cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1925
Views
0
Helpful
3
Replies

Secure-ACS: Special RADIUS-Attributes for Enterasys E7

rolf.fischer_2
Level 1
Level 1

Hi,

we were running a pretty old version of the  Cisco Secure ACS for AAA our network devices.

Unfortunately the  server crashed an we had to install and set it up with a new server.

Using  TACACS+ for our Cisco devices works fine.

We have a couple of  switches made by a vendor called Nexans, which only support RADIUS -  this works fine too.

Furthermore we still have some Enterasys E7  and with those RADIUS doesn't work at all.

Sniffering the packets,  everything looks good.

With the old server it worked well.

Does  anybody know if there are special configurations (e.g. attributes) when  configuring an ACS for Enterasys RADIUS-Clients?

Thanks,

Rolf

1 Accepted Solution

Accepted Solutions

Yudong Wu
Level 7
Level 7


try this

attribute  [011]  Filter-ID to "Enterasys:version=1:mgmt=su:"

View solution in original post

3 Replies 3

Yudong Wu
Level 7
Level 7


try this

attribute  [011]  Filter-ID to "Enterasys:version=1:mgmt=su:"

Great, it works!

You saved my day ;-)

We have this configuration and works fine with our network and associate in a good manner also the policy which we have configured it on Enterasys in this way

Filter-Id===>

Enterasys:version=1:mgmt=su:policy=Administrator

.

.

.

.

After we make the update to ACS 5, the "ASA" consider this filter-id as access-list so it consider the field after the filter-id as the name of the acl, and diconnect the VPN connection.

Could soneone help me to resolve that.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: