Which aaa directives for what?

Hi out there
I am trying to get a AAA Radius server (freeradius 2.0.10 with MySql)  up and run which I need to use for authentication and authorazition of EZVPN clients from remote routers running in network extension mode.
I have tried many of the samples presented by cisco but I am a bit in doubt what aaa directive influence on this and that - so - are there some which can help?
When my ezvpn clients - a remote cisco router running 15.x ios is loggin in on my central vpn router i have to get it authenticated. I am using a virtual template tunnel interface which I want to clone for each router connecting in.
this I expect is done by :
                    aaa authentication login vpnlist group RadiusServers local
This forces the centralrouter to ask for authentication and seems to work
But - I have several AVPairs I want to push out there and as far as I can see i get them returned by the radiusserver but not applied?
Where do I force these settings to be applied to the incoming clients interface - is this done by the crypto-isakmp profile or the virtual template? - I can push a static set of values through the virtual template - but I want to specify them from the AVPairs defined either from the group or user settings
here is the output from my radius server in debug mode when my remote client logs in:
++[exec] returns noop
Sending Access-Accept of id 163 to 11.12.50.3 port 1645
        Service-Type = Outbound-User
        Tunnel-Type:0 = ESP
        Tunnel-Password:0 = "cisco"
        Cisco-AVPair += "ipsec:key-exchange=ike"
        Cisco-AVPair += "ipsec:key-exchange=preshared-key"
        Cisco-AVPair += "ipsec:user-save-password=1"
        Cisco-AVPair += "ipsec:user-vpn-group=adpex-ezvpn"
        Cisco-AVPair += "ip:interface-config=ip vrf forwarding dk-ae-01
How do I define this?
best regards /ti

I always advise going for the 2.0 machine...if it's not going to be too much of a financial hardship. Why? Well, so that if you need it, you've got it. You may think you'll only use it for word processing--but then maybe you'll get into photography or videos in the next year and be glad of the extra power. (That happens with Mac users by the way. The programs that come with the machine are so appealing that they start using them, and doing more on the computers than they'd ever done before.) Or maybe new programs will come out that you want, and you'll be grateful for the extra to help running them.
The other thing to keep in mind is that Macs tend to last. So where people might replace a laptop within a year or two, with a Mac they replace it in three-four years. Maybe even longer. So getting a more powerful machine is worth the money because it's likely that you'll be holding onto it longer and it'll need to keep up with your growing and changing needs.
That, at least, is my advice.

Similar Messages

  • I couldn't get my maps to work while out today which I needed for directions anyone know why ? It kept saying no server .

    I couldn't get my maps to work while out today which I needed for directions anyone know why ? It kept saying no server , is it to do with my settings, my network provider, 3G or what ? Anyone help please.
    Thanks

    Yes it is about 40 mg - I didn't know there was a size limit? How can I change that?

  • I have just started to use Muse for our design agency and learning how to build ourselves a new site, I have manged to create a basic lightbox which contains sliding images, what I need to do now is have a pop up window which goes into detail about the pr

    I have just started to use Muse for our design agency and learning how to build ourselves a new site, I have managed to create a basic lightbox which contains sliding images, what I need to do now is have a pop up window which goes into detail about the projects, what I would like is a piece of text  or icon that when you roll over it and then click a separate window pops up with additional information in, once finished reading the info you can then click to close the box, any advice on how to do this?

    The best way to do what you're asking is with the Composition widget. Start with the Tooltip preset, which, by default shows the info on rollover. You can change the option to show on click, which is what you're after. You can also add the close button or have the info disappear on rollout.
    David

  • I had an apple ID which I used for iCloud.  I upgraded the iCloud account and changed the apple ID to a @me address. Now I can't view what was in my original apple ID account.  How can I get what was stored on the original account?

    I had an Apple ID which I used for iCloud.  I upgraded the iCloud account and changed the apple ID to a @me address. Now I can't view what was in my original apple ID account.  How can I get what was stored on the original account?

    cathorio wrote:
    I recently changed my lap top. My problem is the new lap top won't accept my apple I D it asked me to sing up for a new one which I did.
    I am puzzled by this. The laptop doesn't need the Apple ID - but iTunes does. I could be missing something but ....
    Why would you not be able to use your existing Apple ID and iTunes account on a new laptop? If you authorized the computer - you should be able to use your existing account - unless you already had 5 computers authorized with the existing ID - and that was why iTunes would not accept the ID. However, I'm sure that you would have received a popup message from iTunes telling you that you had reached the limit.
    I just received a new MBP and my daughter did as well. My entire family shares an Apple ID and we had no issues at all with my Apple ID and iTunes on our new computers and I did not have to sign up for a new account. Did you even try the old ID?

