AP 1252 in autonomous mode not sending framed-ip-address

I was attempting to use the Websense RADIUS Agent to transparently map wireless users in it's database. This is done by passing the RADIUS accounting packets through the websense server where Websense can read them and map the username and password. This works for our Cisco VPN clients and Anyconnect clients. The problem I have is that the 1252 AP does not send the framed-ip-address in the RADIUS accounting packet. The AP should know the client IP since it can be seen with "show dot11 association".
For whatever reason, the AP doesn't know the IP address. This is verified by enabling aaa acounting delay-start which delays the sending accounting packets until the peer IP is known. With this command in, no accounting packets are ever sent from the AP.
Does anyone know why the AP doesn't include the framed-ip-address in the accounting packets? Or, why the AP is not able to learn the peer IP address from the client association information?
Thanks,
Mark

For a session to be disconnected, the values in one or more of the key fields in the POD request must match the values for a session on one of the network access server ports. Which values must match depends on the auth-type attribute defined in the command. If noauth-type is specified, all four values must match. If no match is found, all connections remain intact and an error response is returned. The key fields are as follows:
User-Name
Framed-IP-Address
Session-Id
Server-Key

Similar Messages

  • Have a new iPad with ios6.  Will not send emails. Addresses are valid  but get notice each time that recipient was rejected by the server.  No help on web site, and Apple's only manual is for previous os version.  We miss Steve Jobs.

    Have a new IPad with IOS6.  Will not send emails.  Addresses are valid but get notice each time that "recipient was rejected by the server."  Apple has apparently neglected to put out a manual with IOS6 and the previous manual has no indication of what to do.  Really miss Steve Jobs.

    Try going into Settings > Mail, Contacts, Calendars > select the account > account name , tap on SMTP (under the 'Outgoing Mail Server' heading) and then tap on your Primary Server and try entering your email account and password and see if it then works

  • Cfmail not sending to external address

    Hello,
    I have a new web server that I am testing before turning it on live. I have run into a cfmail issue. The server is
    Windows 2008 R2, 64Gig ram, 64-bit, IIS 7.5, Coldfusion 9.0.2 multi server, clustering 2 CF instances, JDK1.7.0_71
    We had a company setup CF and harden so this may be related to the hardening but I am not sure.
    <cfmail is not sending email to recipients outside of our domain/work domain. The 1st <cfmail> tag below sends the email but the 2nd one does not. This is what I see when trying to send via the 2nd <cfmail> tag with external recipient email address domain
    - no errors on the page I run in the browser
    - email is not received at [email protected] (syntax is correct)
    - attempt #2 shows up in mail/Undelivr folder
    - mail.log has this error
    "Error","scheduler-3","01/15/15","10:13:27",,"javax.mail.SendFailedException: Invalid Addresses;   nested exception is:  com.sun.mail.smtp.SMTPAddressFailedException: 550 5.7.1 Unable to relay
    - application.log - no error
    - exception.log has same error in addition to stack trace
    - server.log no error
    Any help is appreciated
    Joe
    <cfmail to="[email protected]" from="[email protected]" subject="test" type="html">
        #DateFormat(now(),"mm/dd/yyyy")# #TimeFormat(now(),"HH:mm:ss")#<br />
    </cfmail>
    <cfmail to="[email protected]" from="[email protected]" subject="test" type="html">
        #DateFormat(now(),"mm/dd/yyyy")# #TimeFormat(now(),"HH:mm:ss")#<br />
    </cfmail>

    CFMAIL is just a wrapper for the underlying Java mail API methods, so there should not be any problem with it.
    Seems like SMTP server is not registered to send mails out. So this is purly the problem with the SMTP server, not with the CFMAIL
    HTH
    Thanks
    VJ

  • Email will not send to email address with a full stop within the name as it drops the last name ie jim.smith@.... changes to jim@....

    I am trying to reply or send a email to a email address that has a full stop in the username ie [email protected] When the email sends it drops the surname ie [email protected] I have checked the address from the reply and it is correct even if I type it in it still has the same issue. Does anybody have an idea of what I can do. Thanks

    The Addons support forum is over here:
    https://forums.addons.mozilla.org/
    Separate forums with separate login credentials. Unfortunately each forum under mozilla.org was started at a separate time ''[years apart]'', by a different project group, and user credentials weren't centralized. About a year ago the plan was to have [https://login.persona.org/ Mozilla Persona] ''[a centralized login system]'' "consolidate" all the different Mozilla domain login credentials for users, but I haven't seen that even start to happen yet.

