out of town, back entrance and began August 18, but Firefox has worked that day. Does not use FF again until today. Today August 22, firefox does not start, shortcut icon changed program not there. Exe in the folder when you click Poster error message says the version of this file is not compatible with the version of Windows, I am running. Exe of Firefox shows created on 20 August. I suspect the update, Windows or FF but lean towards windows, which was spent, who broke things. I noticed that IE 10 updates, updates of .NET framework and the malicious software removal tool have been installed. I tried to restart the computer, has not set. Tried to run as administrator, did not work. I don't want to uninstall FF, at least have to because of all the things I have here, bookmarks, last past passwords, etc..

    Hello

    Some Firefox problems can be solved by performing a clean reinstall. This means that you remove Firefox program files (not the profile folder, where the bookmarks are stored) and then reinstall Firefox. Please follow these steps:

    Note: You can print these steps or consult them in another browser.

    1. Download the latest version of Firefox from http://www.mozilla.org office and save the installer to your computer.
    2. Once the download is complete, close all Firefox Windows (click on quit in the file menu or Firefox).
    3. Remove the Firefox installation folder, which is located in one of these locations, by default:
      • Windows:

        • C:\Program Files\Mozilla Firefox
        • C:\Program Files (x 86) \Mozilla Firefox
      • Mac: Delete Firefox in the Applications folder.
      • Linux: If you have installed Firefox with the distribution-based package manager, you must use the same way to uninstall: see Install Firefox on Linux. If you have downloaded and installed the binary package from the Firefox download page, simply remove the folder firefox in your home directory.
    4. Now, go ahead and reinstall Firefox:
      1. Double-click on the downloaded Setup file and go through the steps in the installation wizard.
      2. Once the wizard is completed, click to open Firefox directly after clicking the Finish button.

    Please report back to see if this helped you!

    Thank you.

  • I downloaded the new version and it says: you cannot use this application with this version of Mac os how can I download the older version?

    I downloaded the new version and it says: you cannot use this application with this version of Mac os how can I download the older version? My os is 10.4.11

    You can read this article: Firefox no longer works with Mac OS X 10.4 or PowerPC processors to read about the EOL for Mac 10.4 support and what the best options going forward.

  • Impossible to pass guard Office suspended on the verification of the addons with new version 3.6,

    I want to improve every time I have the same problem. A normal level is normal, but then the new version will check the addons for compatibility and there it does'nt go further.

    Also, when I first delete the entire installation of firefox and you want to install, I get the same problem

    I used version 3 for years, as whenever I tried an update, it crashes. Even with 9. So I had to always go back and reinstall 3, where everything would be fine. 9 works on my laptop with Vista and the new feature I wanted was synchronization, to synchronize bookmarks. This idea of love. But on my desktop with XP, could not for the life of me get Firefox works with any version past 3.

    Here's the solution that worked for me:

       opened the version that worked, and saved bookmarks to USB drive. That's the main thing I wanted in the new version.
       uninstalled FF
       manually deleted all files in FF and Mozilla folders on the hard drive, including any folder named "mozilla" or "firefox"
       edited the registry (read about how to do this properly elsewhere) and manually did a search for and removed every single instance of "mozilla" and "firefox" that existed on the computer. Made sure I did search from the top of the registry tree
       rebooted
       installed firefox 9
       imported bookmarks from USB drive
    

    everything works fine now! Years of updates does not work and a clean registry does the job.

  • What's up with the Version of El Capitan 10.11.4?

    What's up with the Version of El Capitan 10.11.4? I downloaded the update and see various improvements listed there. But, how can I take advantage of the improvements. There should be a better source to help the owners/users to take advantage of recent improvements.

    Don't know if you saw this link: http://www.macrumors.com/2016/03/21/apple-releases-os-x-10-11-4/

    Kim

  • How to return to the earlier version of El Capitan (from 10.11.3 at 10.11.1) with Time Machine? My HP LaserJet M475dw MFP printer worked fine with previous versions, but fails miserably to recognize the device on the same Wi - fi network now?

    How to return to the earlier version of El Capitan (from 10.11.3 at 10.11.1) with Time Machine? My HP LaserJet M475dw MFP printer worked fine with previous versions, but fails miserably to recognize the device on the same Wi - fi network now with 10.11.3.  I would like to restore the previous version of the operating system without losing any data created in various applications since the 10.11.1.  Fortunately, I had only to use Time Machine is rare over the years, I do not know if you have to return the entire drive to the chosen date or it can somehow just go back to a previous state of OS.  Any suggestions, much appreciated.

    OS X El Capitan: revert to a previous version of OS X

  • I am not able to remove applications pre-installed in iPad model MD910HN with iOS version 6.0.1

    The team, I have MD910HN model of iPad with iOS version 6.0.1.

    I'm trying to upgrade the software, it gives an error of memory almost full. I am also not able to remove the preload Apps.It is a piece of purchased from Croma retail demo.

    Please advise on the solution to remove the preinstalled applications or reset the unit to factory settings.

    You cannot delete built-in on an iPad apps.

    You can try to reset to the factory settings via settings > general > reset > erase all content and settings, or through the Summary tab when it is connected to the computer iTunes - but if it's a demonstration model, they may not work, you may need to contact Apple and see if they can / will help (demo devices must not be sold)

Maybe you are looking for

  • How can I stop firefox from automatically suggest popular searches when I type in the url bar?

    When I start typing in the url for that bar he used to AutoComplete my most used address. Now, the first thing it comes up with is a list of popular searches. for example, I type "tw" and he used to AutoComplete to "twitch.tv" now the first thing tha

  • HDMI to VGA

    Hello I have mac pro mf839 and buy Cable HDMI to VGA but my screen (samsung) did not show something! How can it work? How to detect my monitor under macOS

  • only account admin on vista home 'broken '.

    I have a system running vista SP1 and somehow my account (admin only) is watered. When I try to open a session, after entering the password, the screen goes black with a mouse cursor. The mouse cursor moves, but the keyboard does nothing (CTRL-ALT-DE

  • Can not connect to my computer, even in safe mode.

    my computer won't let me open a session inside the regular way or safe mode.  It tries to start, possibly page asking my password appears and immediately disappears and the screen goes black.  Can someone help me with this? or is the computer just we

  • Report not working not not S170

    After upgrade to 9.1.1 - 074 I have problem with report (by users, websites...) He said "no data was found in the selected time interval" but S170 normally works. In alerts, this message is: There is no such thing as a counter group "WEB_SERVICES_SUM