cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
983
Views
0
Helpful
4
Replies

ACS NAR Configuration problem

miklos.andrasi
Level 1
Level 1

Hi all!

I have a problem with configuration of Network Access Restriction.

I set the feature via Shared Profile Component and Group Level NAR also, but none of them works.

My test AAA client is a VASCO RADIUS Client Simulator. I thought that this software doesn't send the proper RADIUS attributes, but behaviour of ACS is never prohibitive, but sometime it should be.

I tried it with version 3.2 and 4.2 also.

Is there a trick or something I messed up?

Thank you for the answeres!

1 Accepted Solution

Accepted Solutions

For wireless user you need to use CLIS/DNIS based access restriction.

If you user Radius IETF for wireless AP, basic authentication should work but issue would be with authorization part.

Regards,

~JG

View solution in original post

4 Replies 4

Jagdeep Gambhir
Level 10
Level 10

NAR works on the basis of attributes sent by aaa client.

IP-based NAR filters work only if ACS receives the Radius Calling-Station-Id (31) attribute. The Calling-Station-Id (31) must contain a valid IP address. If it does not, it will fall over to DNIS rules.

See this link

http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1/user/SPC.html#wpxref8530

Regards,

~JG

Do rate helpful posts

Would it be problem, if I use RADIUS (IETF) "Authentication using" in the Network Configuration in ACS for Wireless AP? The productive envirement contains this configuration, and another device with TACACS+ configuration.

For wireless user you need to use CLIS/DNIS based access restriction.

If you user Radius IETF for wireless AP, basic authentication should work but issue would be with authorization part.

Regards,

~JG

Thank you for your answers. If I use CLIS/DNIS based access restriction, it works but in case of router works only with CLIS/DNIS based access restriction also. It's interest for me.

Regards,

Miki

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: