Re: IAS - policy profile IP Packet Filter issue



for the benefit of everyone out there - since it has been
hard to find any sort of documentation (either from Cisco
and from Microsoft) - here are the things I did:

The Vendor attribute I added was Cisco-AV-Pair
(from the Advanced tab of the policy profile select Add and
then 'Cisco-AV-Pair').
All the fields are grayed except the field for the
Attribute values.
I wanted to set an ACL to limit all ip traffic from
192.168.0.7 to my user and vice-versa, so I set the
following values:

ip:inacl#1=permit ip host 192.168.0.7 any

and then

ip:inacl#2=permit any ip host 192.168.0.7

Another method is to set a Vendor Specific (Radius
standard) attribute (attribute number 26), set for Cisco
(vendor code 9), specifying that this attribute is RFC
conformed and then, clicking on 'Configure attribute', you
should set vendor-assigned attribute number to 1 (which
means AV-Pair) and finally set the value, exactly as before.

In both cases the things seem to work :)



>-----Original Message-----
>Hello Giulio,
>
> This is happening because the profile element "IP
filters" are a Microsoft
>vendor specific RADIUS attribute (it is not a RFC
standard) and only
>Microsoft products (like RRAS) can understand them.
> To have your Cisco NAS understand the filters, you need
to configure IAS
>to send Cisco vendor specific attributes. Go to
profile->Advanced->add and
>select "Vendor-Specific" and configure the attributes
according to Cisco's
>specs.
>
> Hoep this helps.
> Thanks, Manju
>
>--
>+++++++++++++++++++++++++++++++++++++++++++++++
>This posting is provided "AS IS" with no warranties, and
confers no rights
>
>
>"Giulio" <anonymous@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in
message
>news:202a01c53ea4$da029c50$a601280a@xxxxxxxxxx
>> Hi All,
>> I've a problem with the configuration of a policy profile
>> in IAS: it seems to me that the packet filter IP in the
>> profile of the policy is not applyed.
>>
>> A user (say 'test') is configured in this way:
>> - Dial-in tab: Remote Access: "Control Access through
>> remote access policy"
>> - NAS: Cisco 3700
>> - IAS policy for this user:
>> . Grant Remote Access Permission
>> . profile - IP Deny all traffic except from 192.168.0.7 to
>> user-IP
>> . profile - IP Deny all traffic from user to 192.168.0.7
>>
>> The other profile configurations are set as default.
>>
>> The user is correctly authenticated and from the event log
>> I can see that the policy used is the correct one.
>>
>> I expected I could not ping anything but 192.168.0.7 but,
>> once authenticated, the test user can ping everything
around!
>>
>> The strange thing is that the same policy in a RRAS server
>> (without IAS) works in the correct way. It's exactly the
>> same policy since I imported it from the old server with
>> the netsh command.
>>
>> Please help me!!!
>>
>>
>
>
>.
>
.



Relevant Pages

  • Re: IAS - policy profile IP Packet Filter issue
    ... so I'll try to specify a Cisco VSA as you said. ... >vendor specific RADIUS attribute (it is not a RFC ... >> I've a problem with the configuration of a policy profile ... >> profile of the policy is not applyed. ...
    (microsoft.public.internet.radius)
  • Re: Detecting WAPs
    ... > types of traffic create by the WAP? ... Netstumbler will display the IP & MAC address (and therefore the vendor) ... MAC/IP pairings of devices on your network. ... Cisco AP's use CDP to discover their local Cisco brethren, ...
    (Security-Basics)
  • Re: Mobile Computers Cannot Access Internet away from home
    ... Lan Settings ... ... If the vendor set up a policy to point the clients at a/the ... proxy server would that override or prevent a manual setting? ...
    (microsoft.public.windows.server.sbs)
  • Should AV software protect against rogue hack/crack files (was: Re: SCR file being posted to usenet
    ... If it's the policy of any given AV company/software to be selective ... when it comes to malware detection (ie to specifically NOT protect ... any AV vendor can certainly choose whether to ... include or exclude malware detection within known hack/crack/key-gen ...
    (alt.comp.anti-virus)
  • Re: Semi-OT: My LCD has a bright pixel
    ... bright-pixel "policy". ... If no joy, ... leverage to get a replacement product. ... Usually it takes 30-45 days for the payment to be made to the vendor, ...
    (comp.sys.ibm.pc.games.action)