  • WRT54G Problem- SSID not showing in list & router not sending correct IP address

    Everthing was humming along.  Comcast Internet = fine.  WRT54G router, several XP Pro/SP 3 computers, 1 Powerbook + wireless printers. etc = fine.  PCs find network SSID and auto-connect without fail.
    Then, Comcast Internet down.  Reboot everything. Network back up.  Computers then get wrong IP Address or do not see SSID.  (No config changes on computers.)
    So I:
    1.  Reinstall WRT54G firmware (v8) - no change.
    2.  Install new fresh WRT54G - using CD to install  - no change
    3.  Update firmware in router used in #2 - no change
    4.  Complete reset cycle and reinstall -no change.
    5.  Repeat same reset with original router -no change
    6.  Using static IP address/default gate way/DNS address - PC finds and connects to SSID but does not access Internet.
    Result - no computers find SSID.  (SSID is hidden.) Don't find it when it's not hidden either.
    Ethernet cabled PC works just fine.  Gets correct IP Address & Internet  access is fine.
    Cable modem = Motorola Surf Board.  No physical locations of any omponent has changed.
    Is it possible that both WRT54G's are not working? 
    Is it somehow a Comcast problem? 
    Should I try some other router settings?
    Many thanks!

    Thanks.  These are great instructions and quite useful for setup.  Unfortunately, my problems seemed much more complex. 
    In the end, I redidi all the networking from scratch from the router through all the connected devices.  Finally got things back up.  I don't know how, but the Comcast failure seemed to corrupt lots of the settings even if they all looked OK.

  • Back up assistant will not send 2 email addresses to phone

    I have loaded all my contacts in to a csv file and imported it in to back-up assistant.  Everything looks good when I look at it online.  When I sync with my phone (HTC Rhyme) any contacts that have 2 e-mail addresses only show one addy!  The csv file format was exported from BU so I know it is valid.  There is an email 2 field which goes in to the Personal e-mail online but only the Business email shows up on the phone - wierd??  Anyone??

    I would suggest taking that CSV and importing it into the Gmail account you use with this phone. You can verify all the information was transferred when you view your contacts through the Gmail website. This will sync with the phone without changes. Then remove the contacts from BUA and clear the data for Backup Assistant on the phone to remove any duplicates on there. In the end, you should only have contacts saved under the Gmail account.

  • Framed-IP-Address Problem

    I am trying to setup Single Sign On between wireless and a network filter.  The filter requires the <Framed-IP-Address> to be in the NPS servers (Server 2012 R2) log files.  I have manually checked and the username, etc is there but not
    the framed-ip-address.  This server currently handles DHCP, we added the NPS server for lack of a better place, and then made it do AD CS after finding out we needed that for PEAP authentication.  What would be the likely cause of the logs not having
    the framed-ip-address field.  This field should be unique for each user and submit the ip address they received when connecting to the wireless.  This is what our filter company is telling us.  Thoughts?

    Hi,
    Framed-IP-Address indicates the address to be configured for the user. It is used to assign static IP address to user. If we want NPS to log the Framed-IP-Address, we need to configure static IP address for user.
    To configure static IP address for user, please follow the steps below,
    Open Active Directory Users and Computers.
    In the console tree, click Users.
    In the details pane, right-click a user name, and then click Properties.
    On the Dial-in tab, select the Assign a Static IP Address check box, and then type the static IP address for this user.
    For detailed information, please refer to the link below,
    Configure static IP address assignment
    http://technet.microsoft.com/en-us/library/cc786213(v=WS.10).aspx
    Best Regards.
    Steven Lee
    TechNet Community Support

