<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: What RADIUS attribute to send is needed when adding a Cisco ASA to the NAC appliance for AAA Mangement Access? in ExtremeWireless (General)</title>
    <link>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29567#M343</link>
    <description>I was just thinking out loud but never tried it with any C device.&lt;BR /&gt;</description>
    <pubDate>Thu, 18 Jan 2018 03:28:00 GMT</pubDate>
    <dc:creator>Ronald_Dvorak</dc:creator>
    <dc:date>2018-01-18T03:28:00Z</dc:date>
    <item>
      <title>What RADIUS attribute to send is needed when adding a Cisco ASA to the NAC appliance for AAA Mangement Access?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29561#M337</link>
      <description>I am trying to add a Cisco ASA to the NAC appliance for RADIUS Management Access.  I started by enabling SNMP between the ASA  and NetSight Console. But in order to add the ASA to the NAC appliance, I need to specify a RADIUS attribute to send.  What do I need to put?</description>
      <pubDate>Thu, 18 Jan 2018 01:37:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29561#M337</guid>
      <dc:creator>Pierre_Demassey</dc:creator>
      <dc:date>2018-01-18T01:37:00Z</dc:date>
    </item>
    <item>
      <title>RE: What RADIUS attribute to send is needed when adding a Cisco ASA to the NAC appliance for AAA Mangement Access?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29562#M338</link>
      <description>Hello Pierre,&lt;BR /&gt;
&lt;BR /&gt;
as Radius attribute you need only the Service-Type like:&lt;BR /&gt;
&lt;BR /&gt;
&lt;I&gt;Service-Type=%CUSTOM2%&lt;/I&gt;&lt;BR /&gt;
&lt;BR /&gt;
Corresponding I set the Accept Policy to &lt;I&gt;6 in Custom 2&lt;/I&gt;. Please be aware of the setting in the Management Attributes field. You need this settings to get access via GUI and SSH to your ASA.&lt;BR /&gt;
&lt;BR /&gt;
As far as I found out you can not distinguish the privilege level!&lt;BR /&gt;
&lt;BR /&gt;
Best regards&lt;BR /&gt;
Stephan&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="21a12df5c65b4261af950e5b2931bd37_RackMultipart20180117-36107-rxbdw3-ASA_inline.jpg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/789i98A24A42A4A1869C/image-size/large?v=v2&amp;amp;px=999" role="button" title="21a12df5c65b4261af950e5b2931bd37_RackMultipart20180117-36107-rxbdw3-ASA_inline.jpg" alt="21a12df5c65b4261af950e5b2931bd37_RackMultipart20180117-36107-rxbdw3-ASA_inline.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 18 Jan 2018 03:10:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29562#M338</guid>
      <dc:creator>StephanH</dc:creator>
      <dc:date>2018-01-18T03:10:00Z</dc:date>
    </item>
    <item>
      <title>RE: What RADIUS attribute to send is needed when adding a Cisco ASA to the NAC appliance for AAA Mangement Access?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29563#M339</link>
      <description>I could be wrong but after reading this...&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://www.cisco.com/c/en/us/td/docs/ios/12_2/security/configuration/guide/fsecur_c/scfrdat1.html" target="_blank" rel="nofollow noreferrer noopener"&gt;https://www.cisco.com/c/en/us/td/docs/ios/12_2/security/configuration/guide/fsecur_c/scfrdat1.html&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
...I wonder whether you could use RADIUS attribute "cisco-avpair= "shell:priv-lvl=&lt;I&gt;%CUSTOM2%&lt;/I&gt;"" and then make more then one rule with different custom#2 values to represent the privilege levels ?!&lt;BR /&gt;
&lt;BR /&gt;
-Ron</description>
      <pubDate>Thu, 18 Jan 2018 03:28:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29563#M339</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2018-01-18T03:28:00Z</dc:date>
    </item>
    <item>
      <title>RE: What RADIUS attribute to send is needed when adding a Cisco ASA to the NAC appliance for AAA Mangement Access?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29564#M340</link>
      <description>&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="67dab6514e0f47acbf68006887c3bd04_RackMultipart20180117-59112-1e4g2bo-Cisco_VSA_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2639i400FC6150A64D092/image-size/large?v=v2&amp;amp;px=999" role="button" title="67dab6514e0f47acbf68006887c3bd04_RackMultipart20180117-59112-1e4g2bo-Cisco_VSA_inline.png" alt="67dab6514e0f47acbf68006887c3bd04_RackMultipart20180117-59112-1e4g2bo-Cisco_VSA_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 18 Jan 2018 03:28:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29564#M340</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2018-01-18T03:28:00Z</dc:date>
    </item>
    <item>
      <title>RE: What RADIUS attribute to send is needed when adding a Cisco ASA to the NAC appliance for AAA Mangement Access?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29565#M341</link>
      <description>Thanks, I'll see if that can work.  I'll report back.</description>
      <pubDate>Thu, 18 Jan 2018 03:28:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29565#M341</guid>
      <dc:creator>Pierre_Demassey</dc:creator>
      <dc:date>2018-01-18T03:28:00Z</dc:date>
    </item>
    <item>
      <title>RE: What RADIUS attribute to send is needed when adding a Cisco ASA to the NAC appliance for AAA Mangement Access?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29566#M342</link>
      <description>Hmm Ronald, &lt;BR /&gt;
&lt;BR /&gt;
this granular settings you mentioned works with Cisco Prime and I can switch different user groups and view, but not with Cisco ASA. Maybe I did a mistake but my mentioned setting work for me and my customer and so I did no more investigations .&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Thu, 18 Jan 2018 03:28:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29566#M342</guid>
      <dc:creator>StephanH</dc:creator>
      <dc:date>2018-01-18T03:28:00Z</dc:date>
    </item>
    <item>
      <title>RE: What RADIUS attribute to send is needed when adding a Cisco ASA to the NAC appliance for AAA Mangement Access?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29567#M343</link>
      <description>I was just thinking out loud but never tried it with any C device.&lt;BR /&gt;</description>
      <pubDate>Thu, 18 Jan 2018 03:28:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29567#M343</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2018-01-18T03:28:00Z</dc:date>
    </item>
    <item>
      <title>RE: What RADIUS attribute to send is needed when adding a Cisco ASA to the NAC appliance for AAA Mangement Access?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29568#M344</link>
      <description>I'm looking in the drop-down box for the 'RADIUS Attribute to Send' in the NAC.  How do set it to Service Type you mentioned?</description>
      <pubDate>Thu, 18 Jan 2018 03:46:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29568#M344</guid>
      <dc:creator>Pierre_Demassey</dc:creator>
      <dc:date>2018-01-18T03:46:00Z</dc:date>
    </item>
    <item>
      <title>RE: What RADIUS attribute to send is needed when adding a Cisco ASA to the NAC appliance for AAA Mangement Access?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29569#M345</link>
      <description>Hello Pierre,&lt;BR /&gt;
&lt;BR /&gt;
you have to configure the radius attribute to sind in the Switch context and you can create a new attribute group.&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="fb03b91b47c2457c81362a90f73382bb_RackMultipart20180117-4427-gshx4m-ASA2_inline.jpg"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/383i2C27558B24823B9C/image-size/large?v=v2&amp;amp;px=999" role="button" title="fb03b91b47c2457c81362a90f73382bb_RackMultipart20180117-4427-gshx4m-ASA2_inline.jpg" alt="fb03b91b47c2457c81362a90f73382bb_RackMultipart20180117-4427-gshx4m-ASA2_inline.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 03:55:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29569#M345</guid>
      <dc:creator>StephanH</dc:creator>
      <dc:date>2018-01-18T03:55:00Z</dc:date>
    </item>
    <item>
      <title>RE: What RADIUS attribute to send is needed when adding a Cisco ASA to the NAC appliance for AAA Mangement Access?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29570#M346</link>
      <description>Hello all, thanks for the assistance.  I'm still having issues getting it to work.  &lt;BR /&gt;
&lt;BR /&gt;
I configured a new attribute group and set it with Service-Type=%CUSTOM2%.  I then did 2 things: I created a new rule specific for the ASA access management.  Then I created a new profile with a new policy mapping to include the instructions that SH provided above. I did this because I had an existing rule and policy mapping that was set for Enterasys and EXOS access management. I didn't want to break those.&lt;BR /&gt;
&lt;BR /&gt;
The issue may lie with the SNMP configuration.  It loses connectivity with the ASA intermittently.  The ASA SNMP  User/Group configuration is confusing.  &lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 19 Jan 2018 23:36:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29570#M346</guid>
      <dc:creator>Pierre_Demassey</dc:creator>
      <dc:date>2018-01-19T23:36:00Z</dc:date>
    </item>
    <item>
      <title>RE: What RADIUS attribute to send is needed when adding a Cisco ASA to the NAC appliance for AAA Mangement Access?</title>
      <link>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29571#M347</link>
      <description>So we got this to work by using the following:&lt;BR /&gt;
&lt;BR /&gt;
Service-Type=%CUSTOM2% for the custom RADIUS attribute. &lt;BR /&gt;
&lt;BR /&gt;
The Policy mapping is as follows:&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="909f1c2653f14ff09eefc2d0d096dc0c_RackMultipart20180125-9602-1x5pzgu-Image_12_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2010i14E9874EAB5FB41A/image-size/large?v=v2&amp;amp;px=999" role="button" title="909f1c2653f14ff09eefc2d0d096dc0c_RackMultipart20180125-9602-1x5pzgu-Image_12_inline.png" alt="909f1c2653f14ff09eefc2d0d096dc0c_RackMultipart20180125-9602-1x5pzgu-Image_12_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
Most of the config work has to be done on the ASA side.  I did it using the ASDM.  This method allows for RADIUS auth to both the ASMD and SSH.  Priv exec mode also works as well.  These settings were configured through the ASDM.</description>
      <pubDate>Thu, 25 Jan 2018 22:18:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremewireless-general/what-radius-attribute-to-send-is-needed-when-adding-a-cisco-asa/m-p/29571#M347</guid>
      <dc:creator>Pierre_Demassey</dc:creator>
      <dc:date>2018-01-25T22:18:00Z</dc:date>
    </item>
  </channel>
</rss>

