Re: ACS 5.1 and Radius att for VPN IP pool

From: Ivan Hrvatska <ivanzghr_at_gmail.com>
Date: Wed, 27 Apr 2011 15:57:12 +0200

??? Can you write what do you mean by that.
This is what I found on net:

Class (RADIUS attribute 25)
Sent unchanged to accounting server in Accounting Start message.

Doesn't help me at all.
I also found this about ACS 5.1:

The following features are not supported in ACS 5.1:
 Integration with SQL DB via ODBC, for external authentication and
identity information.
 TACACS+ Proxy.
 Application access control for CiscoWorks applications.
 Network access restriction to users whose Windows accounts have
Windows dial-in permission.
 IP Pools Server feature.
 Support for defining the maximum number of simultaneous sessions for
a user or user group.
 LM hash is not supported for CHAP/MS-CHAP authentications.
 Expiry of any user (admin or internal) after certain number of days
is not supported.

On Thu, Apr 21, 2011 at 6:20 PM, Marcin Zgola <MZgola_at_netrixllc.com> wrote:
> Attribute 25..
>
>
>
> Marcin Zgola | Netrix, LLC | 847.283.7400 |(Direct) 847.283.7328| (fax) 847.283.7610 | http://www.netrixllc.com/
> Internetwork Lead | CCIE# 18676 (Security)
>
>
> -----Original Message-----
> From: nobody_at_groupstudy.com [mailto:nobody_at_groupstudy.com] On Behalf Of Ivan Hrvatska
> Sent: Thursday, April 21, 2011 4:17 AM
> To: Cisco certification
> Subject: ACS 5.1 and Radius att for VPN IP pool
>
> Hi,
>
> I have some issue with configuring ACS 5.1. What I want to do is next:
> I have Remote Access VPN users (IPsec) who are terminated on Cisco ASA 5510. AAA for those users is done on ACS. Group-policies and tunnel groups are defined on ASA. Initialy I had all VPN users defined on ASA and group policies were associated with each user. Each group policy had it's own IP pool for users. Now, I moved users to ACS. HOw can I associate group policy, defined on ASA, with users group defined on ACS? Is it possible that ACS send to ASA information about IP pool for different group policy? I know that I have to use some Radius att, but which one and how?
> Thanks.
>
> Regards,
> Ivan
>
>
> Blogs and organic groups at http://www.ccie.net
>
> _______________________________________________________________________
> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html

Blogs and organic groups at http://www.ccie.net
Received on Wed Apr 27 2011 - 15:57:12 ART

This archive was generated by hypermail 2.2.0 : Sun May 01 2011 - 09:00:29 ART