  • Tbird will not send. unnown error. works in safe mode. turned off firewall and still does not work. works fine on desktop but not laptop

    cannot send on laptop. desktop, with same settings, works fine. getting unknown error on send. please help. here is the setup from the help function.
    thanks,
    tim
    WARNING:
    This contains sensitive information which shouldn't be forwarded or published without permission.
    Application Basics
    Name: Thunderbird
    Version: 31.4.0
    User Agent: Mozilla/5.0 (Windows NT 5.1; rv:31.0) Gecko/20100101 Thunderbird/31.4.0
    Profile Folder: C:\Documents and Settings\Tim\Application Data\Thunderbird\Profiles\dhtmqpol.default
    (Local drive)
    Application Build ID: 20150109111741
    Enabled Plugins: about:plugins
    Build Configuration: about:buildconfig
    Memory Use: about:memory
    Mail and News Accounts
    account1:
    INCOMING: account1, Tim Corey, (imap) imap.gmail.com:993, SSL, passwordCleartext
    OUTGOING: smtp.gmail.com:465, SSL, passwordCleartext, true
    account2:
    INCOMING: account2, Local Folders, (none) Local Folders, plain, passwordCleartext
    Crash Reports
    Extensions
    Important Modified Preferences
    Name: Value
    browser.cache.disk.capacity: 358400
    browser.cache.disk.smart_size_cached_value: 358400
    browser.cache.disk.smart_size.first_run: false
    browser.cache.disk.smart_size.use_old_max: false
    extensions.lastAppVersion: 31.4.0
    gfx.blacklist.direct2d: 3
    gfx.blacklist.layers.direct3d10: 3
    gfx.blacklist.layers.direct3d10-1: 3
    gfx.blacklist.layers.direct3d9: 3
    gfx.blacklist.layers.opengl: 3
    gfx.blacklist.stagefright: 3
    gfx.blacklist.suggested-driver-version: 6.1400.1000.5218
    gfx.blacklist.webgl.angle: 3
    gfx.blacklist.webgl.msaa: 3
    gfx.blacklist.webgl.opengl: 3
    mail.openMessageBehavior.version: 1
    mailnews.database.global.datastore.id: 7bba5461-432a-473f-a4e4-9a009dfee73
    mailnews.database.global.indexer.enabled: false
    network.cookie.cookieBehavior: 2
    network.cookie.prefsMigrated: true
    places.database.lastMaintenance: 1375374210
    places.history.expiration.transient_current_max_pages: 78086
    plugin.importedState: true
    privacy.donottrackheader.enabled: true
    Graphics
    Adapter Description: Mobile Intel(R) 945 Express Chipset Family
    Vendor ID: 0x8086
    Device ID: 0x27ae
    Adapter RAM: Unknown
    Adapter Drivers: igxprd32
    Driver Version: 6.14.10.4926
    Driver Date: 2-15-2008
    WebGL Renderer: Blocked for your graphics driver version. Try updating your graphics driver to version 6.1400.1000.5218 or newer.
    GPU Accelerated Windows: 0. Blocked for your graphics driver version. Try updating your graphics driver to version 6.1400.1000.5218 or newer.
    AzureCanvasBackend: skia
    AzureSkiaAccelerated: 0
    AzureFallbackCanvasBackend: cairo
    AzureContentBackend: cairo
    JavaScript
    Incremental GC: 1
    Accessibility
    Activated: 0
    Prevent Accessibility: 0
    Library Versions
    Expected minimum version
    Version in use
    NSPR
    4.10.6
    4.10.6
    NSS
    3.16.2.3 Basic ECC
    3.16.2.3 Basic ECC
    NSS Util
    3.16.2.3
    3.16.2.3
    NSS SSL
    3.16.2.3 Basic ECC
    3.16.2.3 Basic ECC
    NSS S/MIME
    3.16.2.3 Basic ECC
    3.16.2.3 Basic ECC

    Thanks for the reply. here is the behavior for all steps:
    1. use oper. system safe mode: it works, I can send email
    2. no oper. sys. safe mode, t'bird safe mode: cannot send mail
    3. no oper. sys safe mode, no t'bird safe mode, all addons disabled: cannot send mail.
    It only works when i use oper. sys. safe mode.
    Addons for t'bird were enabled in this test.
    (Not using T'bird safe mode either in this test.)
    Use BitDefender antivirus, which does not have a setting to turn on/off email scanning. Should I contact BD support? (it seems to point to BD as causing the problem. Interesting that I don't have this problem on 2 other desktops, only the laptop. And in the past, T'bird worked on the laptop. I have tried uninstall and reinstall, but mozilla is SAVING all my account and other info, so I cannot do a clean install. it seems to me that if I could do a clean install, it might work. Any idea how to remove all the data and uninstall?
    thanks,
    tim

  • Mail is not sending after standby mode!

    Hello.
    My problem is that mail after reactivation from the standby mode is not sending emails anymore,
    to send emails again i need to deactivate and activate again the internet connection ore restart the mac.
    I had the same problem already with my old mac with lion. Is there a fix for this problem?
    iMac Retina 5K with OSX Yosemite 10.10.2

    I had the same problem with a satellite A100. I did the following:
    1. Go to control panel
    2. In classic view select system
    3. go to tab Hardware
    4. Select device manager
    5. Open the "universal serial bus controllers" (via )
    6. Double click USB Root Hub
    7. select tab: "Power management"
    8. unselect allow the computer to turn off this device to save power
    9. My computer has several USB Root Hub. I repeated 6 till 8 for all
    10. I restarted the computer, but don't know if this is necessary.
    After this the problem was gone. Enjoy

  • Ipad not sending email, forced to reboot for changes to apply

    Hi all
    I was asked to look at a friends two week old iPad today.
    It was set up for them last week.
    Initially the person setting it up tried to add a Gmail account but found that it would receive but not send emails (using the native email app).
    They then decided to open an outlook.com account and use that instead of the gmail account.
    This worked fine for two days but then error messages saying that the mail could not be sent started to pop up. It struck me that the speed with which the error message appeared after clicking send suggested that this was an iOS issue rather than the server rejecting anything.
    I tried to check the imap/smtp settings in the "control panel" but they were not available (read:visible) so I deleted the account and entered the settings manually.
    It still wouldn't send emails but this time it didn't throw up any error messages, instead it decided to just dump them in the outbox without notifying me that there was an issue.
    Suspecting that the issue was with the ipad rather than the outlook servers, I decided to use my own smtp server details. Initially I tried using SSL but when this too failed I switched to the unsecure version on port 25.
    It still wouldn't send anything so I eventually rebooted by holding down the power button until the power off slider appeared. On rebooting I discovered that I could now send emails.
    TBH I have no idea if using the different SMTP server will be an issue if they ever want to check their outlook.com "sent mail" on line or not but i do have some questions
    1. Why was the reboot necessary? I had closed all open, unnecessary apps by double tapping the home button Might it have been the case that manually entering the outlook.com settings would have worked (given that the ideal set up would be to use the SSL outlook servers).
    2. Is this an unresolved iOS7 problem. Google searches resulted in many owners complaining that the iOS7 upgrade had rendered their email accounts incapable of sending emails. TBH the advice given ranged from perhaps sensible to plain daft.
    3. can anyone using outlook.com as their email provider on iOS7 confirm which smtp server, port, etc they use?
    4. Are there better email apps that actually give you detailed feedback?
    i don't know when I will next get the chance to get my hands on their ipad again but I would rather that they were using the correct outgoing servers with encryption (rather than my unencrypted smtp server).
    Thanks in advance

    neilyoung1 wrote:
    For the past few days I am now having trouble sending my client emails.  I get them bounced back with a permanent error of retry time exceeded.
    This is getting fustrating now as my client is needing answers that I cant give.  She is unable to email her colleague in the USA, and I am now unable to email her on a btinternet.com address.
    Do BT engineers monitor these forums?
    -Neil
    Hi again Neil.
    Your extra info now to me means that it appears to be problem at the client end!
    I hope you don't mind me asking a few questions ....
    Is she a regular BT Broadband user with a normal BTinternet email address ? Does she use secondary email addresses ?
    Do you know if she can happily email other people ? If not - it could be an account problem which may last a few days ....
    If you don't wish to provide the complete bounce message you received, could you perhaps email me the detail (emailing me using my shortcuts). Also pehaps you could ask your client to email me via my shortcuts, and see what happens and I'll take a look at replying to see what happens.
    The user on shentel.net domain she's been trying to email, did she ever manage to send any emails initially ? It could be the destination user having a problem.
    The mods do monitor these forums, but there are a lot of posts to go through of course ......
    http://www.andyweb.co.uk/shortcuts
    http://www.andyweb.co.uk/pictures

  • My gmail account receives mail, but will not send, forward, or reply...it gets stuck in the spin and then I have to force quick firefox.

    My gmail accounts receives mail, but will not send, reply or forward. Also cannot open settings. It gets stuck in spin mode.
    I worked with an apple tech, tried several things, and then she suggested I contact Mozilla support.

    Hey Butterworth,
    You may need to use the information in this article to help you troubleshoot the issue with your outgoing server:
    OS X Mail: Troubleshooting sending and receiving email messages
    http://support.apple.com/kb/ts3276
    Thanks for coming to the Apple Support Communities!
    Cheers,
    Braden

  • I can use Mail at home, no problem. But when I travel, I can receive mail but not send it. I get a "server can't be reached" message. Yet when I send a photo using iPhoto, it gets sent. Help!!

    I can use Mail at home, no problem. But when I travel, I can receive mail but not send it. I get a "server can't be reached" message. Yet when I send a photo using iPhoto, it gets sent. Help!!

    To diagnose problems with Thunderbird, try the following:
    *Restart the operating system in '''[http://en.wikipedia.org/wiki/Safe_mode safe mode with Networking]'''. This loads only the very basics needed to start your computer while enabling an Internet connection. Click on your operating system for instructions on how to start in safe mode: [http://windows.microsoft.com/en-us/windows-8/windows-startup-settings-including-safe-mode Windows 8], [http://windows.microsoft.com/en-us/windows/start-computer-safe-mode#start-computer-safe-mode=windows-7 Windows 7], [http://windows.microsoft.com/en-us/windows/start-computer-safe-mode#start-computer-safe-mode=windows-vista Windows Vista], [http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/boot_failsafe.mspx?mfr=true" Windows XP], [http://support.apple.com/kb/ht1564 OSX]
    ; If safe mode for the operating system fixes the issue, there's other software in your computer that's causing problems. Possibilities include but not limited to: AV scanning, virus/malware, background downloads such as program updates.

  • Thunderbird will not send or receive email in Windows 8.1 unless I re-install. The next time I open Thunderbird it is again broken.

    Thunderbird will not send or receive email in Windows 8.1 unless I re-install it. The next time I open Thunderbird it is again broken. So, I have to repeat the un-install / re-install process. Currently I am using Version 31.0, but this was happening the the previous version as well.
    Here are some of the messages in the error console:
    Could not read chrome manifest 'file:///C:/Program%20Files%20(x86)/Mozilla%20Thunderbird/chrome.manifest'.
    Could not read chrome manifest 'file:///C:/Program%20Files%20(x86)/Mozilla%20Thunderbird/extensions/%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D/chrome.manifest'.
    Timestamp: 8/3/2014 8:02:29 AM
    Warning: mutating the [[Prototype]] of an object will cause your code to run very slowly; instead create the object with the correct initial [[Prototype]] value using Object.create
    Source File: resource://gre/components/steelApplication.js
    Line: 783
    Timestamp: 8/3/2014 8:02:57 AM
    Warning: Use of getPreventDefault() is deprecated. Use defaultPrevented instead.
    Source File: https://www.mozilla.org/thunderbird/js/jquery/jquery-1.5.1.min.js
    Line: 16
    Thanks for the help.
    Joe

    That really sounds like anti virus scanning to me. Try rebooting your machine into safe mode with networking and see if it works correctly then.

  • Steps to convert access point from LightWeight mode to Autonomous mode

    I need steps to convert the following access point from Lightweight mode to Autonomous mode
    AIR-AP1242AG-E-K9
    Regards,
    Majid

    Hi Majid,
    The method is just hidden a little further down the doc that Scott linked (+5 points Scott :)
    Using a TFTP Server to Return to a Previous Release
    Note This section does not apply to Cisco C3201WMIC and Cisco C3201LAP.
    Follow these steps to revert from LWAPP mode to autonomous mode by loading a Cisco IOS release using a TFTP server:
    Step 1 The static IP address of the PC on which your TFTP server software runs should be between 10.0.0.2 and 10.0.0.30.
    Step 2 Make sure that the PC contains the access point image file (such as c1200-k9w7-tar.122-15.JA.tar for a 1200 series access point) in the TFTP server folder and that the TFTP server is activated.
    Step 3 On the PC where the TFTP server is located, perform these steps:
    a. Disable any software firewall products, such as Windows firewall, ZoneAlarm firewall, McAffee firewall, or others.
    b. Ensure all Windows files are visible. From Windows Explorer, click Tools > Folder Options > View > Show hidden files and folders.
    Step 4 Rename the access point image file in the TFTP server folder to c1200-k9w7-tar.default for a 1200 series access point, c1130-k9w7-tar.default for an 1130 series access point, c1240-k9w7-tar.default for a 1240 series access point, and c1250-k9w7-tar.default for a 1250 series access point.
    Step 5 Connect the PC to the access point using a Category 5 (CAT5) Ethernet cable.
    Step 6 Disconnect power from the access point.
    Step 7 Press and hold MODE while you reconnect power to the access point.
    Step 8 Hold the MODE button until the status LED turns red (approximately 20 to 30 seconds) and then release.
    Step 9 Wait until the access point reboots, as indicated by all LEDs turning green followed by the Status LED blinking green.
    Step 10 After the access point reboots, reconfigure it using the GUI or the CLI.
    http://www.cisco.com/en/US/docs/wireless/access_point/conversion/lwapp/upgrade/guide/lwapnote.html#wp160918
    Hope this helps!
    Rob

