Привет, all!Никак не могу прикрутить aaa для доступа к циске по http
никак пускать не хочет.
делал как написано здесь
http://www.cisco.com/en/US/tech/tk59/technologies_tech_note0...
>sh ver
Cisco IOS Software, 3800 Software (C3845-ADVENTERPRISEK9-M), Version 12.4(15)T1, RELEASE SOFTWARE (fc2)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2007 by Cisco Systems, Inc.
Compiled Wed 18-Jul-07 11:59 by prod_rel_team
ROM: System Bootstrap, Version 12.4(13r)T, RELEASE SOFTWARE (fc1)
Cisco-3845-RUP uptime is 16 weeks, 6 days, 1 hour, 40 minutes
System returned to ROM by reload at 13:09:39 EDT Wed Apr 2 2008
System restarted at 13:11:15 EDT Wed Apr 2 2008
System image file is "flash:c3845-adventerprisek9-mz.124-15.t1.bin"
___________________________________________________________________________
вот что в конфиге
aaa new-model
!
!
aaa authentication login default group radius local
aaa authentication login CONSOLEandHTTP group radius local
aaa authorization console
aaa authorization exec CONSOLEandHTTP group radius local
ip http server
ip http authentication aaa login-authentication CONSOLEandHTTP
ip http authentication aaa exec-authorization CONSOLEandHTTP
ip http authentication aaa command-authorization 15 CONSOLEandHTTP
line con 0
authorization exec CONSOLEandHTTP
login authentication CONSOLEandHTTP
stopbits 1
вот что в дебаге пишет
Jul 29 11:40:39.205: HTTP AAA Login-Authentication List name: CONSOLEandHTTP
Jul 29 11:40:39.205: HTTP AAA Exec-Authorization List name: CONSOLEandHTTP
Jul 29 11:40:39.205: AAA/BIND(000001AB): Bind i/f
Jul 29 11:40:39.205: AAA/AUTHEN/LOGIN (000001AB): Pick method list 'CONSOLEandHTTP'
Jul 29 11:40:39.205: RADIUS/ENCODE(000001AB):Orig. component type = HTTP
Jul 29 11:40:39.205: RADIUS/ENCODE(000001AB): dropping service type, "radius-server attribute 6 on-for-login-auth" is off
Jul 29 11:40:39.205: RADIUS(000001AB): Config NAS IP: 0.0.0.0
Jul 29 11:40:39.205: RADIUS/ENCODE(000001AB): acct_session_id: 184
Jul 29 11:40:39.205: RADIUS(000001AB): sending
Jul 29 11:40:39.205: RADIUS/ENCODE: Best Local IP-Address X.X.X.41 for Radius-Server 10.179.0.16
Jul 29 11:40:39.205: RADIUS(000001AB): Send Access-Request to X.X.X.16:1645 id 1645/64, len 70
Jul 29 11:40:39.205: RADIUS: authenticator 3D B7 68 CE 94 4B 23 A3 - DD 2D F7 90 AC 6A 96 B1
Jul 29 11:40:39.205: RADIUS: User-Name [1] 7 "admin"
Jul 29 11:40:39.205: RADIUS: User-Password [2] 18 *
Jul 29 11:40:39.205: RADIUS: NAS-Port-Type [61] 6 Virtual [5]
Jul 29 11:40:39.205: RADIUS: Calling-Station-Id [31] 13 "X.X.X.19"
Jul 29 11:40:39.205: RADIUS: NAS-IP-Address [4] 6 X.X.X.41
Jul 29 11:40:39.229: RADIUS: Received from id 1645/64 X.X.X.16:1645, Access-Accept, len 53
Jul 29 11:40:39.229: RADIUS: authenticator 93 86 4E 8C 80 65 A6 DB - 3F 11 4C 65 A0 A7 80 42
Jul 29 11:40:39.229: RADIUS: Framed-IP-Address [8] 6 255.255.255.255
Jul 29 11:40:39.229: RADIUS: Class [25] 27
Jul 29 11:40:39.229: RADIUS: 43 41 43 53 3A 30 2F 32 37 37 37 2F 61 39 33 31 [CACS:0/2777/a931]
Jul 29 11:40:39.229: RADIUS: 38 32 39 2F 61 64 6D 69 6E [829/admin]
Jul 29 11:40:39.229: RADIUS(000001AB): Received from id 1645/64
Jul 29 11:40:39.229: HTTP: Authentication failed for level 15