<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Link-State</title>
	<atom:link href="http://linkstate.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://linkstate.wordpress.com</link>
	<description>General Network Musings</description>
	<lastBuildDate>Thu, 17 Nov 2011 16:42:39 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='linkstate.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Link-State</title>
		<link>http://linkstate.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://linkstate.wordpress.com/osd.xml" title="Link-State" />
	<atom:link rel='hub' href='http://linkstate.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Moving On&#8230;</title>
		<link>http://linkstate.wordpress.com/2011/11/17/moving-on/</link>
		<comments>http://linkstate.wordpress.com/2011/11/17/moving-on/#comments</comments>
		<pubDate>Thu, 17 Nov 2011 16:42:33 +0000</pubDate>
		<dc:creator>Jamie</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://linkstate.wordpress.com/?p=225</guid>
		<description><![CDATA[Today is my penultimate day with my current company; I am moving on to bigger and (hopefully!) better things. It’s a weird feeling leaving a job, especially one where you have made so many changes. There is only a small network here (~700 users, ~200 servers) but when I started it had been badly neglected [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=linkstate.wordpress.com&amp;blog=21547659&amp;post=225&amp;subd=linkstate&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Today is my penultimate day with my current company; I am moving on to bigger and (hopefully!) better things.</p>
<p>It’s a weird feeling leaving a job, especially one where you have made so many changes. There is only a small network here (~700 users, ~200 servers) but when I started it had been badly neglected for several years – There wasn’t really anyone with sufficient experience to manage a network, so things had just been left and fingers crossed that nothing would go wrong&#8230;</p>
<p><span id="more-225"></span></p>
<p>During my time here I have implemented many things that I hope will make the network faster, more stable and more resilient, as well as some procedural changes to help keep things going smoothly when I’m gone. Here is a snippet of some of the things I&#8217;ve done during my tenure here;</p>
<ul>
<li>Documentation/Diagrams – There were virtually no complete diagram of the network, or accompanying documentation, for maybe the first month of my time here, I was on my hands and knees in computer rooms chasing cables, or sat with a scrap of paper trying to map things out using CDP. Once I had a full diagram of the network, I realized just how bad things were.</li>
<li>Redundant Links – were non-existence, the whole network was a mess of SPOF’s (Single Point of Failure)   To be fair to the original designers, you could see what they had planned, and in many cases implemented, but due to lack of accurate monitoring, they had one by one failed (GBIC’s/SFP failure, fibres that had been crushed etc&#8230;) This leads to&#8230;.</li>
<li>Monitoring – there was an installation of Solarwinds NPM, but it was not being fully utilized, only nodes were monitored, and then only by ICMP – no interface status, no SNMP, no traffic graphs etc&#8230; I pretty much started from scratch with monitoring. I installed NCM alongside NPM so that there was actually some configuration management as well as monitoring. All the major interfaces were monitored, alerts configured, configurations backed up, even syslog and SNMP traps setup and alerts generated.</li>
<li>VLAN’s – No one seemed to know how to change the VLAN on a switchport, instead the desktop support guys had a diagram of which switchport’s were configured to which VLAN’s for each switch and just ran a cable, in some instances, this let to cables being stretched across multiple cabs (see my previous posts about <a href="http://linkstate.wordpress.com/category/the-big-weekend/">recabling the Patching Room</a>) I’ve now gone as far as giving the desktop guys privileges on the access switches to change VLAN’s themselves to speed up desk moves etc&#8230;</li>
<li>Remote Authentication – all the equipment was accessed using local accounts, when someone started or left, you can imagine the trouble going to all the kit and changing it, and forget about regular password changes – so people just didn’t bother, there were accounts on there that were for people who had been left 4/5 years. I used windows NPS (Network Policy Server) as a Radius Server, and went to each device, removed all the local accounts (accept a backup local admin account) and configured them for AAA and Radius. Now people use their domain credentials, which are controlled by the AD Password Policies, and the local admin account has the password changed often (which is very easy to do thanks to NCM!!!)</li>
</ul>
<p>There are many many other things I have done here to try to bring the network up to scratch, unfortunately there are still many many things that need to be done, but I have been unable to due to the people who sign the cheques being unwilling to spend the money. I can, however, at least say it is in a MUCH better state than when I started.</p>
<p>Before I wrote this post, I decided to have a last walk around the computer rooms and patching rooms and couldn’t help feel a little sad. This was my first job where I had my “own” network, I know every cable and every switch, and I just hope it won’t miss me too much! I believe they are looking for a replacement, as I think they realized they can’t have the situation again where things are left to rot. I just hope the new engineer who comes in looks after it and treats it well&#8230;   &#8230;anyway, Nexus – here I come!!!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/linkstate.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/linkstate.wordpress.com/225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/linkstate.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/linkstate.wordpress.com/225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/linkstate.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/linkstate.wordpress.com/225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/linkstate.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/linkstate.wordpress.com/225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/linkstate.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/linkstate.wordpress.com/225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/linkstate.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/linkstate.wordpress.com/225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/linkstate.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/linkstate.wordpress.com/225/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=linkstate.wordpress.com&amp;blog=21547659&amp;post=225&amp;subd=linkstate&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://linkstate.wordpress.com/2011/11/17/moving-on/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/acc3b04b131de4577956673f74cd7ca4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rekordze</media:title>
		</media:content>
	</item>
		<item>
		<title>MP-BGP for IPv6</title>
		<link>http://linkstate.wordpress.com/2011/08/16/mp-bgp-for-ipv6/</link>
		<comments>http://linkstate.wordpress.com/2011/08/16/mp-bgp-for-ipv6/#comments</comments>
		<pubDate>Tue, 16 Aug 2011 10:36:20 +0000</pubDate>
		<dc:creator>Jamie</dc:creator>
				<category><![CDATA[BGP]]></category>
		<category><![CDATA[IPv6]]></category>
		<category><![CDATA[MP-BGP]]></category>
		<category><![CDATA[Routing]]></category>

		<guid isPermaLink="false">http://linkstate.wordpress.com/?p=202</guid>
		<description><![CDATA[I recently passed the CCNP SWITCH exam, so now Spanning-tree is out the window, and I am firmly concentrated on all things layer 3 in preparation for the CCNP ROUTE exam. One of the areas I have not really had much exposure too is IPv6.&#160; So I have spent the last few days going over [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=linkstate.wordpress.com&amp;blog=21547659&amp;post=202&amp;subd=linkstate&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I recently passed the CCNP SWITCH exam, so now Spanning-tree is out the window, and I am firmly concentrated on all things layer 3 in preparation for the CCNP ROUTE exam.</p>
<p>One of the areas I have not really had much exposure too is IPv6.&nbsp; So I have spent the last few days going over the theory behind it, and trying to put it into practice.<br />
<span id="more-202"></span></p>
<p>Below is the topology i have been using for MP-BGP (MultiProtocol BGP)</p>
<p><a href="http://linkstate.files.wordpress.com/2011/08/mp-bgp.png"><img class="size-medium wp-image-203 alignnone" title="mp-bgp" src="http://linkstate.files.wordpress.com/2011/08/mp-bgp.png?w=300&#038;h=243" alt="" width="300" height="243" /></a></p>
<p>I have used /127 addresses for the links between the routers, and R1 and R3 have loopback interfaces to simulate host networks.</p>
<p>Again, I am new to IPv6 so any feedback on design etc.. is welcome!! I&#8217;m assuming that anyone reading this has some experience of BGP in IPv4 networks, so i;m not going into massive depth on the config as mostly its the same, just different <img src='http://s0.wp.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>First step is to configure the IPv6 addresses on the interfaces;</p>
<p><span style="font-family:courier new;"><span style="color:#ff0000;">R1</span><br />
<span style="color:#ff0000;">interface FastEthernet0/0</span><br />
<span style="color:#ff0000;">&nbsp;ipv6 address 2001:1::/127</span></span></p>
<p><span style="color:#ff0000;">R2</span><br />
<span style="color:#ff0000;">interface FastEthernet0/0</span><br />
<span style="color:#ff0000;">&nbsp;ipv6 address 2001:1::1/127</span><br />
<span style="color:#ff0000;">interface FastEthernet0/1</span><br />
<span style="color:#ff0000;">&nbsp;ipv6 address 2001:2::/127</span></p>
<p><span style="color:#ff0000;">R3</span><br />
<span style="color:#ff0000;">interface FastEthernet0/1</span><br />
<span style="color:#ff0000;">&nbsp;ipv6 address 2001:2::1/127</span></p>
<p>Next, enable IPv6 routing globally with the &#8220;ipv6 unicast-routing&#8221; command. Now to configure the loopback interfaces</p>
<p>R1 user 2001:11:: and R3 uses 2001:10::</p>
<p><span style="font-family:courier new;"><span style="color:#ff0000;">interface Loopback0</span><br />
<span style="color:#ff0000;">&nbsp;ipv6 address 2001:11::1/112</span><br />
<span style="color:#ff0000;">interface Loopback1</span><br />
<span style="color:#ff0000;">&nbsp;ipv6 address 2001:11::1:1/112</span><br />
<span style="color:#ff0000;">interface Loopback2</span><br />
<span style="color:#ff0000;">&nbsp;ipv6 address 2001:11::2:1/112</span><br />
<span style="color:#ff0000;">interface Loopback3</span><br />
<span style="color:#ff0000;">&nbsp;ipv6 address 2001:11::3:1/112</span><br />
<span style="color:#ff0000;">interface Loopback4</span><br />
<span style="color:#ff0000;">&nbsp;ipv6 address 2001:11::4:1/112</span></span></p>
<p>There are several stages to configuring MP-BGP, first is to enable BGP and disable IPv4. Unlike OSPFv3 you configure MP-BGP under the same process as standard BGP</p>
<p><span style="font-family:courier new;"><span style="color:#ff0000;">router bgp 1545</span><br />
<span style="color:#ff0000;">&nbsp;bgp router-id 1.1.1.1</span><br />
<span style="color:#ff0000;">&nbsp;no bgp default ipv4-unicast</span></span></p>
<p>Now, add your peer&#8217;s IPv6 address and the remote ASN</p>
<p><span style="font-family:courier new;"><span style="color:#ff0000;">&nbsp;neighbor 2001:1::1 remote-as 8547</span></span></p>
<p>You now need to create an IPv6 address family, and add the neighbor to it</p>
<p><span style="font-family:courier new;"><span style="color:#ff0000;">&nbsp;address-family ipv6</span><br />
<span style="color:#ff0000;">&nbsp; neighbor 2001:1::1 activate</span></span></p>
<p>Any other BGP commands you might want to use are carried out within the address-family &#8211; network, aggregate-address, additional neighbor commands. So in order to advertise the loopback interfaces;</p>
<p><span style="font-family:courier new;"><span style="color:#ff0000;">&nbsp;address-family ipv6</span><br />
<span style="color:#ff0000;">&nbsp; network 2001:11::0:1/112</span><br />
<span style="color:#ff0000;">&nbsp; network 2001:11::1:1/112</span><br />
<span style="color:#ff0000;">&nbsp; network 2001:11::2:1/112</span><br />
<span style="color:#ff0000;">&nbsp; network 2001:11::3:1/112</span><br />
<span style="color:#ff0000;">&nbsp; network 2001:11::4:1/112</span></span></p>
<p>and if we want to create a summary range</p>
<p><span style="font-family:courier new;"><span style="color:#ff0000;">&nbsp;address-family ipv6</span><br />
<span style="color:#ff0000;">&nbsp; aggregate-address 2001:11::/96 summary-only</span></span></p>
<p>The full BGP configs for all 3 routers are as follows</p>
<p>R1</p>
<p><span style="font-family:courier new;"><span style="color:#ff0000;">router bgp 1545</span><br />
<span style="color:#ff0000;">&nbsp;bgp router-id 1.1.1.1</span><br />
<span style="color:#ff0000;">&nbsp;no bgp default ipv4-unicast</span><br />
<span style="color:#ff0000;">&nbsp;bgp log-neighbor-changes</span><br />
<span style="color:#ff0000;">&nbsp;neighbor 2001:1::1 remote-as 8547</span><br />
<span style="color:#ff0000;">&nbsp;!</span><br />
<span style="color:#ff0000;">&nbsp;address-family ipv6</span><br />
<span style="color:#ff0000;">&nbsp; neighbor 2001:1::1 activate</span><br />
<span style="color:#ff0000;">&nbsp; network 2001:11::0:1/112</span><br />
<span style="color:#ff0000;">&nbsp; network 2001:11::1:1/112</span><br />
<span style="color:#ff0000;">&nbsp; network 2001:11::2:1/112</span><br />
<span style="color:#ff0000;">&nbsp; network 2001:11::3:1/112</span><br />
<span style="color:#ff0000;">&nbsp; network 2001:11::4:1/112</span><br />
<span style="color:#ff0000;">&nbsp; aggregate-address 2001:11::/96 summary-only</span><br />
<span style="color:#ff0000;">&nbsp; no synchronization</span><br />
<span style="color:#ff0000;">&nbsp;exit-address-family</span></span></p>
<p>R2</p>
<p><span style="font-family:courier new;"><span style="color:#ff0000;">router bgp 8547</span><br />
<span style="color:#ff0000;">&nbsp;bgp router-id 2.2.2.2</span><br />
<span style="color:#ff0000;">&nbsp;no bgp default ipv4-unicast</span><br />
<span style="color:#ff0000;">&nbsp;bgp log-neighbor-changes</span><br />
<span style="color:#ff0000;">&nbsp;neighbor 2001:1:: remote-as 1545</span><br />
<span style="color:#ff0000;">&nbsp;neighbor 2001:2::1 remote-as 8547</span><br />
<span style="color:#ff0000;">&nbsp;!</span><br />
<span style="color:#ff0000;">&nbsp;address-family ipv6</span><br />
<span style="color:#ff0000;">&nbsp; neighbor 2001:1:: activate</span><br />
<span style="color:#ff0000;">&nbsp; neighbor 2001:2::1 activate</span><br />
<span style="color:#ff0000;">&nbsp; neighbor 2001:2::1 next-hop-self</span><br />
<span style="color:#ff0000;">&nbsp;exit-address-family</span></span></p>
<p>R3</p>
<p><span style="font-family:courier new;"><span style="color:#ff0000;">router bgp 8547</span><br />
<span style="color:#ff0000;">&nbsp;bgp router-id 3.3.3.3</span><br />
<span style="color:#ff0000;">&nbsp;no bgp default ipv4-unicast</span><br />
<span style="color:#ff0000;">&nbsp;bgp log-neighbor-changes</span><br />
<span style="color:#ff0000;">&nbsp;neighbor 2001:2:: remote-as 8547</span><br />
<span style="color:#ff0000;">&nbsp;!</span><br />
<span style="color:#ff0000;">&nbsp;address-family ipv6</span><br />
<span style="color:#ff0000;">&nbsp; neighbor 2001:2:: activate</span><br />
<span style="color:#ff0000;">&nbsp; neighbor 2001:2:: next-hop-self<br />
network 2001:10::0:1/112<br />
network 2001:10::1:1/112</span><br />
<span style="color:#ff0000;">&nbsp; network 2001:10::2:1/112</span><br />
<span style="color:#ff0000;">&nbsp; network 2001:10::3:1/112</span><br />
<span style="color:#ff0000;">&nbsp; network 2001:10::4:1/112</span><br />
<span style="color:#ff0000;">&nbsp; aggregate-address 2001:10::/96 summary-only</span><br />
<span style="color:#ff0000;">&nbsp;exit-address-family</span></span></p>
<p>The show commands have also changed slightly, some examples are;</p>
<ul>
<li>show ip bgp &gt; show ip bgp ipv6 unicast</li>
<li>show ip bgp summary &gt; show ip bgp ipv6 unicast summary</li>
</ul>
<p>Hopefully this is all good, again, i cant stress enough, I&#8217;m a novice in terms of IPv6, so please feel free to comment with suggestions and improvements.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/linkstate.wordpress.com/202/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/linkstate.wordpress.com/202/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/linkstate.wordpress.com/202/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/linkstate.wordpress.com/202/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/linkstate.wordpress.com/202/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/linkstate.wordpress.com/202/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/linkstate.wordpress.com/202/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/linkstate.wordpress.com/202/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/linkstate.wordpress.com/202/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/linkstate.wordpress.com/202/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/linkstate.wordpress.com/202/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/linkstate.wordpress.com/202/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/linkstate.wordpress.com/202/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/linkstate.wordpress.com/202/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=linkstate.wordpress.com&amp;blog=21547659&amp;post=202&amp;subd=linkstate&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://linkstate.wordpress.com/2011/08/16/mp-bgp-for-ipv6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/acc3b04b131de4577956673f74cd7ca4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rekordze</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/08/mp-bgp.png?w=300" medium="image">
			<media:title type="html">mp-bgp</media:title>
		</media:content>
	</item>
		<item>
		<title>IP SLA and Object Tracking</title>
		<link>http://linkstate.wordpress.com/2011/07/15/ip-sla-and-object-tracking/</link>
		<comments>http://linkstate.wordpress.com/2011/07/15/ip-sla-and-object-tracking/#comments</comments>
		<pubDate>Fri, 15 Jul 2011 10:46:37 +0000</pubDate>
		<dc:creator>Jamie</dc:creator>
				<category><![CDATA[Routing]]></category>
		<category><![CDATA[HSRP]]></category>
		<category><![CDATA[IP SLA]]></category>
		<category><![CDATA[Tracking]]></category>

		<guid isPermaLink="false">http://linkstate.wordpress.com/?p=186</guid>
		<description><![CDATA[I’ve recently been doing some work with our HSRP setup around our network. Like most people, we use HSRP as a first hop redundancy mechanism to provide clients attached to the network with a virtual default gateway. HSRP will, be default, fail from Active to Standby, should the routers lose the ability to talk to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=linkstate.wordpress.com&amp;blog=21547659&amp;post=186&amp;subd=linkstate&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:justify;">I’ve recently been doing some work with our HSRP setup around our network. Like most people, we use HSRP as a first hop redundancy mechanism to provide clients attached to the network with a virtual default gateway. HSRP will, be default, fail from Active to Standby, should the routers lose the ability to talk to one another on the subnet the HSRP for.</p>
<p>But what if something “down the line” fails…</p>
<p style="text-align:justify;">
<span id="more-186"></span><br />
<a href="http://linkstate.files.wordpress.com/2011/07/track_lab1.png"><img class="alignright size-full wp-image-188" title="Track_Lab" src="http://linkstate.files.wordpress.com/2011/07/track_lab1.png?w=415&#038;h=640" alt="" width="415" height="640" /></a>Take this example to the right, R1 and R2 have a HSRP group between them for the 10.0.0.0/24 network, with R1 having the higher priority. R6 is playing the part of “host” and has a default route to the HSRP Virtual IP Address.</p>
<p>The aim of the lab is to ensure that R6 can always get to the 4.2.2.2 address on R5. There is a very basic OSPF setup between R1, R2, R3, R4 &amp; R5, with R5 propagating default information.</p>
<p>What happens if the link between R1 and R3 were to fail, R1 and R2 would be able to speak to each other, so R2 would not take over as the Active HSRP node.</p>
<p>All of a sudden, R6 has lost connectivity to 4.2.2.2</p>
<p>There are a few different tools at our disposal to combat this problem – IP SLA and Tracking.</p>
<p>IP SLA is Internet Protocol Service Level Agreement, and allows you to retrieve statics for all manner of things, from as simple as a ping response, to making sure a TCP Port is open, to path jitter for your IP Telephony deployments.</p>
<p>Tracking allows you to track a wide range of objects, such as interface status, or the results of an IP SLA object.&nbsp; Tracking objects are either UP or DOWN. Tracking can be used to influence a number of things – HSRP priority, GLBP weighting or policy routing decisions.</p>
<p>In this first example, we are going to be using IP SLA to checking that R1 can ping 4.2.2.2 with a source IP of 10.0.0.11, and then creating a tracking object.</p>
<p><font face="courier new"><br />
<span style="color:#ff0000;">ip sla 10</span><br />
<span style="color:#ff0000;"> &nbsp;icmp-echo 4.2.2.2 source-interface FastEthernet0/1</span><br />
<span style="color:#ff0000;"> &nbsp;frequency 5</span><br />
<span style="color:#ff0000;"> ip sla schedule 10 life forever start-time now</span><br />
<span style="color:#ff0000;"> !</span><br />
<span style="color:#ff0000;"> track 10 rtr 10</span><br />
</font></p>
<p>You won&#8217;t get SLA information unless you add the schedule line (you can set it to only function during certain times etc…)</p>
<p>Once it&#8217;s up and running, the below command shows the results</p>
<p><font face="courier new"><br />
<span style="color:#ff0000;">R1#show ip sla statistics 10</span></p>
<p><span style="color:#ff0000;"> Round Trip Time (RTT) for&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Index 10</span><br />
<span style="color:#ff0000;"> &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Latest RTT: 80 milliseconds</span><br />
<span style="color:#ff0000;"> Latest operation start time: *01:02:44.343 UTC Fri Mar 1 2002</span><br />
<span style="color:#ff0000;"> Latest operation return code: OK</span><br />
<span style="color:#ff0000;"> Number of successes: 4</span><br />
<span style="color:#ff0000;"> Number of failures: 0</span><br />
<span style="color:#ff0000;"> Operation time to live: Forever</span></p>
<p><span style="color:#ff0000;"> R1#show track brief</span><br />
<span style="color:#ff0000;"> Track&nbsp;&nbsp; Object&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Parameter&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Value Last Change</span><br />
<span style="color:#ff0000;"> 10&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; rtr&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 10&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; state&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Up&nbsp;&nbsp;&nbsp; 00:06:28</span><br />
</font></p>
<p>You can see that the SLA object is getting a response, so returning an OK code, and therefore the tracked object is showing as UP.</p>
<p>Tracked objects do work without SLA objects, the following checks that a certain route exists in the routing table</p>
<p><font face="courier new"><br />
<span style="color:#ff0000;">track 20 ip route 0.0.0.0 0.0.0.0 reachability</span><br />
</font></p>
<p>When you look at the tracked object, it confirms the state, and even shows you where the route is learned from.</p>
<p><font face="courier new"><br />
<span style="color:#ff0000;">R1#show track 20</span><br />
<span style="color:#ff0000;"> Track 20</span><br />
<span style="color:#ff0000;"> &nbsp; IP route 0.0.0.0 0.0.0.0 reachability</span><br />
<span style="color:#ff0000;"> &nbsp; Reachability is Up (OSPF)</span><br />
<span style="color:#ff0000;"> &nbsp;&nbsp;&nbsp; 7 changes, last change 01:33:21</span><br />
<span style="color:#ff0000;"> &nbsp; First-hop interface is FastEthernet0/0</span><br />
</font></p>
<p>You can also use tracking to check the state of interfaces, you can check layer 1/2</p>
<p><font face="courier new"><br />
<span style="color:#ff0000;">track 40 interface FastEthernet0/0 line-protocol</span><br />
</font></p>
<p>or layer 3</p>
<p><font face="courier new"><br />
<span style="color:#ff0000;">track 30 interface FastEthernet0/0 ip routing</span><br />
</font></p>
<p>This is a type of tracking object called a list, this lets you bundle several other tracking objects together.</p>
<p><font face="courier new"><br />
<span style="color:#ff0000;">track 1 list boolean and</span><br />
<span style="color:#ff0000;"> &nbsp;object 30</span><br />
<span style="color:#ff0000;"> &nbsp;object 40</span><br />
</font></p>
<p>Tracking lists are using boolean logic to decide its status, you have a choice of OR or AND</p>
<p>OR – if any object is up, the main track group is up<br />
AND – all objects need to be up for the main track group to be up (if any single object is down, the group is down)</p>
<p>If you have a particularly flaky network; and things might blip very quickly, or you just want to allow a little time to make sure the condition is true before things start failing over, you can add delays to a tracked object, either when they are due to go down, or up.</p>
<p><font face="courier new"><br />
<span style="color:#ff0000;"> track 1 list boolean and</span><br />
<span style="color:#ff0000;"> &nbsp;delay down 10 up 10</span><br />
</font></p>
