Integrating AAA Radius-server with Micro-soft IAS for SSH

Hi,
I am configuring aaa-server on ASA-5505(Radius) and i am Using microsoft IAS for authentication for SSH connections on ASA, so during " test aaa-server authentication " i getting this message
ERROR: Authentication Server not responding: AAA decode failure.. server secret mismatch
All users are there on active  directory  And below are the debug radius and debug aaa authentication.
ASA# test aaa-server authentication SSH-TULIP-ASA host 172.16.1.10 usern$
INFO: Attempting Authentication test to IP address <172.16.1.10> (timeout: 12 seconds)
radius mkreq: 0xd4
alloc_rip 0xd83bb99c
    new request 0xd4 --> 124 (0xd83bb99c)
got user 'praveeny'
got password
add_req 0xd83bb99c session 0xd4 id 124
RADIUS_REQUEST
radius.c: rad_mkpkt
RADIUS packet decode (authentication request)
Raw packet data (length = 66).....
01 7c 00 42 37 a4 0d c2 d3 10 09 0e 2f 3c c5 1a    |  .|.B7......./<..
4b 28 41 e6 01 0a 70 72 61 76 65 65 6e 79 02 12    |  K(A...praveeny..
a1 8f e1 ae 58 dd c2 52 d6 37 f7 32 13 3a 1c 71    |  ....X..R.7.2.:.q
04 06 ac 1e 1e 06 05 06 00 00 00 0e 3d 06 00 00    |  ............=...
00 05                                              |  ..
Parsed packet data.....
Radius: Code = 1 (0x01)
Radius: Identifier = 124 (0x7C)
Radius: Length = 66 (0x0042)
Radius: Vector: 37A40DC2D310090E2F3CC51A4B2841E6
Radius: Type = 1 (0x01) User-Name
Radius: Length = 10 (0x0A)
Radius: Value (String) =
70 72 61 76 65 65 6e 79                            |  praveeny
Radius: Type = 2 (0x02) User-Password
Radius: Length = 18 (0x12)
Radius: Value (String) =
a1 8f ERROR: Authentication Server not responding: AAA decode failure.. server secret mismatch
Tulip-ASA# e1 ae 58 dd c2 52 d6 37 f7 32 13 3a 1c 71    |  ....X..R.7.2.:.q
Radius: Type = 4 (0x04) NAS-IP-Address
Radius: Length = 6 (0x06)
Radius: Value (IP Address) = 172.30.30.6 (0xAC1E1E06)
Radius: Type = 5 (0x05) NAS-Port
Radius: Length = 6 (0x06)
Radius: Value (Hex) = 0xE
Radius: Type = 61 (0x3D) NAS-Port-Type
Radius: Length = 6 (0x06)
Radius: Value (Hex) = 0x5
send pkt 172.16.1.10/1645
rip 0xd83bb99c state 7 id 124
rad_vrfy() : bad req auth
rad_procpkt: radvrfy fail
RADIUS_DELETE
remove_req 0xd83bb99c session 0xd4 id 124
free_rip 0xd83bb99c
radius: send queue empty
Thanks in advance all comments and suggestion are welcome
Regards,
Praveen

Hi,
RADIUS as a protocol does not support command accounting, ie., logging of commands that a users enters once authenticated to a router/switch. You will need to use TACACS+ for this purpose. The aaa command accounting commands that you used has been removed from IOS since 12.2T. Please take a look at this for details: http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCdp57020.
Thanks,
Wen

Similar Messages

  • Lion compatibility with Micro Soft Office for MAC ?

    I loaded Lion but now can't access word, excel etc. Can anyone provide advice I have ten years worth of data I need to look at on a regular basis on office for mac programs.
    Thanks

    Office 2008 and 2011 run fine on Lion - but any earlier versions won't.
    Apple's iWork will open most MSOffice files and will export to MSOffice (but not always reliably).
    With Office 2008, the catch is that even though it will run in Lion, you can't install it in Lion because the installer itself won't run in Lion.
    So if you want to get hold of Office 2008, you should do so and install it BEFORE you install Lion. And keep a clone of Snow Leopard somewhere, for that day when you may need to install Office 2008 again....

