<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Management Access to Avaya 8300/8600 Switch via NAC RADIUS Server. in Network Architecture &amp; Design</title>
    <link>https://community.extremenetworks.com/t5/network-architecture-design/management-access-to-avaya-8300-8600-switch-via-nac-radius/m-p/13040#M444</link>
    <description>There is Avaya 8300 switch and NAC.&lt;BR /&gt;
I need to management login to switch CLI via NAC RADIUS. In documentation to Avaya 8300 switch I read, that there is Avaya VSA - "Access-Priority" wich need to be sent by RADIUS accept message from RADIUS Server to have mgmt access to Avaya switch. But I can't access to switch! &lt;BR /&gt;
I've done TCP Dump and saw, that there is no access-priority attribute in RADIUS accept packet. Standart attributes (ex. Service-Type or Tunnel-Group-Id and others) RADIUS Server are sent. I think, that there is because NAC RADIUS Server do not know Avaya VSAs. &lt;BR /&gt;
So, can I do something to resolve this problem? I don't want to go deep into NAC's file system to find FreeRADIUS attributes file and write this attribute myself. Maybe there is some tool to do it from GUI or some other way to do it without risk of broke NAC System?&lt;BR /&gt;
&lt;BR /&gt;
Thanks.&lt;BR /&gt;</description>
    <pubDate>Fri, 25 Apr 2014 11:55:00 GMT</pubDate>
    <dc:creator>Mikhail</dc:creator>
    <dc:date>2014-04-25T11:55:00Z</dc:date>
    <item>
      <title>Management Access to Avaya 8300/8600 Switch via NAC RADIUS Server.</title>
      <link>https://community.extremenetworks.com/t5/network-architecture-design/management-access-to-avaya-8300-8600-switch-via-nac-radius/m-p/13040#M444</link>
      <description>There is Avaya 8300 switch and NAC.&lt;BR /&gt;
I need to management login to switch CLI via NAC RADIUS. In documentation to Avaya 8300 switch I read, that there is Avaya VSA - "Access-Priority" wich need to be sent by RADIUS accept message from RADIUS Server to have mgmt access to Avaya switch. But I can't access to switch! &lt;BR /&gt;
I've done TCP Dump and saw, that there is no access-priority attribute in RADIUS accept packet. Standart attributes (ex. Service-Type or Tunnel-Group-Id and others) RADIUS Server are sent. I think, that there is because NAC RADIUS Server do not know Avaya VSAs. &lt;BR /&gt;
So, can I do something to resolve this problem? I don't want to go deep into NAC's file system to find FreeRADIUS attributes file and write this attribute myself. Maybe there is some tool to do it from GUI or some other way to do it without risk of broke NAC System?&lt;BR /&gt;
&lt;BR /&gt;
Thanks.&lt;BR /&gt;</description>
      <pubDate>Fri, 25 Apr 2014 11:55:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/network-architecture-design/management-access-to-avaya-8300-8600-switch-via-nac-radius/m-p/13040#M444</guid>
      <dc:creator>Mikhail</dc:creator>
      <dc:date>2014-04-25T11:55:00Z</dc:date>
    </item>
    <item>
      <title>RE: Management Access to Avaya 8300/8600 Switch via NAC RADIUS Server.</title>
      <link>https://community.extremenetworks.com/t5/network-architecture-design/management-access-to-avaya-8300-8600-switch-via-nac-radius/m-p/13041#M445</link>
      <description>Hi Mikhail,&lt;BR /&gt;
&lt;BR /&gt;
For Avaya branded firmware versions you don't need to worry about Avaya VSAs. For Nortel branded firmware versions it's/was more "complicated", different to configure.&lt;BR /&gt;
&lt;BR /&gt;
In your case, just add the following line to the RADIUS Return Attributes for your Avaya&lt;BR /&gt;