<p>this means that when trigger changes, and the object should be down, it will wait 10 seconds before actually changing its status, obviously, if the conditions change during this count down, then the countdown will cancel and the object will remain up. Equally, using the up delay, when an object is down, and is due to change to up, it will take 10 seconds before actually changing.</p>
<p><font face="courier new"><br />
<span style="color:#ff0000;"> Track 1</span><br />
<span style="color:#ff0000;"> &nbsp; List boolean and</span><br />
<span style="color:#ff0000;"> &nbsp; Boolean AND is Up, delayed Down (8 secs remaining)</span><br />
<span style="color:#ff0000;"> &nbsp;&nbsp;&nbsp; 2 changes, last change 00:09:33</span><br />
<span style="color:#ff0000;"> &nbsp;&nbsp;&nbsp; object 30 Down</span><br />
<span style="color:#ff0000;"> &nbsp;&nbsp;&nbsp; object 40 Down</span><br />
<span style="color:#ff0000;"> &nbsp; Delay up 10 secs, down 10 secs</span><br />
</font></p>
<p>So now you have setup all your tracked objects, what can you actually do with them? with HSRP, you can use the tracked object to adjust the routers priority, in the example above, HSRP is setup between R1 and R2,</p>
<p>R1 priority = 200<br />
R2 priority = 180</p>
<p>In this example, when any of the tracked object are triggered, they will decrement the routers priority by 30, taking its priority to below that of R2, and because preempt is configured, it will cause R2 to transition into Active state.</p>
<p><font face="courier new"><br />
<span style="color:#ff0000;">interface FastEthernet0/1</span><br />
<span style="color:#ff0000;"> &nbsp;ip address 10.0.0.11 255.255.255.0</span><br />
<span style="color:#ff0000;"> &nbsp;standby 10 ip 10.0.0.1</span><br />
<span style="color:#ff0000;"> &nbsp;standby 10 priority 200</span><br />
<span style="color:#ff0000;"> &nbsp;standby 10 preempt</span><br />
<span style="color:#ff0000;"> &nbsp;standby 10 track 10 decrement 30</span><br />
<span style="color:#ff0000;"> &nbsp;standby 10 track 20 decrement 30</span><br />
<span style="color:#ff0000;"> &nbsp;standby 1 0 track 1 decrement 30</span><br />
<span style="color:#ff0000;"> end</span><br />
</font></p>
<p>You can use tracking objects for adjusting the weighing in GLBP</p>
<p><font face="courier new"><br />
<span style="color:#ff0000;">interface FastEthernet0/1</span><br />
<span style="color:#ff0000;"> &nbsp;ip address 10.0.0.12 255.255.255.0</span><br />
<span style="color:#ff0000;"> &nbsp;speed 100</span><br />
<span style="color:#ff0000;"> &nbsp;full-duplex</span><br />
<span style="color:#ff0000;"> &nbsp;glbp 10 ip 10.0.0.1</span><br />
<span style="color:#ff0000;"> &nbsp;glbp 10 priority 200</span><br />
<span style="color:#ff0000;"> &nbsp;glbp 10 preempt</span><br />
<span style="color:#ff0000;"> &nbsp;glbp 10 weighting track 1 decrement 30</span><br />
<span style="color:#ff0000;"> &nbsp;glbp 10 weighting track 30 decrement 30</span><br />
<span style="color:#ff0000;"> &nbsp;glbp 10 weighting track 40 decrement 30</span><br />
</font></p>
<p>or, you can use it to verify the existence of a next hop in your policy based routing</p>
<p><font face="courier new"><br />
<span style="color:#ff0000;"> ip sla 15</span><br />
<span style="color:#ff0000;"> &nbsp;icmp-echo 10.0.0.12</span><br />
<span style="color:#ff0000;"> ip sla schedule 15 life forever start-time now</span><br />
<span style="color:#ff0000;"> !</span><br />
<span style="color:#ff0000;"> track 15 rtr 15</span><br />
<span style="color:#ff0000;"> !</span><br />
<span style="color:#ff0000;"> route-map MYROUTEMAP permit 10</span><br />
<span style="color:#ff0000;"> &nbsp;set ip next-hop verify-availability 10.0.0.12 1 track 15</span></p>
<p style="text-align:justify;">
<p></font></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/linkstate.wordpress.com/186/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/linkstate.wordpress.com/186/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/linkstate.wordpress.com/186/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/linkstate.wordpress.com/186/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/linkstate.wordpress.com/186/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/linkstate.wordpress.com/186/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/linkstate.wordpress.com/186/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/linkstate.wordpress.com/186/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/linkstate.wordpress.com/186/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/linkstate.wordpress.com/186/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/linkstate.wordpress.com/186/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/linkstate.wordpress.com/186/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/linkstate.wordpress.com/186/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/linkstate.wordpress.com/186/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=linkstate.wordpress.com&amp;blog=21547659&amp;post=186&amp;subd=linkstate&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://linkstate.wordpress.com/2011/07/15/ip-sla-and-object-tracking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/acc3b04b131de4577956673f74cd7ca4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rekordze</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/07/track_lab1.png" medium="image">
			<media:title type="html">Track_Lab</media:title>
		</media:content>
	</item>
		<item>
		<title>Using interface bandwidth to influence EIGRP routing decisions</title>
		<link>http://linkstate.wordpress.com/2011/07/13/using-interface-bandwidth-to-influence-eigrp-routing-decisions/</link>
		<comments>http://linkstate.wordpress.com/2011/07/13/using-interface-bandwidth-to-influence-eigrp-routing-decisions/#comments</comments>
		<pubDate>Wed, 13 Jul 2011 11:31:51 +0000</pubDate>
		<dc:creator>Jamie</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://linkstate.wordpress.com/?p=159</guid>
		<description><![CDATA[Now we have our wireless bridge in place, we wanted to configure EIGRP to seamlessly converge over that link in the event of a fiber failure between sites. We currently have 4 cores (2 at each site) with a full mesh connectivity between them. Each link comprises of 2x 1Gbps fibers bundled together into 2Gbps [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=linkstate.wordpress.com&amp;blog=21547659&amp;post=159&amp;subd=linkstate&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Now we have our wireless bridge in place, we wanted to configure EIGRP to seamlessly converge over that link in the event of a fiber failure between sites.</p>
<p>We currently have 4 cores (2 at each site) with a full mesh connectivity between them. Each link comprises of 2x 1Gbps fibers bundled together into 2Gbps etherchannels.&nbsp; There is also layer2 connectivity between cores at each site (allowing cores within a site to be EIGRP neighbors.</p>
<p><a href="http://linkstate.files.wordpress.com/2011/07/diagram.png"><img class="alignnone size-full wp-image-160" title="diagram" src="http://linkstate.files.wordpress.com/2011/07/diagram.png?w=281&#038;h=281" alt="" width="281" height="281" /></a></p>
<p><span id="more-159"></span>Despite the quite redundant looking diagram above, this only provides us redundancy from GBIC/SFP/Line card failures. The fact is that all of these fibers go into 2 multicore fibers running in the same duct underground, so we are still quite vulnerable.</p>
<p>The WIFI Bridge has an AP at both sites, each one connected back to a core.</p>
<p><a href="http://linkstate.files.wordpress.com/2011/07/diagram1.png"><img class="alignnone size-full wp-image-161" title="diagram2" src="http://linkstate.files.wordpress.com/2011/07/diagram1.png?w=341&#038;h=281" alt="" width="341" height="281" /></a></p>
<p>Once we had confirmed IP connectivity between the two sites via the WIFI bridge, we configured EIGRP to work over the links, the neighbor relationships formed, and BAM utilization on the WIFI link shot to 100%. so i grab a few &#8220;show&#8221; outputs and disabled EIGRP to return traffic back to normal.</p>
<p>What i discovered was that because we use VLAN&#8217;s for alot of routing, the minimum bandwidth EIGRP see&#8217;s is usually a gig, the below shows a routing table entry for a subnet that is load sharing over two of the fiber links</p>
<p><span style="font-family:courier new;"> <span style="color:#ff0000;">D&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 10.21.10.0/24 [90/3072] via 10.0.0.22, 21:04:21, Port-channel2</span> <span style="color:#ff0000;"><br />
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; [90/3072] via 10.0.0.18, 21:04:21, Port-channel3</span></span><br />
<span style="font-family:courier new;"><br />
you can see the minimum bandwidth is always 1000000 Kbit, so its the delay that is used to determine which routes end up in the routing table, as some routes are 2 hops, the delay is incremented per hop, as the below &#8220;show ip eigrp topology x.x.x.x&#8221; shows;</span></p>
<p><span style="color:#ff0000;">IP-EIGRP (AS 99): Topology entry for 10.21.10.0/24</span><br />
<span style="color:#ff0000;">&nbsp; State is Passive, Query origin flag is 1, 2 Successor(s), FD is 3072</span><br />
<span style="color:#ff0000;">&nbsp; Routing Descriptor Blocks:</span><br />
<span style="color:#ff0000;">&nbsp; 10.0.0.22 (Port-channel2), from 10.0.0.22, Send flag is 0&#215;0</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Composite metric is (3072/2816), Route is Internal</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Vector metric:</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Minimum bandwidth is 1000000 Kbit</span><br />
<span style="background-color:#ffff00;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Total delay is 20 microseconds</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Reliability is 255/255</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Load is 1/255</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Minimum MTU is 1500</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Hop count is 1</span><br />
<span style="color:#ff0000;">&nbsp; 10.0.0.18 (Port-channel3), from 10.0.0.18, Send flag is 0&#215;0</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Composite metric is (3072/2816), Route is Internal</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Vector metric:</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Minimum bandwidth is 1000000 Kbit</span><br />
<span style="background-color:#ffff00;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Total delay is 20 microseconds</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Reliability is 255/255</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Load is 1/255</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Minimum MTU is 1500</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Hop count is 1</span><br />
<span style="color:#ff0000;">&nbsp; 10.1.1.11 (Vlan1001), from 10.1.1.11, Send flag is 0&#215;0</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Composite metric is (3328/3072), Route is Internal</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Vector metric:</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Minimum bandwidth is 1000000 Kbit</span><br />
<span style="background-color:#ffff00;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Total delay is 30 microseconds</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Reliability is 255/255</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Load is 1/255</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Minimum MTU is 1500</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Hop count is 2</span><br />
<span style="color:#ff0000;">&nbsp; 10.0.0.1 (Vlan1000), from 10.0.0.1, Send flag is 0&#215;0</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Composite metric is (3328/3072), Route is Internal</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Vector metric:</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Minimum bandwidth is 1000000 Kbit</span><br />
<span style="background-color:#ffff00;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Total delay is 30 microseconds</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Reliability is 255/255</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Load is 1/255</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Minimum MTU is 1500</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Hop count is 2</span></p>
<p>As the Wireless bridges are connected to Gigabit ports, EIGRP sees the bandwidth as 1000000 Kbit, and the delay as 20microseconds, hence being introduced into the routing table and being seen as an equal cost to the fiber links.</p>
<p>There is a very simple way to correct this issue, and that is to use the interface command &#8220;bandwidth&#8221; to change the perceived bandwidth of the link (note: only perceived bandwidth, as the link will still transfer packets as fast as it can)</p>
<p><span style="font-family:courier new;"><span style="color:#ff0000;">interface Vlan900</span><br />
<span style="color:#ff0000;">&nbsp;bandwidth 10</span></p>
<p>Setting the bandwith to 10 means that EIGRP sees the link as only 10k, and therefore pretty much guarantees that it will be the absolute last choice link. The below shows all the available paths to the 10.21.10.0/24 network, Po2 &amp; Po3 are the fiber links, Vlan1000 is the EIGRP VLAN between cores in the same site, and VLAN 900 is used for the WIFI Bridge.</p>
<p><span style="font-family:courier new;"><span style="color:#ff0000;">P 10.21.10.0/24, 2 successors, FD is 3072, serno 8990</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; via 10.0.0.22 (3072/2816), Port-channel2</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; via 10.0.0.18 (3072/2816), Port-channel3</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; via 10.0.3.1 (256000512/2816), Vlan900</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; via 10.1.1.11 (3328/3072), Vlan1001</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; via 10.0.0.1 (3328/3072), Vlan1000</span></p>
<p>As you can see, the metric is very high, meaning that if variance were to be increased to allow unequal cost load balancing there is still a high probability that this route would not be selected.</p>
<p><span style="font-family:courier new;"><span style="color:#ff0000;">&nbsp; 10.0.3.1 (Vlan900), from 10.0.3.1, Send flag is 0&#215;0</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Composite metric is (256000512/2816), Route is Internal</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Vector metric:</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Minimum bandwidth is 10 Kbit</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Total delay is 20 microseconds</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Reliability is 255/255</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Load is 1/255</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Minimum MTU is 1500</span><br />
<span style="color:#ff0000;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Hop count is 1</span></span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/linkstate.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/linkstate.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/linkstate.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/linkstate.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/linkstate.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/linkstate.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/linkstate.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/linkstate.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/linkstate.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/linkstate.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/linkstate.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/linkstate.wordpress.com/159/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/linkstate.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/linkstate.wordpress.com/159/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=linkstate.wordpress.com&amp;blog=21547659&amp;post=159&amp;subd=linkstate&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://linkstate.wordpress.com/2011/07/13/using-interface-bandwidth-to-influence-eigrp-routing-decisions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/acc3b04b131de4577956673f74cd7ca4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rekordze</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/07/diagram.png" medium="image">
			<media:title type="html">diagram</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/07/diagram1.png" medium="image">
			<media:title type="html">diagram2</media:title>
		</media:content>
	</item>
		<item>
		<title>Site to Site WIFI Part 2</title>
		<link>http://linkstate.wordpress.com/2011/07/13/site-to-site-wifi-part-2/</link>
		<comments>http://linkstate.wordpress.com/2011/07/13/site-to-site-wifi-part-2/#comments</comments>
		<pubDate>Wed, 13 Jul 2011 09:10:59 +0000</pubDate>
		<dc:creator>Jamie</dc:creator>
				<category><![CDATA[Wireless]]></category>

		<guid isPermaLink="false">http://linkstate.wordpress.com/?p=143</guid>
		<description><![CDATA[Data cabling was installed at the end of last week. And we finished configuring the AP&#8217;s yesterday.Setup was pretty easy really. You can connect the AP&#8217;s to any type of switch port, so they will take tagged and untagged traffic. By default the management addresses of the AP&#8217;s will be on the native VLAN, however [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=linkstate.wordpress.com&amp;blog=21547659&amp;post=143&amp;subd=linkstate&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Data cabling was installed at the end of last week. And we finished configuring the AP&#8217;s yesterday.Setup was pretty easy really. You can connect the AP&#8217;s to any type of switch port, so they will take tagged and untagged traffic.</p>
<p>By default the management addresses of the AP&#8217;s will be on the native VLAN, however there is an option to enable a management VLAN so that management traffic (HTTP, SNMP, SSH etc&#8230;) will be tagged with the appropriate VLAN ID.</p>
<p>Now the big question &#8211; Speed.<br />
<span id="more-143"></span> Despite our initial testing being around 200Mbps, we were only able to get around 110Mbps out of it. The theory is that when we tested it in February time, the trees were not as dense as they are now, and whilst it works through the trees, they do appear to be causing speed issues.</p>
<p><a href="http://linkstate.files.wordpress.com/2011/07/speed1.png"><img class="alignnone size-full wp-image-155" title="speed" src="http://linkstate.files.wordpress.com/2011/07/speed1.png?w=600&#038;h=310" alt="" width="600" height="310" /></a></p>
<p>Still, the original line of sight solution was 10Mbps, so for 2 grand we have managed to increase the speed by 10x. As long as we have a fiber failure over winter, we&#8217;re laughing!!!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/linkstate.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/linkstate.wordpress.com/143/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/linkstate.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/linkstate.wordpress.com/143/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/linkstate.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/linkstate.wordpress.com/143/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/linkstate.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/linkstate.wordpress.com/143/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/linkstate.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/linkstate.wordpress.com/143/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/linkstate.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/linkstate.wordpress.com/143/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/linkstate.wordpress.com/143/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/linkstate.wordpress.com/143/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=linkstate.wordpress.com&amp;blog=21547659&amp;post=143&amp;subd=linkstate&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://linkstate.wordpress.com/2011/07/13/site-to-site-wifi-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/acc3b04b131de4577956673f74cd7ca4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rekordze</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/07/speed1.png" medium="image">
			<media:title type="html">speed</media:title>
		</media:content>
	</item>
		<item>
		<title>Site to Site WIFI</title>
		<link>http://linkstate.wordpress.com/2011/07/05/site-to-site-wifi/</link>
		<comments>http://linkstate.wordpress.com/2011/07/05/site-to-site-wifi/#comments</comments>
		<pubDate>Tue, 05 Jul 2011 14:19:54 +0000</pubDate>
		<dc:creator>Jamie</dc:creator>
				<category><![CDATA[Wireless]]></category>
		<category><![CDATA[Line of Sight]]></category>
		<category><![CDATA[LoS]]></category>
		<category><![CDATA[Ruckus]]></category>

		<guid isPermaLink="false">http://linkstate.wordpress.com/?p=125</guid>
		<description><![CDATA[The company I work at has two sites; the offices and a warehouse. The sites are about 500ft apart, separated by some council owned woodland. We have a couple of 24x core fibers running between the sites. However we recently realized that all the fibers went via the some underground conduit &#8211; part of which [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=linkstate.wordpress.com&amp;blog=21547659&amp;post=125&amp;subd=linkstate&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The company I work at has two sites; the offices and a warehouse. <a href="http://linkstate.files.wordpress.com/2011/07/img00059-20110705-1402.jpg"><img class="alignright" title="Line of Sight01" src="http://linkstate.files.wordpress.com/2011/07/img00059-20110705-1402.jpg?w=300&#038;h=225" alt="" width="300" height="225" /></a>The sites are about 500ft apart, separated by some council owned woodland. We have a couple of 24x core fibers running between the sites. However we recently realized that all the fibers went via the some underground conduit &#8211; part of which goes under the council woodland &#8211; so given that we have no control over some council worker in a digger sticking is bucket into our fiber, we decided a backup was required!!</p>
<p>Someone previously had installed a laser Line of Sight system, which delivered about 10Mbps, however what they neglected to realize when it was installed (maybe 6 years ago) was that trees grow. The woodland is green belt so we couldn&#8217;t touch the trees, and what use is 10Mbps anyway!! we push around 300Mbps between sites at any one time, going up to 500-600Mbps at peak times.</p>
<p><span id="more-125"></span>After looking at several solutions, we approached the company who supplied our corporate WIFI &#8211; <a href="http://www.wirelessevolution.co.uk/">Evolution Systems</a> &#8211; who are a reseller for <a href="http://www.ruckuswireless.com/">Ruckus</a>. We use a Ruckus Zonedirector 1000 and a variety of different Ruckus AP&#8217;s to provide WIFI services to the offices, warehouse and a Guest SSID. So we were happy to have a look at the Ruckus Site to Site solution.</p>
<p>Evolution suggested we look at the <a href="http://www.ruckuswireless.com/products/zoneflex-outdoor/7731">Ruckus 7731 802.11n Bridge</a> . Given the distance, according to the specs should expect to get at least 190Mbps, so this would provide us with sufficient bandwidth as a backup.</p>
<p>The guys from Evolution arranged a proof of concept by putting the AP&#8217;s on a temporary pole at each site, connecting each one to a laptop, and checking the speed between them. We were getting around between 170 &#8211; 180 Mbps, however they were not as high as they would be when permanently mounted  nor were they fully aligned for best performance. Given the speeds we decided to go ahead with them, and, signed PO in hand, we rang Evolution to place the order.</p>
<p>Today, after what seems like months of getting the necessary risk assessments completed (don&#8217;t your love health and safety!!) , the contractors arrived to install the mounting brackets.</p>
<p>Here are a few piccies from the install, we are still waiting to get the data cables run from the mounting brackets to the comms cabinets, once they are in we will be able to get a full speed test completed, fingers crossed for 200Mbps!!  !</p>
<p>(p.s. in the first picture, the ugly square thing is the old Laser Line of Sight)</p>
<p><a href="http://linkstate.files.wordpress.com/2011/07/img00050-20110705-1116.jpg"><img class="alignleft size-thumbnail wp-image-129" title="IMG00050-20110705-1116" src="http://linkstate.files.wordpress.com/2011/07/img00050-20110705-1116.jpg?w=112&#038;h=150" alt="" width="112" height="150" /></a><a href="http://linkstate.files.wordpress.com/2011/07/img00051-20110705-1210.jpg"> <img class="alignnone size-thumbnail wp-image-131" title="IMG00058-20110705-1402" src="http://linkstate.files.wordpress.com/2011/07/img00058-20110705-1402.jpg?w=150&#038;h=112" alt="" width="150" height="112" /> </a><a href="http://linkstate.files.wordpress.com/2011/07/img00051-20110705-1210.jpg"><img title="IMG00051-20110705-1210" src="http://linkstate.files.wordpress.com/2011/07/img00051-20110705-1210.jpg?w=150&#038;h=112" alt="" width="150" height="112" /></a><a href="http://linkstate.files.wordpress.com/2011/07/img00055-20110705-1216.jpg"> <img class="alignnone size-thumbnail wp-image-132" title="IMG00055-20110705-1216" src="http://linkstate.files.wordpress.com/2011/07/img00055-20110705-1216.jpg?w=150&#038;h=113" alt="" width="150" height="113" /></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/linkstate.wordpress.com/125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/linkstate.wordpress.com/125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/linkstate.wordpress.com/125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/linkstate.wordpress.com/125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/linkstate.wordpress.com/125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/linkstate.wordpress.com/125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/linkstate.wordpress.com/125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/linkstate.wordpress.com/125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/linkstate.wordpress.com/125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/linkstate.wordpress.com/125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/linkstate.wordpress.com/125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/linkstate.wordpress.com/125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/linkstate.wordpress.com/125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/linkstate.wordpress.com/125/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=linkstate.wordpress.com&amp;blog=21547659&amp;post=125&amp;subd=linkstate&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://linkstate.wordpress.com/2011/07/05/site-to-site-wifi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/acc3b04b131de4577956673f74cd7ca4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rekordze</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/07/img00059-20110705-1402.jpg?w=300" medium="image">
