cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
475
Views
0
Helpful
8
Replies

Authorisation between Concentrator and ACS 4.1 not working.

admin_2
Level 3
Level 3

I have a vpn 3005 concentrator in a dmz, directing authentication and authorisation back to a ACS Radius server. Authentication works fine, however as soon as I attempt to have the ACS server authorise as well, I received a Radius Access-reject(3) packet from the ACS Server.

8 Replies 8

rochopra
Cisco Employee
Cisco Employee

Do you have 2 seperate radius servers ?

why are you implementing authorization for vpn?

~Rohit

Not applicable

Just 1 RADIUS server.

I though you need authorisation to push out various settnigs like NAC, IPAddressing, DNS Server addresses etc.

Whenever I just have authentication, I can vpn in fine, however no settings come across from the ACS server?

rochopra
Cisco Employee
Cisco Employee

Well in that case you do not have to specify Authorization.

Passing attributes can be taken care of by ACS with authentication.

configuration in link can give you some idea:

http://cisco.com/en/US/tech/tk59/technologies_configuration_example09186a00800946a2.shtml

~Rohit

Not applicable

Thanks for that.. I have setup just authentication and have successfully pushed out various settings, and downloadable ACLs. All worked fine.

Thanks again.

I had trouble with replying to your post, which is why you see 3 blank posts below :)

rochopra
Cisco Employee
Cisco Employee

do rate helpful posts so that others can benefit from it

Not applicable

Not applicable

Not applicable

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: