Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

login using radius

Status
Not open for further replies.

volleyman

MIS
Jun 12, 2002
183
US
All,

I just configured a router to authenticate using radius. the radius server is a microsoft IAS server.

I am able to telnet and log into the router. When I attempt to change into enable mode, I get the following error:

% Error in authentication.


any ideas where I messed up? something on the router or somethng in the radius setup?

thanks,


Zane D.
Systems Admin
 
I should mention that when I access the router via console, it also authenticates using radius. after logging in, I type "enable" and it works. but when I telnet I get the error message mentioned above.


Zane D.
Systems Admin
 
strange...following those instructions I added both the Cisco attribute plus the reply-message attribute.

when i login, I see the reply message that I configured displayed but the privilege level still doesn't change!

Zane D.
Systems Admin
 
got it, I was missing something in the router config. I added some lines using the following as a template and it started working:

username localuser password 0 localpassword
aaa new-model

aaa authentication login default group radius local
aaa authentication login if_needed local
aaa authorization exec default group radius if-authenticated

radius-server host 10.20.30.50 auth-port 1645 acct-port 1646 key 0 cisco
radius-server vsa send authentication

line con 0
login authentication if_needed

line vty 0 4
login authentication default


Zane D.
Systems Admin
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top