			<media:title type="html">Line of Sight01</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/07/img00050-20110705-1116.jpg?w=112" medium="image">
			<media:title type="html">IMG00050-20110705-1116</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/07/img00058-20110705-1402.jpg?w=150" medium="image">
			<media:title type="html">IMG00058-20110705-1402</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/07/img00051-20110705-1210.jpg?w=150" medium="image">
			<media:title type="html">IMG00051-20110705-1210</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/07/img00055-20110705-1216.jpg?w=150" medium="image">
			<media:title type="html">IMG00055-20110705-1216</media:title>
		</media:content>
	</item>
		<item>
		<title>CCDA&#8230;maybe</title>
		<link>http://linkstate.wordpress.com/2011/05/08/ccda-maybe/</link>
		<comments>http://linkstate.wordpress.com/2011/05/08/ccda-maybe/#comments</comments>
		<pubDate>Sun, 08 May 2011 10:45:33 +0000</pubDate>
		<dc:creator>Jamie</dc:creator>
				<category><![CDATA[Certification]]></category>
		<category><![CDATA[CCNP CCDA ROUTE SWITCH TSHOOT]]></category>

		<guid isPermaLink="false">http://linkstate.wordpress.com/?p=119</guid>
		<description><![CDATA[The eternal question&#8230;what cert to do next?? A few months ago, I was sure that i was going to be going straight on to CCNP R&#38;S. However, since then, I have done 0 studying for it! having a 7 month old baby girl means my time is somewhat limited. My CCNA expires in January next [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=linkstate.wordpress.com&amp;blog=21547659&amp;post=119&amp;subd=linkstate&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The eternal question&#8230;what cert to do next??</p>
<p>A few months ago, I was sure that i was going to be going straight on to CCNP R&amp;S. However, since then, I have done 0 studying for it! having a 7 month old baby girl means my time is somewhat limited. </p>
<p>My CCNA expires in January next year (3 years already!??!??!!??) so rather than re-sit I really want to do another certification. My thoughts &#8211; CCDA &#8211; the syllabus looks pretty easy, it&#8217;s mostly common sense from what I&#8217;ve heard. I did most of the studying for it about 12 months ago, so I think I just need a bit of a refresher and I should be good to go. </p>
<p>this way i get another 3 years to do at least one of the CCNP modules, which I&#8217;m sure I will, maybe SWITCH, I spend 80% of my time dealing with switching issues, so I don&#8217;t think it will be too complicated. It&#8217;s the ROUTE and TSHOOT that worry me slightly. ROUTE isn&#8217;t too bad, but TSHOOT is still a bit of an unknown quantity. Maybe I will have to save my pennies and go on a course rather than the self-study route. </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/linkstate.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/linkstate.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/linkstate.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/linkstate.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/linkstate.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/linkstate.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/linkstate.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/linkstate.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/linkstate.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/linkstate.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/linkstate.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/linkstate.wordpress.com/119/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/linkstate.wordpress.com/119/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/linkstate.wordpress.com/119/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=linkstate.wordpress.com&amp;blog=21547659&amp;post=119&amp;subd=linkstate&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://linkstate.wordpress.com/2011/05/08/ccda-maybe/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/acc3b04b131de4577956673f74cd7ca4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rekordze</media:title>
		</media:content>
	</item>
		<item>
		<title>The Recabling = Completed!</title>
		<link>http://linkstate.wordpress.com/2011/05/01/the-recabling-completed/</link>
		<comments>http://linkstate.wordpress.com/2011/05/01/the-recabling-completed/#comments</comments>
		<pubDate>Sun, 01 May 2011 19:11:05 +0000</pubDate>
		<dc:creator>Jamie</dc:creator>
				<category><![CDATA[The Big Weekend]]></category>
		<category><![CDATA[comms room]]></category>
		<category><![CDATA[patching]]></category>
		<category><![CDATA[recabling]]></category>

		<guid isPermaLink="false">http://linkstate.wordpress.com/?p=87</guid>
		<description><![CDATA[Following on from my last post, we have completed the recabling of our upstairs comms room. We had 4 days to complete the work, and managed to complete it after around 55 hours working around the clock &#8211; well ahead of schedule! We still have a few little things to troubleshoot &#8211; namely some patch [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=linkstate.wordpress.com&amp;blog=21547659&amp;post=87&amp;subd=linkstate&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Following on from my last post, we have completed the recabling of our upstairs comms room. We had 4 days to complete the work, and managed to complete it after around 55 hours working around the clock &#8211; well ahead of schedule!</p>
<p>We still have a few little things to troubleshoot &#8211; namely some patch panel that got damaged and need to be re-terminated on new panels &#8211; awaiting for our cabling contractor to get back to us on that, and I&#8217;m heading back in tomorrow to sort out some printers that are on the wrong VLAN etc&#8230;</p>
<p>Other than that, it all went very well, all the hours of planing ensured we had minimal issues.</p>
<p>We had a web cam running capturing a picture every 10 seconds, here&#8217;s the time-lapse video;</p>
<span style="text-align:center; display: block;"><a href="http://linkstate.wordpress.com/2011/05/01/the-recabling-completed/"><img src="http://img.youtube.com/vi/W_lfLmsYqD8/2.jpg" alt="" /></a></span>
<p><span id="more-87"></span><br />
First, here are some pictures to remind you what we were dealing with;</p>
<p><a href="http://linkstate.files.wordpress.com/2011/05/dsc02971.jpg"><img class="alignnone size-thumbnail wp-image-91" title="Before" src="http://linkstate.files.wordpress.com/2011/05/dsc02971.jpg?w=224&#038;h=150" alt="" width="224" height="150" /></a> <a href="http://linkstate.files.wordpress.com/2011/05/dsc02970.jpg"><img class="alignnone size-thumbnail wp-image-90" title="Before" src="http://linkstate.files.wordpress.com/2011/05/dsc02970.jpg?w=225&#038;h=150" alt="" width="225" height="150" /></a> <a href="http://linkstate.files.wordpress.com/2011/05/dsc02966.jpg"><img class="alignnone size-thumbnail wp-image-89" title="Before" src="http://linkstate.files.wordpress.com/2011/05/dsc02966.jpg?w=100&#038;h=150" alt="" width="100" height="150" /></a> <a href="http://linkstate.files.wordpress.com/2011/05/dsc02962.jpg"><img class="alignnone size-thumbnail wp-image-88" title="Before" src="http://linkstate.files.wordpress.com/2011/05/dsc02962.jpg?w=100&#038;h=150" alt="" width="100" height="150" /></a></p>
<p>We started by removing all of the old cables, that took around 5 hours, and was one of the most physically demanding jobs of the whole project. After 8 years or so, the network cables had become so tangled, we could only remove them in big clumps (a hacksaw came in useful here!)</p>
<p><a href="http://linkstate.files.wordpress.com/2011/05/dsc02981.jpg"><img class="alignnone size-thumbnail wp-image-93" title="Cables" src="http://linkstate.files.wordpress.com/2011/05/dsc02981.jpg?w=150&#038;h=100" alt="" width="150" height="100" /></a><a href="http://linkstate.files.wordpress.com/2011/05/dsc02982.jpg"> <img class="alignnone size-thumbnail wp-image-94" title="Cables" src="http://linkstate.files.wordpress.com/2011/05/dsc02982.jpg?w=150&#038;h=100" alt="" width="150" height="100" /></a> <a href="http://linkstate.files.wordpress.com/2011/05/dsc02987.jpg"><img class="alignnone size-thumbnail wp-image-98" title="Cables" src="http://linkstate.files.wordpress.com/2011/05/dsc02987.jpg?w=150&#038;h=100" alt="" width="150" height="100" /></a> <a href="http://linkstate.files.wordpress.com/2011/05/dsc02985.jpg"><img class="alignnone size-thumbnail wp-image-96" title="Cables" src="http://linkstate.files.wordpress.com/2011/05/dsc02985.jpg?w=150&#038;h=100" alt="" width="150" height="100" /></a></p>
<p><a href="http://linkstate.files.wordpress.com/2011/05/dsc02986.jpg"><img class="alignnone size-thumbnail wp-image-97" title="Cables" src="http://linkstate.files.wordpress.com/2011/05/dsc02986.jpg?w=100&#038;h=150" alt="" width="100" height="150" /></a> <a href="http://linkstate.files.wordpress.com/2011/05/dsc02983.jpg"><img class="alignnone size-thumbnail wp-image-95" title="Cables" src="http://linkstate.files.wordpress.com/2011/05/dsc02983.jpg?w=100&#038;h=150" alt="" width="100" height="150" /></a></p>
<p>There were an awful lot of cables, so one og the guys decided to dive into it</p>
<p><a href="http://linkstate.files.wordpress.com/2011/05/dsc03007.jpg"><img class="alignnone size-medium wp-image-100" title="Dive!" src="http://linkstate.files.wordpress.com/2011/05/dsc03007.jpg?w=300&#038;h=200" alt="" width="300" height="200" /></a></p>
<p>By now we were starting to flag, luckily we had lots of sugar and supplies to keep us going, diabetic Stu was finding it hard to resist the allure of all the sweets!</p>
<p><a href="http://linkstate.files.wordpress.com/2011/05/dsc03016.jpg"><img class="alignnone size-medium wp-image-101" title="Sweets" src="http://linkstate.files.wordpress.com/2011/05/dsc03016.jpg?w=300&#038;h=200" alt="" width="300" height="200" /></a></p>
<p>With all the cables out, we rearranged the cabinet layout, previously all the switches were at the top of the cabs meaning ports at the bottom needed excessively long cables, so we arranges the cabs so the switches are distributed across the height, meaning you never need more than a 1 meter cable, often only 0.5 meter;</p>
<p><a href="http://linkstate.files.wordpress.com/2011/05/dsc03020.jpg"><img class="alignnone size-medium wp-image-102" title="During" src="http://linkstate.files.wordpress.com/2011/05/dsc03020.jpg?w=200&#038;h=300" alt="" width="200" height="300" /></a><a href="http://linkstate.files.wordpress.com/2011/05/dsc03022.jpg">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <img class="alignnone size-medium wp-image-103" title="During" src="http://linkstate.files.wordpress.com/2011/05/dsc03022.jpg?w=200&#038;h=300" alt="" width="200" height="300" /></a></p>
<p>The next step was to begin the job of repatching in the data (the green cables)</p>
<p><a href="http://linkstate.files.wordpress.com/2011/05/dsc03031.jpg"><img class="alignnone size-medium wp-image-105" title="Data Cables" src="http://linkstate.files.wordpress.com/2011/05/dsc03031.jpg?w=367&#038;h=245" alt="" width="367" height="245" /></a>&nbsp; <a href="http://linkstate.files.wordpress.com/2011/05/dsc03030.jpg"><img class="alignnone size-medium wp-image-104" title="Data Cables" src="http://linkstate.files.wordpress.com/2011/05/dsc03030.jpg?w=163&#038;h=245" alt="" width="163" height="245" /></a></p>
<p>Next the phone cables (the blue ones) needed to be run in from the phone system opposite the data cabs</p>
<p><a href="http://linkstate.files.wordpress.com/2011/05/dsc03033.jpg"><img class="alignnone size-thumbnail wp-image-106" title="Telephones" src="http://linkstate.files.wordpress.com/2011/05/dsc03033.jpg?w=100&#038;h=150" alt="" width="100" height="150" /></a> <a href="http://linkstate.files.wordpress.com/2011/05/dsc03044.jpg"><img class="alignnone size-thumbnail wp-image-108" title="Telephones" src="http://linkstate.files.wordpress.com/2011/05/dsc03044.jpg?w=100&#038;h=150" alt="" width="100" height="150" /></a> <a href="http://linkstate.files.wordpress.com/2011/05/dsc03039.jpg"><img class="alignnone size-thumbnail wp-image-107" title="Telephones" src="http://linkstate.files.wordpress.com/2011/05/dsc03039.jpg?w=225&#038;h=150" alt="" width="225" height="150" /></a></p>