switch(es) in NAC Manager -&amp;gt; Switches Tab -&amp;gt; Edit Switch -&amp;gt; RADIUS Return Attributes, select&lt;BR /&gt;
the one you are currently using: &lt;BR /&gt;
&lt;BR /&gt;
Service-Type=%Custom1%        (or %Custom2%...%Custom5%)&lt;BR /&gt;
&lt;BR /&gt;
In the NAC Profile which is used/applied for CLI access, just use the following values in&lt;BR /&gt;
the Custom1 to Custom5 fields, whichever you used in the above defined RADIUS Return Attribute:&lt;BR /&gt;
&lt;BR /&gt;
A value of "6" gives you admin/RW privileges in the CLI (telnet/SSH).&lt;BR /&gt;
A value of "7" gives you read-only privileges. &lt;BR /&gt;
&lt;BR /&gt;
That's it basically and has worked so far for any Avaya switches.&lt;BR /&gt;
&lt;BR /&gt;
Hope this helps.&lt;BR /&gt;
&lt;BR /&gt;
Kind regards,&lt;BR /&gt;
&lt;BR /&gt;
Markus&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 25 Apr 2014 13:28:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/network-architecture-design/management-access-to-avaya-8300-8600-switch-via-nac-radius/m-p/13041#M445</guid>
      <dc:creator>Markus5</dc:creator>
      <dc:date>2014-04-25T13:28:00Z</dc:date>
    </item>
    <item>
      <title>RE: Management Access to Avaya 8300/8600 Switch via NAC RADIUS Server.</title>
      <link>https://community.extremenetworks.com/t5/network-architecture-design/management-access-to-avaya-8300-8600-switch-via-nac-radius/m-p/13042#M446</link>
      <description>Thanks, Markus.&lt;BR /&gt;
&lt;BR /&gt;
We've done all you wrote, and it works with Avaya 4500 switches. Service-Type=6 - rw access, Service-Type=7 - ro access. That's ok with 4500 switches.&lt;BR /&gt;
But this is not works with Avaya 8300 and 8600 switches! We have not cli access to switches. Maybe, as you wrote before, there is Nortel branded firmware on the 8300/8600...&lt;BR /&gt;
&lt;BR /&gt;
In documentation (Authentication, Authorization and Accounting (AAA) for ERS and ES  Technical Configuration Guide (Document Number : NN48500-558) &lt;A href="http://downloads.avaya.com/css/P8/documents/100123717" target="_blank" rel="nofollow noreferrer noopener"&gt;http://downloads.avaya.com/css/P8/documents/100123717&lt;/A&gt;  ) I've read, that there is Avaya VSA "Access-Priority" to mgmt access to 8300 and 8600 switches... But this attribute is invalid for NAC, I can't write it in Radius Attributes to Send, error message. I think, that NAC don't know about Avaya VSAs.&lt;BR /&gt;
&lt;BR /&gt;
If so, can I add this attribute to NAC RADIUS Server? Or there is no way to do this?&lt;BR /&gt;
&lt;BR /&gt;
Kind regards, Mikhail.</description>
      <pubDate>Fri, 25 Apr 2014 13:28:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/network-architecture-design/management-access-to-avaya-8300-8600-switch-via-nac-radius/m-p/13042#M446</guid>
      <dc:creator>Mikhail</dc:creator>
      <dc:date>2014-04-25T13:28:00Z</dc:date>
    </item>
    <item>
      <title>RE: Management Access to Avaya 8300/8600 Switch via NAC RADIUS Server.</title>
      <link>https://community.extremenetworks.com/t5/network-architecture-design/management-access-to-avaya-8300-8600-switch-via-nac-radius/m-p/13043#M447</link>
      <description>Thank you very much for your feedback, Mikhail.&lt;BR /&gt;
&lt;BR /&gt;
I understand and remember this from my past Nortel experience.&lt;BR /&gt;
&lt;BR /&gt;
In the past I just defined such vendor VSAs in cleartext as RADIUS Return Attribute&lt;BR /&gt;
in NAC Manager and it worked, maybe those VSAs have already been present in&lt;BR /&gt;