  • Configuring Radius server with Cisco MDS - 9606 switch

    Need help in configuring Radius server with cisco MDS - 9606
    please let me know if any document available

    rtt min/avg/max/mdev = 0.260/0.327/0.468/0.077 ms
    IFCBCCEMCSW2# sh version
    Cisco Storage Area Networking Operating System (SAN-OS) Software
    TAC support: http://www.cisco.com/tac
    Copyright (c) 2002-2008, Cisco Systems, Inc. All rights reserved.
    The copyrights to certain works contained herein are owned by
    other third parties and are used and distributed under license.
    Some parts of this software may be covered under the GNU Public
    License or the GNU Lesser General Public License. A copy of
    each such license is available at
    http://www.gnu.org/licenses/gpl.html and
    http://www.gnu.org/licenses/lgpl.html
    Software
    BIOS: version 1.1.0
    loader: version 1.2(2)
    kickstart: version 3.3(1c)
    system: version 3.3(1c)
    BIOS compile time: 10/24/03
    kickstart image file is: bootflash:/m9500-sf1ek9-kickstart-mz.3.3.1c.bin
    kickstart compile time: 5/23/2008 19:00:00 [06/19/2008 23:56:56]
    system image file is: bootflash:/m9500-sf1ek9-mz.3.3.1c.bin
    system compile time: 5/23/2008 19:00:00 [06/20/2008 00:26:51]
    Hardware
    cisco MDS 9506 ("Supervisor/Fabric-1")
    Intel(R) Pentium(R) III CPU with 1028596 kB of memory.
    Processor Board ID JAB094300ER
    bootflash: 250368 kB
    slot0: 0 kB

  • How do i download micro soft office for Mac

    How do i download micro soft office for Mac

    http://www.microsoft.com/en-us/default.aspx     (for US)
    and select Downloads.  You can pay and download from there.

  • Server 2008 R2 RADIUS Server with a Cisco Aironet 1040 Wireless AP

    I am trying to get Server 2008 R2 RADIUS Server to work with a Cisco Aironet 1040 Wireless AP. I have installed the RADIUS server by MS standards and performed some searches on Google to configure the Cisco Aironet. I see others using a Wireless LAN Controller, which I do not have. I found this post below:
    https://supportforums.cisco.com/discussion/11546056/wlc-2504-radius-2008-r2-server
    But I have yet to locate a good step by step document on how to set it up and I have found so many different ways that others have set it up, but none have yet to work. I am having authentication issues that I have know of and I do not see any errors in the Windows Event Viewer and I do not know where the Acess Point stores it logs for any sort of error. Keep in mind this is the first time I am doing this. I do not have a Wireless LAN Controller and all my network / domain services are on individually built servers and not on one single server as I have seen with most of the documentation they all say the same thing by putting the Certificate Services, Domain Services (AD / ADS, etc), and NPS. I do not want that configuration and my setup should not be any different, but something is not right. I know from reading that this is not rocket science, but from someone who has never done it before this is difficult as I keep reading on and so many people do it different ways including what I have been reading according to what Cisco says to configure in the environment. Does anyone know where I can find good step by step documentation along with where I can look for logs on either device? I find that all the documentation I see on Cisco's website and from searching that it is old and outdated and not been updated in a long time so it is hard to determine what works and what does not work. I am stumped here and have been doing this for several weeks now with no luck. Thank you in advance.

    I did configure the Server 2008 R2 RADIUS Server using this video below: 
    https://www.youtube.com/watch?v=g-0MM_tK-Tk
    I also referenced Technet to make sure it was configured correctly as well. I am still not sure if I am 100% setup correctly on the Windows Server side, but I for sure want to make sure I have the AP side setup correctly. Do you know of a better article for the Windows Server 2008 R2 setup? Does it matter that I do not have all the services installed on the same server? Instead I have them installed on multiple servers.
    I have image number c1140-k9w7-tar.124.25d.JA1 on the AP. The part that confused me in that article, which I have seen before was the part about "Setting up access point must be configured in the authentication server as an AAA client." What is the AAA Client? I also am not aware of having Cisco Secure ACS anywhere built into the AP as that part through me off completely. Do I need to skip these steps? Thank you for help on this.

  • Aaa radius server control privilege level

    I've got radius authentication working on my switch, but I'm trying to allow two types of users login using Windows Active Directory. NetworkUsers who can view configuration and NetworkAdmins who can do anything. I would like for NetworkAdmins to when they login go directly into privilege level 15 but cant get that part to work. Here is my setup:
    Windows 2008 R2 Domain controller with NPS installed.
    Radius client: I have the IP of the switch along with the key. I have cisco selected under the vendor name in the advance tab
    Network Policies:
    NetworkAdmins which has the networkadmin group under conditions and under settings i have nothing listed under Standard and for Vendor Specific i have :
    Cisco-AV-Pair    Cisco    shell:priv-lvl=15
    My switch config:
    aaa new-model
    aaa group server radius MTFAAA
     server name dc-01
     server name dc-02
    aaa authentication login NetworkAdmins group MTFAAA local
    aaa authorization exec NetworkAdmins group MTFAAA local
    radius server dc-01
     address ipv4 10.0.1.10 auth-port 1645 acct-port 1646
     key 7 ******
    radius server dc-02
     address ipv4 10.0.1.11 auth-port 1645 acct-port 1646
     key 7 ******
    No matter what i do it doesnt default to privilege level 15 when i login. Any thoughts

    Have you specified the authorization exec group under line vty? I think it is authorization exec command. Something like that.

