Re: [OSL | CCIE_Security] Auth Proxy Telnet Vs http confusion

2010-03-15 Thread Badar Farooq
I did some more research. Using radius, the issue doesnt happen. I tested cisco av pairs auth-proxy:priv-lvl=15 auth-proxy:proxyacl#1=permit ip any any as well as shell:priv-lvl=15 shell:proxyacl#1=permit ip any any and http and telnet both works fine. With Tacacs though, I am still having

Re: [OSL | CCIE_Security] Auth Proxy Telnet Vs http confusion

2010-03-15 Thread Badar Farooq
Well HTTP proxy sends the following *Mar 1 00:13:45.399: FastEthernet0/1 AAA/AUTHOR/HTTP(3860994093): send AV service=auth-proxy *Mar 1 00:13:45.403: FastEthernet0/1 AAA/AUTHOR/HTTP(3860994093): *send AV cmd** *Mar 1 00:13:45.415: AAA/AUTHOR/TAC+: (3860994093): send AV service=auth-proxy *Mar

Re: [OSL | CCIE_Security] Auth Proxy Telnet Vs http confusion

2010-03-15 Thread Kingsley Charles
Did you try confguring one service with just auth-proxy and another one with both auth-proxy and ip protocol. With regards Kin On Mon, Mar 15, 2010 at 6:43 PM, Badar Farooq badarfar...@gmail.com wrote: Well HTTP proxy sends the following *Mar 1 00:13:45.399: FastEthernet0/1

Re: [OSL | CCIE_Security] Auth Proxy Telnet Vs http confusion

2010-03-15 Thread Piotr Kaluzny
Badar, What are the ACS logs saying about this? Regards, -- Piotr Kaluzny CCIE #25665 (Security), CCSP, CCNP Sr. Support Engineer - IPexpert, Inc. URL: http://www.IPexpert.com On Mon, Mar 15, 2010 at 2:19 PM, Kingsley Charles kingsley.char...@gmail.com wrote: Did you try confguring one

Re: [OSL | CCIE_Security] Auth Proxy Telnet Vs http confusion

2010-03-15 Thread Tyson Scott
AM To: Kingsley Charles Cc: ccie_security@onlinestudylist.com Subject: Re: [OSL | CCIE_Security] Auth Proxy Telnet Vs http confusion Badar, What are the ACS logs saying about this? Regards, -- Piotr Kaluzny CCIE #25665 (Security), CCSP, CCNP Sr. Support Engineer - IPexpert, Inc. URL: http

Re: [OSL | CCIE_Security] Auth Proxy Telnet Vs http confusion

2010-03-15 Thread Badar Farooq
*Sent:* Monday, March 15, 2010 9:28 AM *To:* Kingsley Charles *Cc:* ccie_security@onlinestudylist.com *Subject:* Re: [OSL | CCIE_Security] Auth Proxy Telnet Vs http confusion Badar, What are the ACS logs saying about this? Regards, -- Piotr Kaluzny CCIE #25665 (Security), CCSP, CCNP Sr

Re: [OSL | CCIE_Security] Auth Proxy Telnet Vs http confusion

2010-03-15 Thread Piotr Kaluzny
:* ccie_security-boun...@onlinestudylist.com [mailto: ccie_security-boun...@onlinestudylist.com] *On Behalf Of *Piotr Kaluzny *Sent:* Monday, March 15, 2010 9:28 AM *To:* Kingsley Charles *Cc:* ccie_security@onlinestudylist.com *Subject:* Re: [OSL | CCIE_Security] Auth Proxy Telnet Vs http confusion