[cisco-nas] Autocommand PAD over ISDN

Aaron Leonard Aaron at cisco.com
Wed May 13 11:55:39 EDT 2009


For this scheme to work, the session needs to go through local exec
authorization (aaa authorization exec ... local).

Cheers,

Aaron

------------------------------------------------------------------------

bordin at cetrel.lu wrote:
>
> Hello Aaron,
>
> Ok for don't use resource-pool manager.
> But I have already configured aaa authentication and authorization :
>
>
> aaa new-model
> !
> !
> aaa group server tacacs+ TACACS-CETREL
>  server xxxxxxxxxxxx
>  server xxxxxxxxxxxx
> !
> aaa authentication login TAC-CET group TACACS-CETREL enable
> aaa authentication login EMPTY none
> aaa authentication enable default group TACACS-CETREL enable
> aaa authorization exec default group TACACS-CETREL none
> aaa authorization exec EMPTY none
> aaa authorization exec TAC-CET group TACACS-CETREL local
> !
>
>
> And when I configured
>
> username 11111111 nopassword dnis
> username 11111111 autocommand pad 990101803 /cud ABRK /profile krone
> /quiet
>
>
> I have this debug :
>
>   [ ... ]
> May 13 17:05:17.139: AAA/AUTHOR/RM call-accept(3726381892) no method
> list defined
>         Type "resource-manager" list "default". Using method "local"
> [ ... ]
> May 13 17:05:17.139: AAA/AUTHOR (3726381892): Post authorization
> status = FAIL  


More information about the cisco-nas mailing list