  • Integrating portal/identity server with netegrity siteminder?

    Has anyone integrated identity server/portal server with Netegrity Siteminder for single sign on?
    Both products seem to support SAML and the Liberty Alliance project. Can a new auth module in the identity server just exchange the appropriate messages to create a single sign on token in netegrity and then validate the token on each request?

    We are running Identity Server 6.1 on Solaris.
    The logs are in /var/opt/SUNWam/debug/
    The most useful one is amAuth. You might also want to look at amAuthInternal, amSession, amAuthLDAP, and amAuthContext.
    If you are seeing these, checkout AMConfig.properties (in /opt/SUNWam/lib). It should have the log level set to warning or message for you to get all these logs. Here's the setting from my AMConfig.properties:
    com.iplanet.services.debug.level=warningPS Sorry for the unix paths, but hopefully they map closely to the windows directories.

  • Radius Server with Active Directory

    I have an XSERVE with 10.6.7. It is an OD Master that is also bound to Active Directory.
    I am trying to set up the RADIUS service to provide authentication to users on the wireless network.
    So far, I have been able to set it up to the point where the wireless access point is attempting to authenticate to the server. The client is asked for user ID and password. I will even see the self-signed certificate on the client. However, I am never able to connect to the wireless system.
    I tried using an Air Port Express with all the automatic settings from the server, and got the same results.
    I tried authenticating with a local OD test user, and that did not work, either.
    When I tried it on my network at home (no Active Directory), the RADIUS server worked exactly as expected.
    Is there some other setting that must be modified to make this work with AD?

    Here are some links:
    http://www.cisco.com/en/US/products/ps6366/products_configuration_example09186a00807917aa.shtml
    http://www.cisco.com/en/US/products/ps6366/products_configuration_example09186a0080921f67.shtml
    http://www.cisco.com/en/US/tech/tk722/tk809/technologies_configuration_example09186a0080665d18.shtml

  • Using MS Radius Server with WLC

    I'm currenlty running WLC version 4.1.171. For authentication I'm using Microsoft IAS. I was able to get this to work by using Web Authentication but I want to use 802.1x w/ PEAP. I've been researching this and most of the documents talk about ACS. I did find one document on how to make this work, however I still have not been able to get authenicated. I'm hoping someone has some documentation on how to configure IAS on MS WIN Ser 2003. Thanks in advance.
    Here is the document I've been using: http://wireless.dweezle.org/Docs/PEAP/Step-by-Step%20Guide%20for%20Setting%20Up%20Secure%20Wireless%20Access.ppt

    Hi,
    can You send me some information about configuring WEB-AUTH with IAS ?
    I cannot figure how to comfigure user / ias in my server .
    I've done EAPTLS with the same IAS, but now i was trying to do simple user/pass authentication, if it's possible.
    Many thanks
    Luigi

  • Windows 2k8 Radius Server with Cisco Wireless Controllers

    We currently are using a Cisco 4400 wireless controller with an older Cisco Secure ACS appliance that is going EOL.  My hope was to just connect our 4400 Wireless Controller to a Windows Server 2008 Radius Server (Just using Microsoft's Network Policy Server) but have not had any luck in getting this to work.  Does anyone have an easy to follow set of instructions on configuration of Microsoft Windows Server 2008 NPS for use with Cisco Wireless Controllers?  Any advise would be greatly appreciated.
    Thank You,
    Jim

    Hi NPT,
    Here is the post which may help you!!
    https://supportforums.cisco.com/message/3073519
    Regards
    Surendra

  • Any Way to test Integration of File Server with Portal??

    Hi all,
    I want to integrate File Server with my Portal so that my Application and Data remains seperated.
    I have integrated File Server but i am not able to find the Folder of file server in KM.
    i have create KM Navigation Iview When i specify any folder that is available in KM it works fine but i can not see the folder of file server...
    <b>Is there any test with which i can check that weather my File Server is Integrated properly with my Portal or not?? </b>
    Any help will be highly Appretiated ...
    its very Urgent!!
    Thanks in Advance
    Vinit

    Hi,
    I think already file system repository created in the portal. plz check it
    Goto >System Admin>System Config>KM>Content management>Repositories manager>File system Repository. or create a new repository..
    You can use File System Repository so that you can integrate ur file server with portal. Refer this link
    http://help.sap.com/saphelp_nw04/helpdata/en/e3/92322ab24e11d5993800508b6b8b11/frameset.htm
    Regards,
    Senthil K.

