Configuration of cisco concerning POD and policy maps
aaa new-model aaa session-mib disconnect aaa session-id unique aaa server radius dynamic-author client X.X.X.X server-key xxxxx auth-type any policy-map type control RULE_IP_SESSION2a class type control always event session-start 30 authorize aaa list AUTHOR_LIST1 password password identifier circuit-id plus mac-address ! class type control always event session-restart 30 authorize aaa list AUTHOR_LIST1 password password identifier circuit-id plus mac-address ! class type control always event account-logon 10 authenticate aaa list AUTHEN_LIST1
As a result, all sessions running on this very vlan are being reset. And won't get reestablished untill router is being rebooted. After session reset router begins to ignire all packets incoming from this vlan. So, if end-user sets up IP-address manually, even ICMP-packets won't pass through from him to router. But if he tries to do it via DHCP, router logs are still empty. The same is if we try to reset the session via SNMP. debug for aaa pod
00:22:32: ++++++ POD Attribute List ++++++ 00:22:32: 6390C2F8 0 00000001 addr(8) 4 172.30.30.2 00:22:32: 6390C6A0 0 00000001 session-id(363) 4 19(13) 00:22:32: 00:22:32: POD: Converted to internal Session-Id of 00000013 00:22:32: POD: X.X.X.X user 172.30.30.2 sessid 0x13 key 0x0 00:22:32: POD: Line User IDB Session Id Key 00:22:32: POD: KILL FastEthe 0004012d x.x.x.x 0x13 0xE4666E78 00:22:32: POD: Sending ACK from port 1812 to x.x.x.x/43090
5 such packets pass through, after them - some watchdogs (update as configured - 1 min) After that stop-packet follows.
Hi everyone, I would like to thank you in advance for any help you can provide a newcomer like myself!
Im studying the 100-105 book by Odom and am currently on the topic of Port security. I purchased a used 2960 and I'm trying to follow a...
While deploying a number of 18xx/2802/3802 model access points (APs), which run AP-COS as their operating platform. It can be observed on some occasions that while many of their access points were able to join the fabric WLC withou...