<p>Last job, tidy up the fibre in the cabinet containing the upstairs core switch</p>
<p><a href="http://linkstate.files.wordpress.com/2011/05/dsc03038.jpg"><img class="alignnone size-medium wp-image-109" title="Core Switch" src="http://linkstate.files.wordpress.com/2011/05/dsc03038.jpg?w=200&#038;h=300" alt="" width="200" height="300" /></a></p>
<p>I have uploaded all of these pictures and more to flickr <a title="Flickr" href="http://www.flickr.com/photos/jamieparks/sets/72157626623363380/">here</a></p>
<p>So there you go, we have another comms room that is in nowhere near as bad a state, but will still be a big job non the less. But having only just finished this one, will be a few months yet before we tackle that one</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/linkstate.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/linkstate.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/linkstate.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/linkstate.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/linkstate.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/linkstate.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/linkstate.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/linkstate.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/linkstate.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/linkstate.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/linkstate.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/linkstate.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/linkstate.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/linkstate.wordpress.com/87/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=linkstate.wordpress.com&amp;blog=21547659&amp;post=87&amp;subd=linkstate&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://linkstate.wordpress.com/2011/05/01/the-recabling-completed/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/acc3b04b131de4577956673f74cd7ca4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rekordze</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/05/dsc02971.jpg?w=150" medium="image">
			<media:title type="html">Before</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/05/dsc02970.jpg?w=150" medium="image">
			<media:title type="html">Before</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/05/dsc02966.jpg?w=100" medium="image">
			<media:title type="html">Before</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/05/dsc02962.jpg?w=100" medium="image">
			<media:title type="html">Before</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/05/dsc02981.jpg?w=150" medium="image">
			<media:title type="html">Cables</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/05/dsc02982.jpg?w=150" medium="image">
			<media:title type="html">Cables</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/05/dsc02987.jpg?w=150" medium="image">
			<media:title type="html">Cables</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/05/dsc02985.jpg?w=150" medium="image">
			<media:title type="html">Cables</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/05/dsc02986.jpg?w=100" medium="image">
			<media:title type="html">Cables</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/05/dsc02983.jpg?w=100" medium="image">
			<media:title type="html">Cables</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/05/dsc03007.jpg?w=300" medium="image">
			<media:title type="html">Dive!</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/05/dsc03016.jpg?w=300" medium="image">
			<media:title type="html">Sweets</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/05/dsc03020.jpg?w=200" medium="image">
			<media:title type="html">During</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/05/dsc03022.jpg?w=200" medium="image">
			<media:title type="html">During</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/05/dsc03031.jpg?w=300" medium="image">
			<media:title type="html">Data Cables</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/05/dsc03030.jpg?w=200" medium="image">
			<media:title type="html">Data Cables</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/05/dsc03033.jpg?w=100" medium="image">
			<media:title type="html">Telephones</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/05/dsc03044.jpg?w=100" medium="image">
			<media:title type="html">Telephones</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/05/dsc03039.jpg?w=150" medium="image">
			<media:title type="html">Telephones</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/05/dsc03038.jpg?w=200" medium="image">
			<media:title type="html">Core Switch</media:title>
		</media:content>
	</item>
		<item>
		<title>Recabling Project</title>
		<link>http://linkstate.wordpress.com/2011/04/19/recabling-project/</link>
		<comments>http://linkstate.wordpress.com/2011/04/19/recabling-project/#comments</comments>
		<pubDate>Tue, 19 Apr 2011 14:16:31 +0000</pubDate>
		<dc:creator>Jamie</dc:creator>
				<category><![CDATA[The Big Weekend]]></category>
		<category><![CDATA[Cabling]]></category>

		<guid isPermaLink="false">http://linkstate.wordpress.com/?p=66</guid>
		<description><![CDATA[Before I even started at my current job, I had heard rumours of the &#8220;upstairs comms room&#8221;. Imagine, if you will, 8 &#8211; 10 years of poor cable management, poor cabinet layout, and cables 10x too long for the job at hand. Whatever you now have in your head, double it, and you might be [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=linkstate.wordpress.com&amp;blog=21547659&amp;post=66&amp;subd=linkstate&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Before I even started at my current job, I had heard rumours of the &#8220;upstairs comms room&#8221;.</p>
<p><a href="http://linkstate.files.wordpress.com/2011/04/005.jpg"><img class="size-medium wp-image-67 alignright" title="005" src="http://linkstate.files.wordpress.com/2011/04/005.jpg?w=225&#038;h=300" alt="" width="225" height="300" /></a>Imagine, if you will, 8 &#8211; 10 years of poor cable management, poor cabinet layout, and cables 10x too long for the job at hand. Whatever you now have in your head, double it, and you might be getting close to our upstairs comms room.</p>
<p>This mass of cables to the right is comprised of around 2000 floor ports and 19 1u 18 port switches, and a whole heap of cable! I would say at least 50% of the cable is not actually in use, but has become so tangled and matted, it&#8217;s easier for the guys to run a new cable than move the old one &#8211; which obviously only serves to compound the problem!!</p>
<p>This single room has around 60% off our office space and 30% of our warehouse space patched into it. So downtime windows long enough to tackle this mess are few and far between.</p>
<p>But, thanks to <a href="http://en.wikipedia.org/wiki/Wedding_of_Prince_William_of_Wales_and_Kate_Middleton">Kate and Wills,</a> we have been graced with an extra 4 day weekend this year. So we are going to take the opportunity to recable the entire room. Several codenodes for the projects have been suggested, including &#8220;project subu&#8221;, but we eventually settled on &#8220;The Big Weekend&#8221;</p>
<p><span id="more-66"></span>So, starting at 1800 on the 28th April, we are going to remove every single cable, all the switches, all the old cable management rails, and re-do the lot! We have until 0700 on Tuesday 03rd May to get everyone done. I&#8217;ve drafted in most people in IT to help out (The desktop Guys, Server Guys, Helpdesk Guys, even the Head of Infrastructure) so there will be around 10 of us working in shifts around the clock to get it completed. We hope to be finished for early on the Monday giving us enough time to go around the offices testing everything.</p>
<p>One of the major problems at the moment is that the cabinet layout was poorly planned in the first place, all the switches are located at the top of the cabinets, meaning the floor ports at the bottom need long cables to reach the top, which results in lots of slack which needs to be dealt with! So first on the agenda will be to move all the patch rails around in order for the switches to be distributed evenly across the cabinet (top, middle, bottom) meaning that you should never need more than a meter cable to reach a switch, with most of the cables being 0.5meter.</p>
<p><a href="http://linkstate.files.wordpress.com/2011/04/013.jpg"><img class="alignleft size-medium wp-image-69" title="013" src="http://linkstate.files.wordpress.com/2011/04/013.jpg?w=225&#038;h=300" alt="" width="225" height="300" /></a>We have done a &#8220;test run&#8221; of sorts on a single cabinet, I don&#8217;t have any before pictures, but the after picture should give you an idea of the look we are going for!</p>
<p>We are going to set up a webcam on a 10 second time lapse to capture the action as it happens, and obviously lots of photos will be taken over the weekend so there is an everlasting record of our Big Weekend.</p>
<p><P><BR><BR><BR><BR><BR><BR><BR><BR><BR><BR>More to come<BR>But in the mean time, here are some pictures for your viewing pleasure&#8230;.sorry about the quality, but what do you want from a blackberry!!!!</p>
<p><a href="http://linkstate.files.wordpress.com/2011/04/001.jpg"><img class="alignnone size-thumbnail wp-image-73" title="001" src="http://linkstate.files.wordpress.com/2011/04/001.jpg?w=112&#038;h=150" alt="" width="112" height="150" /></a><a href="http://linkstate.files.wordpress.com/2011/04/002.jpg"><img class="alignnone size-thumbnail wp-image-74" title="002" src="http://linkstate.files.wordpress.com/2011/04/002.jpg?w=112&#038;h=150" alt="" width="112" height="150" /></a><a href="http://linkstate.files.wordpress.com/2011/04/004.jpg"><img class="alignnone size-thumbnail wp-image-76" title="004" src="http://linkstate.files.wordpress.com/2011/04/004.jpg?w=112&#038;h=150" alt="" width="112" height="150" /></a><a href="http://linkstate.files.wordpress.com/2011/04/006.jpg"><img class="alignnone size-thumbnail wp-image-77" title="006" src="http://linkstate.files.wordpress.com/2011/04/006.jpg?w=112&#038;h=150" alt="" width="112" height="150" /></a><a href="http://linkstate.files.wordpress.com/2011/04/007.jpg"><img class="alignnone size-thumbnail wp-image-78" title="007" src="http://linkstate.files.wordpress.com/2011/04/007.jpg?w=112&#038;h=150" alt="" width="112" height="150" /></a><a href="http://linkstate.files.wordpress.com/2011/04/008.jpg"><img class="alignnone size-thumbnail wp-image-79" title="008" src="http://linkstate.files.wordpress.com/2011/04/008.jpg?w=112&#038;h=150" alt="" width="112" height="150" /></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/linkstate.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/linkstate.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/linkstate.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/linkstate.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/linkstate.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/linkstate.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/linkstate.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/linkstate.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/linkstate.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/linkstate.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/linkstate.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/linkstate.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/linkstate.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/linkstate.wordpress.com/66/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=linkstate.wordpress.com&amp;blog=21547659&amp;post=66&amp;subd=linkstate&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://linkstate.wordpress.com/2011/04/19/recabling-project/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/acc3b04b131de4577956673f74cd7ca4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rekordze</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/04/005.jpg?w=225" medium="image">
			<media:title type="html">005</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/04/013.jpg?w=225" medium="image">
			<media:title type="html">013</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/04/001.jpg?w=112" medium="image">
			<media:title type="html">001</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/04/002.jpg?w=112" medium="image">
			<media:title type="html">002</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/04/004.jpg?w=112" medium="image">
			<media:title type="html">004</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/04/006.jpg?w=112" medium="image">
			<media:title type="html">006</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/04/007.jpg?w=112" medium="image">
			<media:title type="html">007</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/04/008.jpg?w=112" medium="image">
