<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: X460-24x and FreeRadius in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/x460-24x-and-freeradius/m-p/41164#M9430</link>
    <description>Create Date: Aug 16 2012  4:03PM&lt;BR /&gt;
&lt;BR /&gt;
You will need this attribute:&lt;BR /&gt;
&lt;BR /&gt;
Service-Type = Administrative  (from john_padilla)</description>
    <pubDate>Wed, 08 Jan 2014 05:54:00 GMT</pubDate>
    <dc:creator>EtherNation_Use</dc:creator>
    <dc:date>2014-01-08T05:54:00Z</dc:date>
    <item>
      <title>X460-24x and FreeRadius</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/x460-24x-and-freeradius/m-p/41163#M9429</link>
      <description>Create Date: Aug 14 2012 11:06PM&lt;BR /&gt;
&lt;BR /&gt;
Good day!&lt;BR /&gt;
May be you can help me?&lt;BR /&gt;
I have a X460-24x configured to be a radius client.&lt;BR /&gt;
But can't login to switch with read-write privileges. Only with read rights.&lt;BR /&gt;
The user in userss file looks like:&lt;BR /&gt;
user            Crypt-Password := '/fc/f%Q(T2msY', Auth-Type := Crypt-Local&lt;BR /&gt;
                Service-Type = NAS-Prompt-User,&lt;BR /&gt;
                Service-Type = Login-User,&lt;BR /&gt;
                Cisco-AVPair = "shell:priv-lvl=15",&lt;BR /&gt;
                Extreme-CLI-Authorization = Disabled&lt;BR /&gt;
&lt;BR /&gt;
I have added to the dictionary file:&lt;BR /&gt;
VENDOR  Extreme 1916&lt;BR /&gt;
BEGIN-VENDOR    Extreme&lt;BR /&gt;
ATTRIBUTE       Extreme-CLI-Authorization       201     integer Extreme&lt;BR /&gt;
ATTRIBUTE       Extreme-Shell-Command   202     string  Extreme&lt;BR /&gt;
ATTRIBUTE       Extreme-Netlogin-Vlan   203     string  Extreme&lt;BR /&gt;
ATTRIBUTE       Extreme-Netlogin-Url    204     string  Extreme&lt;BR /&gt;
ATTRIBUTE       Extreme-Netlogin-Url-Desc       205     string  Extreme&lt;BR /&gt;
ATTRIBUTE       Extreme-Netlogin-Only   206     integer Extreme&lt;BR /&gt;
ATTRIBUTE       Extreme-User-Location   208     string  Extreme&lt;BR /&gt;
ATTRIBUTE       Extreme-Netlogin-Vlan-Tag       209     integer Extreme&lt;BR /&gt;
ATTRIBUTE       Extreme-Netlogin-Extended-Vlan  211     string  Extreme&lt;BR /&gt;
ATTRIBUTE       Extreme-Security-Profile        212     string  Extreme&lt;BR /&gt;
VALUE   Extreme-CLI-Authorization       Disabled        0&lt;BR /&gt;
VALUE   Extreme-CLI-Authorization       Enabled 1&lt;BR /&gt;
VALUE   Extreme-Netlogin-Only   Disabled        0&lt;BR /&gt;
VALUE   Extreme-Netlogin-Only   Enabled 1&lt;BR /&gt;
END-VENDOR      Extreme&lt;BR /&gt;
&lt;BR /&gt;
Then i'am trying to login tcpdump shows:&lt;BR /&gt;
         Access Accept (2), id: 0x56, Authenticator: bb4ce22bbe219e946974870d0dd5005a&lt;BR /&gt;
          Service Type Attribute (6), length: 6, Value: NAS Prompt&lt;BR /&gt;
          Vendor Specific Attribute (26), length: 25, Value: Vendor: Cisco (9)&lt;BR /&gt;
            Vendor Attribute: 1, Length: 17, Value: shell:priv-lvl=15&lt;BR /&gt;
          Vendor Specific Attribute (26), length: 12, Value: Vendor: Unknown (1916)&lt;BR /&gt;
            Vendor Attribute: 201, Length: 4, Value: ....&lt;BR /&gt;
&lt;BR /&gt;
I see that Vendor Attribute: 201 value is .... But it should be 0 i think.&lt;BR /&gt;
&lt;BR /&gt;
At the same time radiusd -x  shows:&lt;BR /&gt;
Sending Access-Accept of id 87 to 192.168.1.2 port 56198&lt;BR /&gt;
        Service-Type = NAS-Prompt-User&lt;BR /&gt;
        Cisco-AVPair = "shell:priv-lvl=15"&lt;BR /&gt;
        Extreme-CLI-Authorization = Disabled&lt;BR /&gt;
&lt;BR /&gt;
There is a string value - Disabled. That's better but anyway i thought it should be 0. &lt;BR /&gt;
May be this is the case. What can you suggest?&lt;BR /&gt;
Thank you!  (from Tim_Kap)</description>
      <pubDate>Wed, 08 Jan 2014 05:54:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/x460-24x-and-freeradius/m-p/41163#M9429</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:54:00Z</dc:date>
    </item>
    <item>
      <title>RE: X460-24x and FreeRadius</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/x460-24x-and-freeradius/m-p/41164#M9430</link>
      <description>Create Date: Aug 16 2012  4:03PM&lt;BR /&gt;
&lt;BR /&gt;
You will need this attribute:&lt;BR /&gt;
&lt;BR /&gt;
Service-Type = Administrative  (from john_padilla)</description>
      <pubDate>Wed, 08 Jan 2014 05:54:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/x460-24x-and-freeradius/m-p/41164#M9430</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:54:00Z</dc:date>
    </item>
  </channel>
</rss>