the "dictionaries" of the freeRadius version, which came with the NAC version that&lt;BR /&gt;
time, this was more Cisco related.&lt;BR /&gt;
&lt;BR /&gt;
If this didn't work, then "Dictionaries" is the term/topic you need to look at now.&lt;BR /&gt;
&lt;A href="http://freeradius.org/features/vendors.html" target="_blank" rel="nofollow noreferrer noopener"&gt;http://freeradius.org/features/vendors.html&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
With my next answer I will give you the working path with the dictionaries on our&lt;BR /&gt;
NAC appliances - you might find them on your own , and try to give you a example, &lt;BR /&gt;
how to modify a dictionary, add a new one or replace the current Avaya/Nortel disctionary or VSA strings in the Nortel or Avaya dictionary. &lt;BR /&gt;
After that a restart of the NAC services is needed (nacctl restart).&lt;BR /&gt;
&lt;BR /&gt;
The freeRadius guys always try to get the newest dictionaries from the vendors.&lt;BR /&gt;
You might also try to google for them or try to get them from the Avaya support as &lt;BR /&gt;
well.&lt;BR /&gt;
&lt;BR /&gt;
Just as hint... there are actually Bay, Nortel and Avaya dictionaries.&lt;BR /&gt;
&lt;BR /&gt;
It looks like you need to state "&lt;B&gt;Passport-Access-Priority=&lt;VALUE&gt;&lt;/VALUE&gt;&lt;/B&gt;", not just&lt;BR /&gt;
"&lt;B&gt;Access-Priority&lt;/B&gt;". Give it a try. Because I think the those dictionaries from Bay&lt;BR /&gt;
and Nortel are included and contain this Attributes already, they are quite old.&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://www.opensource.apple.com/source/freeradius/freeradius-36/freeradius/share/dictionary.bay" target="_blank" rel="nofollow noreferrer noopener"&gt;https://www.opensource.apple.com/source/freeradius/freeradius-36/freeradius/share/dictionary.bay&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
# Passport 8000 Series Specific Attributes# ATTRIBUTE &lt;B&gt;Passport-Access-Priority&lt;/B&gt;  192 integer  VALUE Passport-Access-Priority None-Access  0 VALUE Passport-Access-Priority Read-Only-Access 1 VALUE Passport-Access-Priority L1-Read-Write-Access 2 VALUE Passport-Access-Priority L2-Read-Write-Access 3 VALUE Passport-Access-Priority L3-Read-Write-Access 4 VALUE &lt;B&gt;Passport-Access-Priority&lt;/B&gt; Read-Write-Access 5 VALUE Passport-Access-Priority Read-Write-All-Access 6  &lt;A href="https://github.com/FreeRADIUS/freeradius-server/blob/master/share/dictionary.nortel" target="_blank" rel="nofollow noreferrer noopener"&gt;https://github.com/FreeRADIUS/freeradius-server/blob/master/share/dictionary.nortel&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="http://code.metager.de/source/xref/freeradius/server/share/dictionary.nortel" target="_blank" rel="nofollow noreferrer noopener"&gt;http://code.metager.de/source/xref/freeradius/server/share/dictionary.nortel&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://downloads.avaya.com/elmodocs2/p330/P330/Configuring%20FreeRadius.pdf" target="_blank" rel="nofollow noreferrer noopener"&gt;https://downloads.avaya.com/elmodocs2/p330/P330/Configuring%20FreeRadius.pdf&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
I will try and see, what I can find and get for you as well.&lt;BR /&gt;
&lt;BR /&gt;
Kind regards,&lt;BR /&gt;
&lt;BR /&gt;
Markus&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 25 Apr 2014 13:28:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/network-architecture-design/management-access-to-avaya-8300-8600-switch-via-nac-radius/m-p/13043#M447</guid>