  • Integrating existing file server with EP6SP9

    hello everyone
    we are implementing EP6 SP9 portal for our SBU and we need to integrate our existing file server with portal in which we can upload documents and download existing documents.
    do we need to use content management to access this file server using the file system repository manager or it can be done in some other way
    If theres an alternate way to do this, kindly explain what needs to be done.
    Kindly help
    Thanking you
    Anurag

    Anurag,
    yes, CM is the software to use for this. you could, in principle, go without CM and code the neccessary stuff on your own. But: The more funcionality you desire (think of: additional properties, search functionality, versioning ...), the more sense using CM makes. Plus you get all required user interfaces (like a repository browser) for free.
    Regards,
    Dominik

  • Integrating WebSphere Portal Server with Sun Java System Access Manager

    Hi All,
    Is it possible to Integrate WebSphere Portal Server with Sun java System Access Manager?. If so plz send me any doc or web site link for the same.
    Thanks in Advance
    Rgds,
    Lessly J

    Rushi-Reliance wrote:
    Kindly let us know how to proceed further as we are waiiting some reply from your team.As I already advised in your previous posting (http://forums.sun.com/thread.jspa?threadID=5359095), you are best off re-installing solaris from scratch and installing Communication Suite 6 update 1 if you cannot get Access Manager 7.1 configured.
    Regards
    Shane.

  • Integrating Apache Http Server with Streaming Server

    Hi,
    How to integrate my Apache Http Server with a Darwin Streaming Server or any server?
    Any links are really appreciated.
    Thanks.

    Your question has nothing whatsoever to do with JSP, JSTL, or java. Locking.

  • How do I manage Integrated Web Logic server with JDev?

    I need to change admin password on WebLogic Server (for the weblogic admin) and do it from JDev so that start/stop of weblogic server is possible. How do I do it? Continuing, how do I manage WLS from JDev?
    Note that I am able to view the application server using view->Application Server Navigator and expand the integrated application server. At this stage, I want I can right click on the application server and launch the admin console. In the authentication tab, the passwords are "grayed" out. I want to reset the password for this weblogic server. The question is how do I do that?
    Edited by: 975250 on Dec 5, 2012 2:50 PM

    Hi,
    There is no way to change password from the JDev configuration.
    It should be done directly from WLS.
    You can change the password @ WLS side and include the WLS into Jdev.
    Here is the following way to change current password.
    1.- Take the back of the LDAP folder of the admin server as well as managed server (you may rename those folders) and then delete the actual LDAP folder (found at servers\<MyServer>\data\ldap).
    2. Make sure WebLogic instance is down.
    3. Set your environment variables using setDomainEnv.sh.
    4. cd to security directory in your instance.
    (eg: $WL_HOME/user_projects/domains/base_domain/security)
    5. Run:
    java weblogic.security.utils.AdminAccount admin_user admin_pass .
    Remember to change “admin_user” and “admin_pass” to your need.
    Also, don’t forget the period “.” at the end of the above command, it is required.
    6. After running the command, the file “DefaultAuthenticatorInit.ldift” will get updated.
    7. Delete the following file from “ldap” folder:
    cd WL_HOME/user_projects/domains/base_domain/servers/AdminServer/data/ldap
    rm DefaultAuthenticatormyrealmInit.initialized
    8. Go to folder DOMAIN_HOME/servers/AdminServer/security
    9. Edit the boot.properties file and change the password to the value already used on step 5. Do this for all the servers in the domain.
    10. Start Weblogic Server (Weblogic Server will encrypt the password for you).
    Regards,
    Kal

Maybe you are looking for

  • [svn] 3275: Initial check in for support for asdoc comments in mxml files.

    Revision: 3275 Author: [email protected] Date: 2008-09-19 15:01:57 -0700 (Fri, 19 Sep 2008) Log Message: Initial check in for support for asdoc comments in mxml files. For adding comments at the class level or to properties defined inside mxml use th

  • Iweb help - blog entries problem

    Hello, I am trying to create a highly customized blog in iweb '08 and so far am doing very well, all the pages look perfect over all browsers however i have tried to edit the blog entries page but am having grave difficulty, i have set the page attri

  • Sales before Purchase

    At one of my client side, sales is done before purchase.. in that case gross profit  shown will be 100%. but that is not correct and also the inventory level goes in negative.. Is there any way to handle this sceneario?

  • Time on Phones are Different Then System Time

    The time on the phones are different then the time on the system.  How do we force a sync? Here is the time on the phone Screenshot below of system time The system has been rebooted twice and still no resolution.

  • Iphoto import freezes preventing me from logging out

    Iphoto suggest I'm still trying to import a file but I cancelled the operation as it seemed to be taking too long but it doesn't seem to recognise that the task was cancelled. It's left me in a strange position that I can't do some operations as the