Wired Intelligent Edge

 View Only

AOS-S Downloadable User Roles breaks Radius VSA

This thread has been viewed 6 times
  • 1.  AOS-S Downloadable User Roles breaks Radius VSA

    Posted 12 days ago

    When enabling the following configuration, the following message is received:

    switch# aaa authorization user-role enable download
    Some legacy secure client access functionality is not supported when user roles
     are enabled.

    Does anyone know precisely what legacy secure client access functionality is not supported? When I enable DUR, I can no longer send Radius VSA attributes for VLAN assignment from Clearpass, I can only send a DUR. Is this expected behavior? Is there a way to continue having some devices receive radius VSA on a switch while others receive a DUR?



    -------------------------------------------