			<media:title type="html">008</media:title>
		</media:content>
	</item>
		<item>
		<title>Using Active Directory for Radius Authentication</title>
		<link>http://linkstate.wordpress.com/2011/03/31/using-active-directory-for-radius-authentication/</link>
		<comments>http://linkstate.wordpress.com/2011/03/31/using-active-directory-for-radius-authentication/#comments</comments>
		<pubDate>Thu, 31 Mar 2011 11:37:49 +0000</pubDate>
		<dc:creator>Jamie</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[AAA]]></category>
		<category><![CDATA[Radius]]></category>

		<guid isPermaLink="false">http://linkstate.wordpress.com/?p=44</guid>
		<description><![CDATA[When i started at my current job about 12 months ago, there was no means of centralized authentication. All the equipment used generic logins, and every device was different, so you need a spreadsheet of logins just to do the simplest of tasks! My initial idea was to deploy a TACACS+ server, but no one [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=linkstate.wordpress.com&amp;blog=21547659&amp;post=44&amp;subd=linkstate&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>When i started at my current job about 12 months ago, there was no means of centralized authentication. All the equipment used generic logins, and every device was different, so you need a spreadsheet of logins just to do the simplest of tasks!</p>
<p>My initial idea was to deploy a TACACS+ server, but no one wanted to spend on Cisco&#8217;s ACS and I couldn&#8217;t find a decent free one, so i looked at using Radius with Active Directory.</p>
<p>It turns out it&#8217;s actually quite easy to set up and administer!</p>
<p>Firstly, if you have more than 50 devices, you will need Windows Server Enterprise or Datacentre (2k3 or 2k8), or several servers, because Server Standard only supports 50 radius clients.</p>
<p><span id="more-44"></span>To start with you need to install he radius service on Windows, in 2003 this is called IAS (Internet Authentication Service) in 2008 this is called NPS (Network Policy Service). I&#8217;m not going to go over the install of this here as it&#8217;s quite simple, but follow the links below for more info</p>
<p>2003 &#8211; <a title="http://technet.microsoft.com/en-us/library/cc781690%28WS.10%29.aspx" href="http://technet.microsoft.com/en-us/library/cc781690%28WS.10%29.aspx" target="_blank">http://technet.microsoft.com/en-us/library/cc781690%28WS.10%29.aspx</a><br />
2008 &#8211; <a title="http://technet.microsoft.com/en-us/library/cc725922%28WS.10%29.aspx" href="http://technet.microsoft.com/en-us/library/cc725922%28WS.10%29.aspx" target="_blank">http://technet.microsoft.com/en-us/library/cc725922%28WS.10%29.aspx</a></p>
<p>Next you need to set up the Radius Policy, at the moment i have only done this in 2003 as this i what i had when i set it up, i indent to move it over to 2008 once our Windows team have built the server for me!!! but i believe the process is pretty similar.</p>
<p>First Step, open us the IAS MMC, and right-click on the Remote Access Policies branch and select &#8220;New Remote Access Policy&#8221; you should get the below window;</p>
<p>&nbsp;</p>
<p><img src="image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAgQAAAGYCAIAAACyLG1kAAAa9ElEQVR4nO3dO27cyL4H4A4n7CWMgbOAcTihtYMzOxg4PDiBoB0YCgWvwHB2wnN3IC9BDi5Q4cwStATegNdtivVg8dXNZn9/fDBabLJYVWzVr6mHdfj93/8B4MYdLt4DAC5OGAAgDAAQBgD8LgwA+L0QBuF/XwDYpbsPdyPCoFFKKbW7evz0ODoMLh5fACxrYhj88o9/AbAPwgAAYQCwL6O+T3D34a49ShgA7Er9t3Xb1b89ShjsQZvwF+/GLnsLV+cyYdD7xJ75Sd67f1lpmsa2vGp/FpmN0w6T+9k9MPl4wRkQBrCqbhgcDofD4dANgO6W5cOgu3bMHENySVp2mq4rDGq6Pb97g2Fw2UsA1Gve3hl0V/9eNqwSBqf3j8ntv6TeY8aLQmEZyjXYO/uoo3Jbkl1aquX6DuRmI9dCebdcazXnih9Ujj33kmhSUw0soom+THTo1IpfJvqlbt0pPOiOobwk5Q6v36F30lwj8Q7lPSvHUnNgfQuLzG1hpGOHHB9b2RSwoCb1PYM4CVYJg1/evitvovplzILVPSq5vby+lHeoaTnuUuF05S3JPsdNFU6d3D/Xt9wwB8+V7HBhyMkP45Em9891AFhEc8E7g9PjypUotyrVLCXJjcnHgxtzLZf7nDyqZkvcZm7L2FEXHpRPnXy28GGyY2PnuTznwEzNpb5n0OvEL0PrYPx4cIdpO49dpModLjRSuWXs/vWjLjwYPG/lBaoce808l/sAzNRc6qeJep04PehWd2P8uHt4eQXpNljTctyH7sZCV0f1p2ZLt8+DPSxMUaGR+rEXXkNxm8lTVI401+1CH4CZGr90RplVGG6BMGCAMIBb0DTN46fHSsIAYJ/uPtyN0h4lDAAQBgDMCQMA9mRiGDRKKaX2UsJAKaWUMFBKKSUMlFJKNcJAKaVUIwyUUuoMdTg0h8NhU//2ShgopdTqtYXVv/dvr4fCQCmlVq8trP7uDJRS6sLVWYW3UO4MlFLqEjX/vfzdh+bp89Pzt+b52/PT5+bdr+/cGSil1JVVZxUeXcfj8fnbc9M0z9+eH+4fnj4/vXx/aZrm458fpzXozkAppS5Tk9+/H4/H19fm5fvLu1/fbH+4f3h9nXV/0KsLh0EisIZ27j5Y5KSTW5jfk/oTLXX4qAannX3tOVHqGquzCo+rL1+/vHx/OR6Pve13H+6apnm4f5jQ5hbvDHoLR3kdKT+7xhnX68Z52o+bGmy8u8O0nqw9P0pdY017//7xz6ZpmrsPiWfbMPjv//x3V3cGuQ/LOy9yxou0cLb2Dz8q+eHg2YWBUktVZxWurafPT03TvL6+Jp99uH9omub52/OoNk9rQPxJut0weNPxt89O2C13xvipXOPxxkJPcs82+QV6VPuF7iVHlPyw8uw1R9V0RqlbrrHv3L98bZqmefneLveJfdpvKT/cP+zqziC3JPUeFx4MPts7Y64nyaZGnXTUxmQHxjY1ONi4aiZ5/vCVUqdqPy1yn5K9+vL1S9M0H//8+HD/8PL9Jd6h/RpR0zR//POPyjbf1ubvDJLb4xUnfpA8tvzsqDOutLGJ1uv57ceDiiv3bKHNmT1R6sar/j37w33TNM2Xr827X9+9/61pmubd258jOh6Pf/3dNE3z+to0TfNwv6M7g/L2eMVJrkHxseVnR51x7Y3LNlWYivpDlu2JUjde7afFoaKapnltl/mmefn+8vr6+vL95e7DXfvs8Xhsf8mg/RGjh/uHdof4x43KJ4k/SfcTBvHjwZYHm1pqY7c/5T7P35gc7Myzz++JUjde9e/Zmx/fCbj7cPfl689g6NaXr83xeGz3f/9bmxk/t+zqzqDpLKA1S0+vnfJ6dHhbNWcsn73QbLyxcNKxI809LszD4JDHjnRwVpVSzcg7g+5vD5ze/jdN094ixDcB7fcYTncPNSeJP0n3+RvIl12PrIZKqV5NuDPobj8ejw/3zevr68v35v1v77vPtj931Px/GFztncHi1U3Xi5xXEiil4uqswkNv2vP/6dC7X991fqL0cPhxT9CWOwOllNp6jbozKL/Hb3/d7MvXL6d7grbcGSil1NarswoPvWmveI///rf38TeW3RkopdTWq/49+8v35unz0+Ce7f1Bt9wZKKXU1quzCg/U0+env/7+a3C3TBhU1h7vDPpD/LFxkZYvcuz1Vv2oJ8zP4cdPu449UF1j7e9y179nv/vQNE3z/rfRdwa9nzK60TuD3sgu/hq6eAe6NbMza4xlchioZJ1/ctY+4/4ud2cVHq7X19fBP1TQC4Oam4lO7fHOoC1hUChhsPsSBtuvUe/Zv3z98vJ93J3Bxz9HtN/+26s9h8Hh7Yh/ZmLm2N6DbiPdA5Mf9p5KnqXcn2SfCzvn+jN255r56U5IeWZGDTZ+tmZ+yg0mhzY4LblGCt3OTVTNEGrmv3zVRu1c6GG5q8nZGDxj98Pk6Q6dGpyrcveSY9lmtd0/1NUf//yjaZryfzfUDYORtwWH27ozyL2qkjsnH+R2621Jvi4LxxbaSTaVPLzmpGN3Huz84JQOTnVyn/IAk41XTkj9KUYNMHmifVziuMHcKQpnzL1gJpxu8uXeYB3GvGc/HA5//Z39Swbtv+2fvmnr458fx7Yfz9xuw6D3+PC24p1rXoKnx912aj4Pky/ZXDs1h3dPGo+r0MPcJMRHJc/VfZCc5AmDLTSVa7w8IfHZB08xaoDJE+3jEie3JOe2sDH3gik0vvjl3mC1s36orvYvFuSePR6P3f/ZtL7ZH5WYuhsKg/KxhZdg3Fqy5dxuybOXe1h/+KiWByehfPbeg9yJxg52cIfCpSl0cmwf6geYPNE+LvHgzrkXQ7kz57/cG6zDyHfu7c8U5Z5t/zZyW0+fx7V8cGeQ2zn37Nhlq/KTbeZCM3jSpXqYe2rw1GMHO+qQwlx1+xbXYB/qB5g8154ucXKkuc+Lms6c/3JvsDqrcFW9+/Vdk//VgfZPGrQ1+HNHqUq8/m8lDJrm52UoH36IXvS9A3tbesfmzhJvL7dTPjzZTqEblZNQ6HzhvDVnKQw2d+pk4+VTJPtcbjA30vJAatovj3pU9wZbbpa4xIMjzU14oSfJwSa7kWykMKjyZG6wDpPeud99aA6Hw/vf3vxOcvt/1Z1qJ3/pTF1XrfQZuEhTi/TtKpaVa6/FL/dVVGcVrq3mx5847n3/oNfymF88/tlG3I4wUFUVvwq3EwbJz5CLNKJqaguX+/w14Z37y/eX9l1/9/sH7eNutXcP7gyUUuoKqrMK19bzt+f2+wHdO4P2cbdG/vXjw6knvXaEgVJKrV4T3rk/f3v+8rV/Z/Bwv0DL7b+9EgZKKbV6dVbh2nq4f3j+9nx4e2fQ+18oXl9fR7X5o9wZKKXUJWrCO/eH+4fnb/07g6fPb5ot/5Zy+d9eCQOllFq9OqtwbT3cP7Rv/Lt3Br2fK21vHcaXOwOllLpETXjnfsqA7p3B87c3zdb8TbTcv70SBkoptXp1VuHa6oTBzzuD3p8+bn8RYXy5M1BKqUvUhHfu7f9I8fT56Y9//myh2+aEv2HQ/bdXwkAppVavzio8otpvG7QtHI/HNh7a+vjnx7GtdcqdgVJKXaImv38/Ho8P983r6+vra/Pf//lv29rMe4L2314JA6WUWr06q/CUOh6PD/cPf/39VzP3nuBw6kmvh8JAKaVWr5nv4k//vv9tmXbcGSil1AWqswpvodwZKKXUJWqpO4MF/+2VMFBKqdVrC6t/799eD4WBUkqtXltY/d0ZKKWUGihhoJRSShgopZQSBkoppZo5YfD46RGAHZgVBhdOMaWUUsvV9DAAYE+EAQDCAABhAEAQBgAEYQBAEAYABGEAQBAGAARhAEAQBgAEYQBAEAYABGEAQBAGAARhAEAQBgAEYQBAuK4wOBwOhQ+XapbJ8zZ/JtsW6ts5/KiLzwZcO2Gw3TBYY7Wd38jp8DXmbVSb3Z03exHhWgiD7a4jwuBsgwJ2Ega9LxcUHsSHdPdJfs0h2VrydIVOVjYS9yfuc7m38YHJYRZmMjk5cePJDudOkWszNwmVlzU37cBYVxYGvTpt7+4Tikvw4CGFnXN71h8b7xDyq2phyVuqtzNnI3muOXOebGdUy8A0VxYGyQ9r1pTLhkFureym2qhVu3DG+NnCiebPRvKo5Oo8JwxGDR+YQBhcJgzqV8bKIdfsWbNlkTCYfBZhAJeyzzDIbUxuqVzIKt8R15yrsgPTVsNR0RUfMj8Mcjk0JwzKMwzMt4cwCJ0vhuSeTbbWOypupHDq+HSDS22uz+W1L9daubf1k5Psfzw5cR8Ki3vywGSb8SUoj7E8vcBk1xQGF3RrK84a412kzVu7EHA2wmBA7t3xvm0wDG7zQsDZCAMAhAEAwgCAIAwACMIAgCAMAAjCAIAgDAAIwgCAIAwACMIAgCAMAAjCAIAgDAAIwgCAIAwACMIAgHALYfD46fHk4p0B2KY9h0EbAHcf7k5EAkDSbsPgFANNp05bkof0/sTunL+4e/E//r7XPxdcP64JM9AeMvlAzNJV23kYNFEVhjA/DE6HXPx1v2CwLdvI2Vo+25p+8WsNi9hnGOSSoJwHwmBUm+v19lJtCgNumTD4qbCAHg6H+MN4FThtPP1beVTyQbeR7oHJD3tPxWPJHZ7brXyi5BQVOjBq3spjzzWV27MwM8lDCvNcaLlyxmrmf/ASdCenvL0wxkIHRvWn/mWTmyU2Qhj8FH+SJx/0Xve5Q6YdlTsk/jDebdQpBveJ98x1oHKYi0x1zVkGZ6+m8cL+9XNbXu8m97AwUTUTWDmQyv7kWsv1rfIVwvkJg58GPzlPj7uVPCT3aVM4qmY9ijtQPmlNxwpDzp2oMEWD7VfOW3k9Si4i5d5WLm2FU1SuoblT1E9CTZ9zE1U5gfVnzPW80Fr59Vk+BRe0zzAIK3wDObcWDO5TWBfiHZLrUe7zp3K3yn0GhzkzDEZ1b2wYDE74RsKgcn7qr/WyYbDGC0AYXIs9h0H7oJcEhSFMXqEKh9QclXt27KI2MwxGrSPxIYuEQbepQh9GrUH1V6R8il7fxl70sZNQea0XDIMJxwqDPdltGIQfMVDe0nPoVLw93i3ZQsi84gePivdPdqm3Jdmx8ppV6EZ5mMlmu90odKC+e4X9C6MoTEvu1MnGy6cYvHbJ3tZPQk0Pky+Swg65LuU6MKE/yTMW+pYcPpe15zBoxXcGrGf+Z/jg4nupji3bH9ia/YdBpUOmLt6x6zJnxuIJ304YeDGwe8IAAGEAgDAAIAgDAIIwACAIAwCCMAAgCAMAgjAAIAgDAIIwACAIAwCCMAAg3EIYPH56PLl4ZwC2ac9h0AbA3Ye7E5EAkLTbMDjFQPeP25y25I7yZwziCQn+qAvcgJ2HQRNVYQiVf2NrUyvj2p3Z1GCB9ewzDHpJ0L7ZH8yDyoVvU+ujMAAWsf8w6P4Ny2lhEP8R8MJfZzx9XaXwFaf6p5I3K7nOJPvZ7U/uXL2zxB0onKI8dcC1EAZvJBfH3uPkqlrYp7BQ1oRKbkvyw/JTk09X2Rngeu0/DOq/TNQVvxfuvsvO7RzqwiD5lryy5fqNq4ZBuWXg6uwzDMKkbyB3FZa5mWFQ+VR55/JCLwyAsfYcBu2DXhIUhjD2HXdy56XCIF7QN/hlom7HgKu22zAIP2KgvKUn99Wb3sbcV35CZ91MNtVrMNdO71y5YOh1pndsTRjkTleInMGpAK7RnsOgFd8ZnMFVLJGLdPIqRgoM2n8YVDqkak5rFx/R2p30BSLYE2EAgDAAQBgAEIQBAEEYABCEAQBBGAAQhAEAQRgAEIQBAEEYABCEAQBBGAAQhAEAQRgAEIQBAEEYABCEAQBBGAAQhAEAQRgAEIQBAEEYABCEAQBBGAAQhAEAQRgAEIQBAEEYABCEAQBBGAAQhAEAQRgAEIQBAEEYABCEAQBBGAAQriIMDm/r4lM2cywbaWGRmYwb2VT3gHpXEAatq14dTp2vGUV5n6XmYU47o4Zzzo4BkwmDs3ZeGKzaMWCyaw2D3nqU/DpS4StLuae6reV27n5Yecbu/pXt5zqc7EbywFyzo2Zs7HDGjiLZz7idZPvneeHBjdhPGPSeirdUNltYbuJ1qvKMySVysP1ka4Pjnb9DYaSDw6k8cPCkY7sEzLTnMEi+Dz3tk3wquaD3di6EwWCzo9ov9Cp5rmTjM2csueYWzlh5YLkbyWcLpwbm23MY1DQ1GAY16139GUe1X9mrwRPNnLHKFTnX7LTpFQZwZtcaBiH/JZfBVekMYVCOrsr25/Rqzg6FkVYOZ/DAwZMWprR73YGlXHcYdB+fKt6YbC35bGH1Oe2cC4PBM1a2nxtsvE9yvLnhx2FQM2Njh1NesmtOmmwnOW/JiQKmuZowiFkUrs4il8m1hjVcZRjE7zotEFdh5mXK3aYA811lGACwLGEAgDAAQBgAEIQBAEEYABCEAQBBGAAQhAEAQRgAEIQBAEEYABCEAQBBGAAQhAEAQRgAEIQBAEEYABCEAQBBGAAQhAEAQRgAEIQBAEEYABCEAQBBGAAQhAEAQRgAEIQBAEEYbM3jp0eA1jnX20dhsCnt9QA483p7BWFweFuF3U7/Xq/2ejRKqZuvM6+31xEGhQ8Ht1+XUxj88o9/7c/hcLjwp5dS11NnXm+FwbYIA6VUW2deb684DHpfOOp9mSj5bK613heg4mNPHw7uuWwYdF8Zpy1LLc1x46OOFQZKrVrCIBEG8fcMeity8t/42WQYFJby3LG5syx1PZqmiRfcZunbhW6DizcuDJSaWWdeb68jDMoby2GQXMcL7YS38ZM8tnuX0EupRa5HkwqDxTUrh40wUGpOnXm9FQbZe4h4S+HOYNnr0eTDoHn7FaTu9sEt9WHQO7aJ7iGa6AtZgz0RBkqNqjOvt/sPg977/cp2klsu+2Wi3FpcXqwLb/mbTBjUtFZ/3m6zwkCp+jrzenutYXBa3HMLdPzVm8pQ6R5bDoNcH+Zfj6buzqCw3JefHQyDblWG0OCx7gyUGlVnXm+vIAyWssZXdVa6Hk1FGOSCYZEwyO3cVIRB4VzCQKn6OvN6u/UwOKRqWiMXWdynXY8m/9NEzdCinNtSmSujHo/a0vgykVJj6szr7dbD4NbU/55Bd2N3z8KWOAxy+yS3N6lgqDnv6UNhoFR9nXm9FQbb4jeQlVJtnXm9FQbbslIYxK8zYaDUxuvM660w2Bb/a6lSqq0zr7fCYFuEgVKqrTOvt8JgW4SBUqqtM6+3wmBbhIFSqq0zr7fCYFuEgVKqrTOvt8JgWx4/PV68D8BGCIPbddl3IkqprdXZFh9hAIAwAEAYABCEAQBBGAAQhMGmzPyzDTXtr7T/zN6u/dcmav5M6Wmf+BL0dt7I38bYSDfYDWGwIedZExfcf+bf+5z2d4omn6gyDJIb1/h719PIAFYiDDZkU2GQXBxzDV5dGIRMNggDbpYw2JDk53m8TsVfxDh9mNxe00LuvLlFsHe63KIZnyXuYaFjucHmdh48dW62B8OgsE99z+P+D05aYQbKVzPZyKhXI7dGGGzIoVPdjb0HvafiHeK1L7moJduMtyc7kFyPBs+e26emY4UVubDM5QZeGGN8FQbDoDAz5eFXXrJRkzaq53AiDDaksDTH7/KS7xC7DwphkEydXE8qwyB+KtfP3OHJzhQGWxhF8qjcIp4cbHI2yu2UJ7ByS2HSRl3lwrWDJGGwIYWledSKPBgGNT2Jl9qxYVAYXWUYVJ6x8qj5YdC7FoWjJodBfcujwqDyunPLhMGGjH1bOj8MBte+3IlGhUFlzycckuzwqBQsHJtrcI2l//yTBj3CYEPK78d7a3FhRT5tLzSV3J78MD4wea7czuXlOxkz8eJbM4rcTCY7mRvsnH1yPc8Nv2bSclsmzHPuckNLGOyWz3mgnjDYLWEA1BMGAAgDAIQBAEEYABCEAQBBGAAQhAEAQRgAEIQBAEEYABCEAQBBGAAQhAEAQRgAEIQBAEEYABCEAQBBGAAQhAEAQRgAEIQBAEEYABCEAQBBGAAQhAEAQRgAEIQBAEEYABCEAQBBGAAQhAEAQRgAEIQBAEEYABCEAQBBGAAQhAEAQRgAEIQBAEEYABCEAQBBGAAQhAEAQRgAEIQBAEEYABCEAQBBGAAQhAEAQRgAEIQBAEEYABCEAQBBGAAQhAEAQRgAEIQBAEEYABCEAQBBGAAQhAEAQRgAEIQBAEEYABAmh8Hjp0cAduC0qk8Jg0YppdReanoYALAnwgAAYQCAMAAgCAMAgjAAIAgDAIIwACAIAwCCMAAgCAMAgjAAIAgDqHSR/z7sbHX34e6w97rx6zv4ChcGUGXHr/x2FTgcDpdestaqdnQ3fn0rdxMGMGDHr/xuGFy8M+uNrrzbLsfenYHK3YQBDNjxK18YhBu4vpW7CQMYsONXvjAIN3B9K3cTBjBgx698YRBu4PpW7iYMYMB6r/z6n3iJD1ykAwuGQa9LS/VwkdGVd1vk+k6+lGMndsIMVO4mDGDAqmGQfDzqwDmWDYNpw1kvNs4WBqsGoTCArVjqlR9/VguDwWlZZHTl3RYPg2UJA9iKpb6MUN7Yexyvrd0t8YNpFv8yUbJj5c4nv7SyyPJ68TBIDrx8ZQvTNXkGKncTBjDgDItFYYeQyox4+zRnCINc5wdHseDoyrud4c4gjoHyla2Zn/oZqNxNGMCAma/8wifz4J1Bbjko5Mcoa3wDOV7x48yrfOe71H1PebezhX3NQh9PlzCArVh1sYgfVy4ZhWbrrfTTRINrfU0YXPudwbR3/TVbxs5A5W7CAAac+XsGoxaRpd47nycMkp0fnJn5oyvvttJPE40Ng/rAGDsDlbsJAxiw6k8T9b5+ktsef1hott55fs8g1/lcpC2SBGEDv2fQ25jL/txRS13fyt2EAQzY8SvfbyCHG7i+lbsJAxiw0iv/kKozD22pMEiO5fzDyY2uvNuOVzZhAEva8SvfnUG4getbuZswgAE7fuULg3AD17dyN2EAA3b8yhcG4Qaub+VuwgAG7PiV3w2Dx0+P+yMMhAEsZq8LZXe5vPtwt1c1YXDxq7Dq9R18hT8KA6hx8eXsDMvlvuvGr+/gK1wYACAMABAGAARhAEAQBgAEYQBAEAYABGEAQBAGAARhAEAQBgCECWFw8f9xCYA1jAiDi/9fSwCspzYMALgdwgAAYQCAMADgd2EAwO///s//AX5wU9BBAPt4AAAAAElFTkSuQmCC" alt="" /></p>