  • I run a mac air on a single user account but multiple people using it, which is ok for the situation. All have their accounts in the apple mail app. what is missing for me is a separate password to access the mail account. otherwise anyone can see anyones

    I run a mac air on a single user account but multiple people using it, which is ok for the situation. All have their accounts in the apple mail app. what is missing for me is a separate password to access the mail account. otherwise anyone can see anyones
    Any clue, how i can add a mail account to apple mail app, but with separate password / pin to open it.
    Years ago there was a program called mail switcher which added this functionality, but thats gone.
    cheers
    Tom

    They would have to be logged in as separate users in order not to see your account in Mail. Whatever accounts put in Mail under your account will show up. All mail accounts usually have there own user and password. The only thing you can do is to remove the password from Keychain and take the account offline so you don't keep getting prompts for passwords each time it checks for mail.
    Not a great solution.
    Best way is to give the other user their own user account with their own mail and enable fast user swithcing to log between the different users if all access the computer frequently.

  • I had to restore my computer to the factory settings, which means my itunes library was lost except for what was on my ipod nano.  How do pull the songs from my ipod back onto my computer?

    I had to restore my computer to the factory settings, which means my itunes library was lost except for what was on my ipod nano.  How do pull the songs from my ipod back onto my computer?  I have over 200 songs.  There is no way I can re-purchase them!  Any help?

    How to use your iPod to move your music to a new computer 

  • I bought an ipad mini from some guy returning to the states and when i upgraded its os version its now asking for his apple id which i dont have. what should i do

    i bought an ipad mini from  some guy returning to the states and when i upgraded its os version its  now asking for his apple id which i dont have. what should i do

    That is Activation Lock.
    You have to contact the previous owner to have him remove it
    Find My iPhone Activation Lock: Removing a device from a previous owner

  • What are appropriate directives for array implementation in hls

    dear friends,
      I have tried hardware implementation in VivadoHLS by passing arrays to the function in Microblaze based soc. The problem I am facing is that the RTL is not being implemented properly.Though the implementation was success for register inputs and outputs , there were no functions generated in the header files in include directory of pcores through which inputs are to be given to hardware while the input and output arguments are arrays in SDK. i need a help to know the appropriate directives for this implementation . And the functions to be used to give inputs after generating hardware and how the final outputs from the hardware are taken. Please clarify the implementation of this basic example.
    void array_add(int z[4],int x[4])
    #pragma HLS INTERFACE ap_fifo port=z
    #pragma HLS INTERFACE ap_fifo port=x
    #pragma HLS RESOURCE variable=z core=AXIS
    #pragma HLS RESOURCE variable=x core=AXIS
    #pragma HLS RESOURCE variable=return core=AXI4LiteS
    int i;
    label0:for(i=0;i<4;i++)
    z[i]=x[i];
    return;
    thanks and regards
    sasidhar

    Hi
    There are couple of directives for this. This can determine the way you want to implement your array or partition this.
    I found a good guide.
    http://users.ece.utexas.edu/~gerstl/ee382v_f14/soc/vivado_hls/VivadoHLS_Improving_Performance.pdf
    Hope this helps.
    Regards
    Sikta

  • HT3275 This file 'Volumes/Data/iMac van Bruno Heutz.sparsebundle' which is used for backup copie is already in use. What do I have to do?.

    Every 30 min I get this message from Time Machine.
    This file 'Volumes/Data/iMac van Bruno Heutz.sparsebundle' which is used for backup copie is already in use.
    What do I have to do?.
    Kind regards,
    Bruno

    Restart the TC..
    But yours might be more serious than that.
    Read C12 in pondini.
    http://pondini.org/TM/Troubleshooting.html
    I would suggest you change all names to match what Pondini writes here.
    C9
    And use ethernet not wireless.

  • My iPod is up to a 4.1 ios, and it won't update to a 5.1 which I need for some of my apps for school. It keeps saying that my internet connection is bad; but, it works just fine. What do I need to do?

    My iPod is up to a 4.1 ios, and it won't update to a 5.1 which I need for some of my apps for school. It keeps saying that my internet connection is bad; but, it works just fine. What do I need to do?

    If you get a network timeout error, then disabling the computer's security software duirng the download and update usually resovles that error.
    If that is not the error what is the wording of the error message.
    Note that only a 3G or 4G iPod can go to iOS 5.  A 2G iPod can only go to iOS 4.2.1

  • Trying to update apps on iPhone keeps saying funds not available which there are. What's the minimum balance for free updates?

    Trying to update apps on iPhone keeps saying funds not available which there are. What's the minimum balance for free updates?

    Updates are free. Upgrades aren't.

  • How are the Apps Store and iTunes store different? Which do you use for what?

    Can you explain the difference between Apps Store and iTunes store? Is Apps a subset of iTunes store? To which store do you go for what?

    Apps you buy from the Mac App store can be used on your computer.  You use the same Apple ID as the iTunes Store, but that's the only connection.
    Apps you buy from the iTunes App Store are written to run on an iOS device (iPhone, iPad or iPod Touch).  They won't run on your computer, only on your iDevice.

  • Which legacy systems are used for what purpose?

    Hi gurus,
    I tried looking in this forums, but couldnt gather much information on which legacy systems are used and for what purpose? <b>can any body send me a link that can help me understand when and where, which systems are used for what purpose..</b> I have a general understanding of Legacy systems so i am not looking for terminology explanation,  i would appreciate any thing that is related to business and explains the purpose.
    thanks,
    kishore karnati

    Hi,
    Term legacy system means tailor made system by group of software developer or any branded software which deals with the group requirement  like tally we user for finance.
    Legacy system can be based on any technology like visual basis as front end and oracle as back end or Developer 2k as front end and oracle as back end. For report most of the legacy system we have seen uses crystal report.
    You can develop and implement based on the requirement from the user though you need to define some specify process to keep the system streamline which is in your hands.
    Concept like devlopment/quality/production we don't have that verys strict concept.
    More and more they are not intergrated each other functionally mean lets say inventory has come to the godown then your vendor outstanding should increase in finance which does not happens you need to key in the seperate value for it.
    Hope this helps!!!

  • HT5429 I live in Iceland, now I always get " No direction for this destination" It worked fine with Google maps, what can I do, can I revert to OS 5?

    I live in Iceland, now after downloading OS 6 on my iphone 4S, no directions for any destination what so ever, are available anymore on the Maps app. It worked just fine previously. What can I do ?

    Annewin wrote:
    I can no longer choose Lab color under mode because many option are greyed out.
    Anne when a feature is not compatible with the active document Photoshop will gray out the features in its menus. For example if you are editing an HDR image in 32 Bit color mode.  Many Photoshop features do not support 32 Bit Color so they will be grayed out. Lab for sure will be grayed out as will many other menu items.
    Supply pertinent information for quicker answers
    The more information you supply about your situation, the better equipped other community members will be to answer. Consider including the following in your question:
    Adobe product and version number
    Operating system and version number
    The full text of any error message(s)
    What you were doing when the problem occurred
    Screenshots of the problem
    Computer hardware, such as CPU; GPU; amount of RAM; etc.

  • TOC which account for what comes before it

    I'm trying to create a TOC (Table of Contents) which can also account for what comes BEFORE it. (And not only the sections which follow it).Anyone has an idea?

    Pages TOC will only index what comes after it.
    You could perhaps add any prior items manually.
    Peter

Maybe you are looking for

  • How do i save a .m4v file to the movie folder when it will only save to the music folder?

    I have a movie file in my ITunes music folder that i want to mover to the movie folder because it is a movie. The file type is a .m4v. When i click and drag it itunes wont let me drop it in movies. What do i do??

  • 'Lost' media After ITunes Upgrade

    Hi - I have an older computer and have saved my ITunes library to an external harddrive owing to capacity limitations on my system. I recently updated ITunes to the latest version and it changed the media file location back to the main unit C:Drive,

  • I cannot use bridge it is stuck in building criteria.

    Has anyone else noticed that Adobe is NO HELP AT ALL! I cannot get a person to assist me and I have been trying for 2 months! A refund would be great! I cannot use bridge it is stuck in building criteria. I have reinstalled on M AC and still NOTHING

  • Graphic Glitch on export transition

    Here's whats going on. I'm shooting on a T2i, and I import the .mov files into FCP just fine, they playback and all. I've export project after project without problems with this same setup. I export the project using quicktime, and the export has gra

  • Dynamic Directive in Java App

    I created a JSP using the dynamic directives based on what is in the Application Development guide of mod_osso. I have the app deployed on a standalone oc4j 9.0.3. It doesn't seem to pick up the getRemoteUser...do I need to deploy in the OHS, or am I