      <dc:creator>Markus5</dc:creator>
      <dc:date>2014-04-25T13:28:00Z</dc:date>
    </item>
    <item>
      <title>RE: Management Access to Avaya 8300/8600 Switch via NAC RADIUS Server.</title>
      <link>https://community.extremenetworks.com/t5/network-architecture-design/management-access-to-avaya-8300-8600-switch-via-nac-radius/m-p/13044#M448</link>
      <description>For the 8600 it might be those...&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="https://github.com/FreeRADIUS/freeradius-server/blob/master/share/dictionary.nortel" target="_blank" rel="nofollow noreferrer noopener"&gt;https://github.com/FreeRADIUS/freeradius-server/blob/master/share/dictionary.nortel&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
VENDOR  Nortel    562&lt;B&gt;BEGIN-VENDOR Nortel&lt;/B&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;ATTRIBUTE Nortel-User-Role   110 string&lt;/B&gt;&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;ATTRIBUTE Nortel-Privilege-Level   166 integer&lt;/B&gt;&lt;BR /&gt;
&lt;BR /&gt;
ATTRIBUTE Passport-Command-Scope   200 integer&lt;BR /&gt;
ATTRIBUTE Passport-Command-Impact   201 integer&lt;BR /&gt;
ATTRIBUTE Passport-Customer-Identifier  202 integer&lt;BR /&gt;
ATTRIBUTE Passport-Allowed-Access   203 integer&lt;BR /&gt;
ATTRIBUTE Passport-AllowedOut-Access  204 integer&lt;BR /&gt;
ATTRIBUTE Passport-Login-Directory  205 string&lt;BR /&gt;
ATTRIBUTE Passport-Timeout-Protocol  206 integer&lt;BR /&gt;
ATTRIBUTE Passport-Role    207 string&lt;BR /&gt;
&lt;BR /&gt;
 Kind regards,  Markus</description>
      <pubDate>Fri, 25 Apr 2014 13:28:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/network-architecture-design/management-access-to-avaya-8300-8600-switch-via-nac-radius/m-p/13044#M448</guid>
      <dc:creator>Markus5</dc:creator>
      <dc:date>2014-04-25T13:28:00Z</dc:date>
    </item>
    <item>
      <title>RE: Management Access to Avaya 8300/8600 Switch via NAC RADIUS Server.</title>
      <link>https://community.extremenetworks.com/t5/network-architecture-design/management-access-to-avaya-8300-8600-switch-via-nac-radius/m-p/13045#M449</link>
      <description>Thanks a lot.&lt;BR /&gt;
But the problem is not solved yet.&lt;BR /&gt;
 &lt;BR /&gt;
&lt;A href="https://support.avaya.com/public/index?page=content&amp;amp;#38;id=SOLN182138&amp;amp;#38;group=UG_PUBLIC" target="_blank" rel="nofollow noreferrer noopener"&gt;https://support.avaya.com/public/index?page=content&amp;amp;id=SOLN182138&amp;amp;group=UG_PUBLIC&lt;/A&gt; document I read, that in the RADIUS dictionary I need to add the following radius VSAs: &lt;BR /&gt;
ATTRIBUTE Access-Priority-Attribute 192 integer Passport &lt;BR /&gt;
ATTRIBUTE Cli-Commands 193 string Passport &lt;BR /&gt;
ATTRIBUTE Command-Access 194 integer Passport &lt;BR /&gt;
ATTRIBUTE Commands 195 string Passport&lt;BR /&gt;
&lt;BR /&gt;
with your help, it became clear, that assess-priority (192) attribute in NAC's RADIUS is Passport-Aceess-Priority. However, I could not find the rest attributes... &lt;BR /&gt;
&lt;BR /&gt;
I Have to write them in the RADIUS dictionary myself? Or maybe they're there, but I can not find them? Help, please .&lt;BR /&gt;</description>
      <pubDate>Fri, 25 Apr 2014 13:28:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/network-architecture-design/management-access-to-avaya-8300-8600-switch-via-nac-radius/m-p/13045#M449</guid>
      <dc:creator>Mikhail</dc:creator>
      <dc:date>2014-04-25T13:28:00Z</dc:date>
    </item>
  </channel>
</rss>