  • Vpn-framed-ip-address not working with anyconnect

    Hi Folks, please help me to verify if this case is a bug or a "not valid scenario".
    Scenario:
    ASA 5520, OS 9.1, SSL VPN with Anyconnect v3.x, static ip address for the client, and RSA token authentication (all the users/pin/passwords are in the RSA server, not in the ASA, but i need to create some users in the ASA in order to apply the vpn-framed-ip-address attribute for specific users).
    In fact the anyconnect ssl vpn with RSA auth works fine, the ssl connection works, the user is authenticated, the anyconnect works, traffic passing,  BUT.. the anyconnect its getting an ip address from the ip local pool INSTEAD of the static ip defined with the  vpn-framed-ip-address command.
    I'm trying to assign a static ip address for a user (defined locally on the ASA) that performs auth via RSA (aaa-server), by using the  vpn-framed-ip-address  command as an attribute for this local user. But it seems the command is not working.
    Already I´ve tried to resolve (with no success) by entering the
    no vpn-addr-assign aaa
    no vpn-addr-assign dhcp
    vpn-addr-assign local
    Also i´ve tried by removing the pool from tunnel-group in order to force all the connection session to use the static ip address, but in this case, the anyconnect sends a message "No Address Available for SVC Connection".  Meaning the ASA simply is ignoring the  vpn-framed-ip-address command.
    Its supposed the ASA implement the policies in this order, DAP > User policy > UserGrp policy > ConnProfile > DefGrpPolicy, and according to this, the vpn-framed-ip-address command should take effect first since its specified as User policy, overriding everything else. But its not working.
    At this point i think the issue is... since the user is locally defined but its password its being authenticated via RSA (not local), the user attributes (static ip) are being ignored by the ASA because its not expecting to receive an ip address from the aaa server (RSA), so jumps to the next policies falling to the pool. Anyway the user policies attributes SHOULD work according to cisco.
    Please your advise, or tell if its a bug? or a not valid scenario for this command to work with the ASA.
    This is the current config:
    ip local pool PoolSSL 192.168.229.10-192.168.229.19 mask 255.255.255.0
    aaa-server RSA protocol sdi
    aaa-server RSA (inside) host 192.168.12.1
     retry-interval 5
    no vpn-addr-assign aaa
    no vpn-addr-assign dhcp
    group-policy GroupPolicyABC internal
    group-policy GroupPolicyABC attributes
     wins-server none
     dns-server value 192.168.61.1 192.168.61.2
     vpn-tunnel-protocol ssl-client
     group-lock value TunnelGroupABC
     split-tunnel-policy tunnelspecified
     split-tunnel-network-list value ServersDB
     default-domain value my.domain.com
     split-tunnel-all-dns disable
     webvpn
      anyconnect ask none default anyconnect
    username USER1 password xHhacRZ56Uadqoq encrypted
    username USER1 attributes
     vpn-framed-ip-address 192.168.229.7 255.255.255.0
     group-lock value TunnelGroupABC
    tunnel-group TunnelGroupABC type remote-access
    tunnel-group TunnelGroupABC general-attributes
     address-pool PoolSSL
     authentication-server-group RSA
     default-group-policy GroupPolicyABC
    tunnel-group TunnelGroupABC webvpn-attributes
     group-alias AccessToDB enable
    I´ll wait for your answers, regards!

    https://tools.cisco.com/bugsearch/bug/CSCtf71671/
    you need AAA assignment, or at least you needed to have it a couple of years back. 

Maybe you are looking for