<p><a href="http://linkstate.files.wordpress.com/2011/03/ias_011.jpg"><img class="alignleft size-medium wp-image-49" title="IAS_01" src="http://linkstate.files.wordpress.com/2011/03/ias_011.jpg?w=300&#038;h=237" alt="" width="300" height="237" /></a>Select &#8220;Setup a Customer Policy&#8221; and give it a name, press Next..</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a href="http://linkstate.files.wordpress.com/2011/03/ias_02.jpg"><img class="alignleft size-medium wp-image-50" title="IAS_02" src="http://linkstate.files.wordpress.com/2011/03/ias_02.jpg?w=300&#038;h=239" alt="" width="300" height="239" /></a>Next you will need to set &#8220;Policy Conditions&#8221; &#8211; these are what defines which users can access the devices. We are going to be using an Active Directory group to grant access, so members of this group will be allowed to login. Click Add and look for &#8220;Windows-Groups&#8221; (usually the last on the list) From here you can choose you group, it can be a local group on the server or an Active Directory group. Once you have selected your group it should look like this;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>At the next window, you will define if this policy Grants or Deny&#8217;s access, the default is Deny, so make sure you change it! Next you will be asked to edit the Profile, this is where the magic happens! There are several changes you need to make in order for Radius to work.</p>
<p>&nbsp;</p>
<p><a href="http://linkstate.files.wordpress.com/2011/03/ias_03.jpg"><img class="alignleft size-medium wp-image-51" title="IAS_03" src="http://linkstate.files.wordpress.com/2011/03/ias_03.jpg?w=260&#038;h=300" alt="" width="260" height="300" /></a>1) Select Authentication, Select &#8220;unencrypted authentication&#8221;, uncheck  everything else (Cisco on seems to support PAP, if anyone has a way to  make it support CHAP, please let me know!!)</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><a href="http://linkstate.files.wordpress.com/2011/03/ias_04.jpg"><img class="alignleft size-medium wp-image-52" title="IAS_04" src="http://linkstate.files.wordpress.com/2011/03/ias_04.jpg?w=300&#038;h=274" alt="" width="300" height="274" /></a>2) Go to the Advanced Tab, and remote the two attributes that are there  by default. Now click &#8220;Add&#8221; and select &#8220;Vendor-Specific&#8221; from the list,  click &#8220;Add&#8221; again on the window that pops up (This should be the  &#8220;Multivalued Attribute Information&#8221; windows) Select &#8220;Cisco&#8221; from the  drop down list, and say select &#8220;Yes, it conforms&#8221;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><img src="image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAfoAAAHRCAIAAAANHOzrAAAgAElEQVR4nO2dS5LjOnAAtXwH8SW8nL6Ow5eY0FV8nbdxBK/TXmiGRuNTLIAFoEAkI6NDggofFskkG6Kk13/+9/8AAMDjeU0fAQAADADdAwBsAboHANgCdA8AsAXoHgBgC9A9AMAWoHsAgC1A9y0c//svAMASfP36Qve3dP/NwsLC4n55/36jewPdTz9pAwDIoHsz3b9/vwEAfILu0T0AbAG6R/cAMI2qmfevX193aqF7dA8A09C/7ff+/Q5131AL3bvQ/blh7nOzKcORTGlf0zsnZvBDKu5XsKB7d0S6zwpFtsz5ahTW4KZOuk9FWTXU0gparUi0f/fITFsCObuATCTu0PKR8d8F3acnhrDkje4H6D495m1teNmUbfWbum8YXu2KXMZP0T2AzH3d62uh+466Dw2eFXpaWArO1krj26pEhamthDY1Iy+toDA8YdXkE5KwOpetZcecXcds3oS0aIKzKwWPpzQtUzuZo5kCOp+ie0vdvyvFnX31slZIbUc3GxeGGj61GlXVIGtXM7W5Mv4yRfczD48nq/vU2pe619RC9710/25S26XjBKvqxar0WjoMIVL59Kbus0kQsq0ZvD758kaRG6kaEuyDle65up+s+5Aeutc3VWpfaCd6Ve81+elN3QuHzXjdVzWC7iGLyY2YzN0/Tffy0966l1dE/xTda4YE+3D/6p47c/zq/nwcbsXsq2+F8pRNtRVmOy0NVTnyUkfyqJSDbBCxINzSS/pkCsFys7APhnP3Wd7ovqvuAQCU8KnaxUD3ANDG5zvolYS6b6iF7tE9AEzj69dXFXdqoXt0DwBbgO7RPQBsAbq31D0AgGfQPboHgC1A9+geALYA3aN7ANgCdI/uAWAL0D26B4AtQPfoHgC2AN2jewDYAnSP7gFgC9A9ugeALUD36B4AtgDdo3sA2AJ0j+4BYAvQPboHgC1A9xN0n/4QpRypjwcAKIHu5+v+fFrSukb3nBIAQAbdj9Z9esGO7gFgAOjehe7PwvTB+fQsTKuHVcL4Utdp79m6l5HTd18A0IPuh+pevqgvPcjKvVSS7eJ8Ksi61I7w7wgALAS6f6Du0/8G5N6jK/rSGErNAsASoPvRuk+l2e/qPu29oZ00EgBWBN2P033t/EkakK1SNZlTaudyMEzmAKyOVvfTBwoAe/L162v6GJ5Bhe6/WVhYWMYuH0NNF+UzqNP99OECwFage/NkVuj+n//4LwCAAaB7dA8AW4Du0T0ATKNq5v3r19edWuge3QPANPTv4X3kcqfWge5Nma/7z/l8+k5cGtiUsc3NycQVB/+k4i593NpQ9+/fb5DRZLhR96EObqrBpLqVoc5G2lYwHYb8VNO7YfY0iRoj+qq0gCsirUSfDw+NX9J99us9zpKs7kHm0N05ubbu+2mireWbum/ovXacl/FTdA8LcV/3+loHkzlqJug+vX78/rmEO40cHDWetUPWGpoeS4XRg6iw1Eg61FK80F2292wqSpGXIxTGlhYqt0jaSNr75SA1PQorBSP5LmildjJHMwV0oHsPuv9HFME/ovsaCkvHeVYEbT22xevrCk/Tis2rIHQtB1wOPgrQx1+mqG3FYRbfOa1kvyf1cu7+staB7p3rXqODtkJNp3I7QmTDYNLDQKhb9dQkP9nRlsZ2OXi5R83jcEj3Vxxm8W2ke67ubclul+wWsb+6j8Kix22Fl3thbTtpYfNgvnNLWkX5tDk/l+nKNnLZi7LH+8OuGhJM4dviRkzm7s3RbJdbN2JqXNOmgJIX5L2wtp20sHkwGn/pnzbn5zJd2UYue1H2eH/YVUOCKXzfvrpvuDNnukz9k90u2S1io/uz5Fz+udJBGBkVlrqQuysVKnusGraQimyV9GmpVtsqyKsvrGxpxTVbpPTS5ZDkkWiahSl8283dC0r61DrQvR/d+wQjAPSjTdzovjfoHgCM+f7+1n/UM9R9Qy10j+4BYBq1H/i8Uwvdo3sA2AJ0j+4BYAvQ/WTdAwAMA90rQfcAsDboXgm6B4C1QfdK0D0ArA26V4LuAWBt0L0SdA8Aa4PulaB7AFgbdK8E3QPA2qB7JegeANbmY6hvFsWiTCa6BwCPcHVvnkx0DwAeQffmyUT3AOARdG+eTHQPAB5B9+bJRPcA4BF0b57MLrpPf7tSjtTHA8AmoHvzZI7Q/fm0pHWN7jklAGwFujdPpr3u0wt2dA8AtaB782QO0v1ZmD44n56FafWwShhf6jrtPVv3MnL6RgLYFnRvnkxj3csX9aUHWbmXSrJdnE8FWZfaEf4dAYBZoHvzZC6p+/S/Abn36Iq+NIZSswAwHnRvnkx73afS7Hd1n/be0E4aCQDTQffmybTUfe38SRqQrVI1mVNq53IwTOYAuALdmydzhO7TB8JESlhXEHR2yuXOZE7aLNIHmAi6N08mn6oFAI+ge/NkonsA8Ai6N08mugcAj6B782SiewDwCLo3Tya6BwCPoHvzZKJ7APAIujdPpqXu37/fAACX6H9Ne7oon8G7h+6/fn0BAAgolYLuDeml++krBgDOQfeDQfcAMAd0Pxh0DwBzQPeD6ah7+dts9FTVsvruYr4pE6A36H4wj9K9+fdZYnmAfqD7wfSdzDHxb5vuTUD3AP3Q6376PaP+0SdztO6zXzKc/erjKCx9GnadtbPwvcr6IV1+6zIA1KI3FBje1TpU92lh1rNpjFASvpR6vKqpsORyVADQDJM5U5LZ8c6crCijK+47Rj5+ni2imFJFYQClLrJhANAMup+SzNG6j6rc1H0WWffCALKR6B7AHHQ/JZl977uPLHlf7hprK3XPZA7ALND9lGQO1f0h/h5sNEUThZVqlVrOtiOHhY2nfaUVAaANdD8lmU/+VC1qBvAJup+STHQPAKNB91OS+WTdA4BP0P2UZKJ7ABgNup+STHQPAKNB91OSie4BYDTofkoy0T0AjAbdT0mmse6nrzkA+AfdT0mmpe6/WVhYWHSL0lDTZeoffTItdQ8AYAW6V4LuAWBt0L0SdA8Aa4PulaB7AFgbdK8E3QPA2qB7JegeANYG3StB9wCwNh9DzbhHdL1FmUx0DwAe4erePJnoHgA8gu7Nk4nuAcAj6N48megeADyC7s2Tie4BwCPo3jyZ6B4APILuzZNpr/vX3+Xm+M4W5v7COL9vTq5gCujePJnGug8PeJODf3ojKIxcwRTQvXkyO+reBHS/EOQKDEH35skcoftXsKSFpZLPg7OkNLcThZWaKjUSxWiqZFfNpKT0VA4TxqxZwey2E2oJw9D3BXAJujdP5oi5+/SxviTr5bQ7ZeOlB5dVLm1Vu16avko61q+mchhVtfTD0GcPIAXdmyez4505sn2iS8KSfTS61zeenkg06hRspVyLUhXNSgkrK/SeXQt5qLW10D10Bd2bJ3Oa7kvBpcgq3csjqdV9ts2b6yW3pgmTWy5lT26/qha6h66ge/Nkjrgz544j0uvZyx41JfoRdnWffGopnQCUVpXXWnPWMV9BAD3o3jyZg+buhcJSiWzqbGFYN21ciC/1fjmAdNUa1vQsKT2Vwy5PD5rghlrpKpeScNkpQAq6N0/miE/VWh3kyAJgH9C9eTLX0H3pahcAngq6N0/mCN0DANSC7s2Tie4BwCPo3jyZ6B4APILuzZOJ7uHf9+83wACqTPJG96bHOLqHf4+/uwJAV45Kk6B782Mc3cOfXeGbhaVmqdrH0P1c0D38Ad2zNCzH//6rjDzF/Y3upx7j6B7QPUvLcqjNgO6ng+7hD+iepWE50P06dNR9+F789PWES1Ldh1+Dc5YM9wmL6+VA9+vQRfcfxYdvxyN9/0S6j8yO6FmyyzFE99NvHvWPJqv2uj9FH+4TZ0mpVvr1kNmYOzoz+dIek3Z8IuuehSW7HIEZXrkl2sGOJt2DjDKrvXQv7xZZjaaPhTCZNNLE0SZjc4tG9+GsThgQzflkS1geuRw/j+uS6w8mczqjyaqx7lNlhAd8qRGlK9F9V/S6j6byI8tnS1ieuhzJQV36Tx3dd0WT1Y66T9/oKzVScmW037wKv5uRjYzaPEvSsOzT7P76+jmZk+1xXe/XXt0Lkeh+nyV7UGePAnTfFU1WXej+EH956vjp2VJ5qSRqLX2Q1srGlIaxuuWz2+77SvffBfULYSyPXJRmONB9ZzRZdTGZE5Jea0cXzqXybCPZZtOYBt1nW1gazZ05LyZzWH4uSjMc6L4zmqy6eKs2pKTao3wdPUv38miXI91w6f9n4YPI6ZclLI9clMf1ge47o8lqF92f3Yf7hNDCpUCZzBlA6TzNwiIswnGd3cH08VEtkNFk1V73x1/RyyUR4eRMqTB8EAVnS6Km0nKhfaGRaBilV5cD3bM0LHozoPuuaLLaRfdn9+E+Ac5B9ywNy1Hzwzjovh+arHbUvZJXbpmeuw1B9ywNS6fPf0a75fSjwz+arM7XPTjhzZcawRDQ/aysonv4w8xLRJbNFv1uie71x68ymegeADyC7pWgewBYG3SvBN0DwNqgeyXoHgDWBt0rQfcAsDboXgm6B4C1QfdK0D0ArA26V4LuAWBt0L0SdA8VVP3sPUAzDR+zGvwpsEUXZTLRPfzZFQC6cvAlCrOPcXQPHFcwCHQ/C3QPf+C4gjGg+1mge/gDxxWMAd3PAt3DHziuYAzofhYddR++Fz99PeESjisYA7qfRRfdfxQfvh2P9P3DcQVjQPezsNf9KfrwhtCzJFvF/JcL00bamq2qVbsK3n6jkeMKxoDuZ9FL99mPAAi617Ss9+N43UeRmoroHvYE3c/CWPfyR+BKjfS4HA6Dm8V65wTTo0pXOK5gDOh+Fn51/ykM50bSx9mX0jajx1HFtHo6LVPVXVTe0PjEXWFK17AV6H4WXnRf0uL5+Ag8mKpcnr2RK5Z6UZakLQtj0JTM3RUmDgA2Ad3Pwovu5cJU99EZQmihdGXdJvceus+e7WbtChMHAJuA7mfh961aWff6FuTLZw+6n74ThBtu+jDg8aD7WXTR/edB5HqhhTu6l6UZld+Xu1L3dxqfBccVjAHdz6LLx6xCxZdKQrITGlkPpvM5aXDUcqkvuZc07LK77JyMUFK7LmN2hSldw1ag+1l0/BKF9OoePMNxBWNA97OY/xVpr9wyPS8bwnEFY0D3s5ive3ACxxWMAd3PAt3DHziuYAzofhboHv7AV5bCGND9LNA9/KH04TgWFvNFv1uie0PQPQD4Bd2bJxPdA4BH0L15MtE9AHgE3ZsnE90DgEfQvXky0T0AeATdmycT3QOAR9C9eTLRPQB45GOo9++3zKWd5t10OmJRnhHRPQD45WMomUNhpwfrS/8PELoHAL/IP5D3WQ50j+4BYHWULkP3+kh0DwAeQfdWKTrQPQB4Bt1bpehA9wDgmVm6T78g1uorY6N27jeL7gHgCUzUfVRFc7tnQ8v3m0X3APAEJuo+vO5W3t2vbBndAwDEzNX9WSv79DwfRCeGbEwYkNV9+KmxHik60D0AeGbuZM7HvOff08vH34/pRi9FFcOYqOX06edBtopJig50DwCema776O+Rk/sRnBI+fQnf8SDrPhtjkqID3QOAZ6a/VRsaXNZ9GhN99Deqkm0hG2OSogPdA4BnPOi+9CB9fHaUlqctlzpKY0xSdKB7APDMdN0fBYOf76mWHJ2NiV6KzhBClfspOtA9AHhmlu6zVcKSdJYmrZKNiV6KzhZClZspOtA9AHhmou47rU6W48YN+OgeAJ7AW/HzJsc6uj/KP7TSPEh0DwBP4M3Pm+hSpI9E9wDgkTc/b6JLkT4S3QOAR9C9MkX6SHQPAB4x1L38BsDSTNP96+9yczOfLbQ1VVXr5mjvr6zccr/2p6+gee+vn4vcVCmytO+FT4X9vDSGbLkwWtvsNe9LAw5AASvdX74BsDr6ZJrpPtq5DXfWHhWtzihWZ4tSO1XrYk6PlvttHUHQ8tPsY81pQHNSqY2ckvD7VXqsiJXu4eiqexPQfe26mPMY3aeXt5de1otbM4ZL3fcD3cMxRvfyP7alkvPgjI5S5SEaVS910RAcBSirZxOStpNd6zSBqbPSBjVdX6ZdbjkasJCH7DDk0bal95VsozRRl8HZPAvlyjFcjra0vaJVlvMgb1Ah7cLGVe4qmu2bjRdA94aMmLvXHHKlkoYjMN0LLzutCs52fVm9lCt5HWvTJXetbKfUu6ZTTd3a0Val9/VzEdZdMyo5gSVzCWOICoV94+ZuEJVU7Z/KKsKKaPYZJejekI535sibPNr1lftcGpnu0/Leme30zgiV1aOK8jDuHOdC18IqKFvWb53S9rpM3c306hvRBF8m8DKrciqyDcobSM5DqQthjwojhd1Ss6sot528yhHo3pBpui8FlyLlI7D0V9npnREqq2fbUUqzWcr6VahtWa/72tQZpjdqJD1D+Nd9bR6adX+5cdH9AxhxZ06VU6KSqPzyeGvrtHaEDX0Jo72j+zMnVQJt2BA3R67XgWF6L7ddqZ07w1bW0g++bWNFJXeaeobu5RZWXxzdd/8KFk2YcpfKlssHZLZTZXC2d331bIrSxktHWild2VXWdC2nXVg7YdjCYIStJo+2Nr1RSdrCZWJLq5zGXK5aKSfyzpC+KkQqN2hpu8hrmtbNbn1hleVaGvhUrTJF+si+n6qt3cC92wFYkT33f3SvTJE+0rvuS9c+APuw5yGA7pUp0kf21T0AQBvoXpkifSS6BwCPoHtlivSRjnQ/+D/W0rtSho3v+T84gAkDdP/5PSy5pHnw4U9udU2RPnJf3d/v9PKWA03jnBIAsozRffRqWtI8+HOQ/YyP7sd1iu4B+jFG96GLP08NdR8+7ZcifWT3j1llb+a9vOc3fZp2l8YL9/xeDqbUe9ppOrDsg9KqRVkSVry07gA7MEz3Z0D26Wnq6MSQjQkDIt1fNhs9OP8KpwpHur9Um75Wqa+2RiIjy2HCyqYSvzMw5UsAmzBsMifS6yf+8zScjYmUfZZnZ2xKuheajR6cohemgyb/mtXxU1LR5e0dL2f7Kj2Wuy6NttRXWCXbppXuo/YvxwPwYEbqPvp75OR+/Lzu/k5+E7F0OX/knJ72fvw85Zyz/2lrUYr0yeyr+2xANlhZkm2t6h8CebSXV/Tymlpd3csjB9iBkW/VhgaXdZ/GROOJqmRbCAvlv9nWohTpk2n8Vu3lRffNkqjl+81eNqVZnQbdC/8iCO0D7MNg3ZcepI/PNtPytGW5SnSyOXInnmMJ3R/BBEX6anYS47JW1HKphbSRUrNZU0cV0xYu/X4+LQ1D2fVlHgCeykjdHwUdhxPoaZVSTFguvFTqVD7fpCnSJ9PRjZjN4EGA5zFA99lXw5Kwo1KVbExYLrxU6lQoTFOkTya6BwCPjNF9p5Fn6ZQifeQTdA8Az2Nd3R/l31TpkSJ9JLoHAI8srfuRKdJHonsA8Ai6V6ZIH4nuAcAj6F6ZIn0kugcAjxjqvvTe6QNA9wCwPFa6//r19Wz0yUT3AOARK93Dge4BwDPo3jyZ6B4APILuzZOJ7gHAI+jePJnoHgA8gu7NkzlN9+G3Qu7zFwCUoHvzZHbRfddvBQKAHTC87/7By8wbMc87/09K0t/tane39QW4CZ+qVaZIH2mp+1P00cnnU5LGpwZsdmIPmSJogImge2WK9JH2uldukuwvRt3XvZWjzV3PyQOgCnSvTJE+0kz30bb52Pxyq0Q/1Ne82v51DwBVoHtlivSRXXQf/kZraauUfuX1LBR+tTUl+rnX9NVsa+kYsu2kwWF8Wjc7DM4fAFWge2WK9JHTdB8imDE6GZSkKQQIrR0F0ZcaLL2kqQsAVSyhe801qCb4Tor0kdMmc4RpnNfPRZMppe5LXStPMErdj9nSAM8G3StTpI+c9latkIXLS3jhJSe677FpAbbCv+5Te6SvyiUmKdJHGuv+zG+4PbItyFf3pYT2m8zR9HhnMgf7A1SxqO6zMxNRiW2K9JHGH7MKFV8qKWUtm7KoRIhvaE3jdCFYfnB5igIAAee6zzpHcylpniJ9ZJcvUUiv7uVk7cBu6wtwE3SvTJE+sovu9flKlx4dAcBy+Nd9dt4mDMiWmKdIHzlN97uZfbf1BbiJZ92X5pPR/UXK9vkLAHpW1P2x1Vu1AAAmeNa9E9A9ADwBz7p38r4jugeAJ+BZ905A9wDwBNC9MkX6SHQPAB5B98oU6SPRPQB4BN0rU6SPRPcA4BFD3X9+MfuRoHsAWB4r3X9+LvvB6JOJ7gHAI1a6hwPdA4Bn0L15MtE9AHgE3ZsnE90DgEfQvXky0T0AeATdmycT3QOAR9C9eTLRPQB4BN2bJxPdA4BHDD9m9eBl/n334Ye+pu80ALAifImCMkX6SGPdn5/rPUH6ANAAulemSB9pqftT9NH/Gp+SbJXoNwGqfiJAGbzcDwcuN2CAHqB7ZYr0kfa6r9ok0a/AtOlerjXGnla94HqAD+hemSJ9pJnu5W1TagTdTxktgH/QvTJF+sj5uj8K4r78Bcjoh97TV0u/By90UWoqfSnbeGkMQq2orjDg83FYLqcIYF3m6j76nuHp2RBSpI90qnvNJb9wdZ9WryqJGswKWmitagylljXDEzIAsDrTdR925NP4S+r+UMjusm72pbTl46dqs5fbba0JtRraQfewOR50X3rqhPXeqg0fz7q6L9W90xq6B7iDW91HMzzh02jmJ40MX8rGNKRIH2ms+zO/4fYQWnCi+8vJnKrWzMeA7mFDpus+mrv/tHM+/v47w3NO+5wvneXZyLP9sMp303zR5I9ZhYovlYTIYpWnWeRTQnaiJnwqlGg6ytYtjUGzUtkTQDa49ADpw5OYrvuwo/Ri/MPnpfNMED5I5X78PQeEJ4aotYYU6SO7fIlCenUPAFCFB92nT6PTQIPu0yrNwnSheyWvwjJmZwIAz3jW/VmYfUnQ/RFc2mfLG1Kkj5ypewCAEj51f/x8c1W4uk8jSy2nMVUp0keiewDwyFzdpxXDp9Hci/wgjCy1nMboU6SPRPcA4JGJuo/eQb1zr+SAFOkj0T0AeGTu1b3Qox/QPQA8gemTOf5B9wDwBNC9MkX6SHQPAB5B98oU6SPRPQB4xFD3pbdeHwC6B4DlsdJ9+NPZj0SfTHQPAB6x0j0c6B4APIPuzZOJ7gHAI+jePJnoHgA8gu7Nk4nuAcAj6N48megeADyC7s2Tie4BwCPo3jyZNrqXNwlL10V54y3AWhh+zOrBy4T77i8DoBP6j9UBrAVfoqBMkT4S3a8Nuoengu6VKdJHovu1QffwVNC9MkX6SHS/Nugengq6V6ZIH4nu1wbdw1NB98oU6SNn6v4VLLUVz7+26NvsN4Yq0D08Fee6j76IOBtw/u2aIn3kNN1Hoqz1bCdKoyp1qhlM1wGje3gq/nWfDiYNOP5+4X6/FOkjveh+QEVly2H76B5gFkvoXhlwGXwnRfpId7qPpndOBYclkZejSaHU12n1bO/Z6lELUS/pfFRz7723N8BaLKr7cIbnvK4vTfiYpEgf6Uv3l648kivubJVSSfbKXXjp8oFV7wO2N8Ba+Nd9OnH/efwZ26n786/5SB6o+1JJm3DT6/FS15oHVr0P2N4Aa+Ff99FIjtwETvi3U4r0kdvpXhiPMDNjfnU/fnsDrMUSuhcK0f3/k724ttX9Ke7L6ZRUxKWKPXofs70B1gLdK1Okj3R3333p+voQFZzWCoOF9tNe0saF3oVVkIcq99JjewOshX/dl6bvo7dqPwPY+q3aHvSYLXEOuoen4lz3R/LVytnycADmI9lO99nr6zuN3G9tJOgenopn3UeX9p3us1SmSB+5vO43B93DU/Gs+6PwqylTUqSPRPdrg+7hqTjXvQfQ/V6ge3gq6F6ZIn0kul8bdA9PBd0rU6SPNNN99r0LGAC6h0fyttP99IN0+uH/NtT9168vmMj0IxPAHCvdTz88PRz+lroHALDFSvdwoHsA8Ay6N08mugcAj6B782SiewDwCLo3Tya6BwCPoHvzZKJ7APAIujdPJroHAI+ge/NkonsA8Ai6N08mugcAj1x+ZPTzKnbSJxPdA4BH5Kv782SAnfTJRPcA4BH56h7dNyQT3QOAR9C9eTLRPQB45GOo0s+IovuGZKJ7APDIqfus8dF9QzLRPQB4JNR9anx035BMdA8AHol0Hxkf3TckE90DgEe4ujdPJroHAI8wd2+eTHQPAB7hzhzzZKJ7APAI992bJxPdA4BH0L15MtE9AHgE3ZsnE90DgEc+hnr/fpdA97XJRPcA4JGPoWQO7FSTTHQPAB65/L77D9hJn0x0DwAe0fya1fmbVqBJJroHAI8or+5Bn0x0DwAeQffmyUT3AOARdG+eTEvdC7dMAQCcaJTyRvd2vM11r3lThYWFheUb3Y/FXvcAAFage/NkonsA8Ai6N08mugcAj6B782SiewDwCLo3Tya6BwCPoHvzZKJ7APAIujdPJroHAI+ge/NkonsA8Ai6N08mugcAj6B782SiewDwCLo3Tya6BwCPoHvzZKJ7APAIujdPJrqHBXg9fUlXecrXlg1bNB5H94age1iG1+s1W1C9lq9fXyXdT097J5QeR/fmOUf3sAAf3U8fhjmfgxDd3wkDfc7RPSwAun8S6H5WztE9LAC6fxLoflbO0T0sALp/Euh+Vs7RPSxAb91nb5IpPTakt+7lm39utnxzra3CQJ9zdA8L0FX3kbnOp+kDc7rqvrRePZLWsNZWYaDPObqHBZio+36uP8bqvmvSGtbaKgz0OUf3sACzdN/VmMck3UfTO+dZLZq8kkvQ/Vqge1gGdH9/vUoBWfWnMUJJ21pbhYE+5+geFoDJnPvrFZaHl+oalb9+LjfTgu7Hg+5hGXir9v56pYVVutc0XrXWVmGgzzm6hwWYq/s0xorxd+bU6p7JnGeA7mEZuur+UNx3nz41Ycp995eTOWFMWut+NtD9eGKPu6EAAALlSURBVNA9LENv3c+CT9XeDwN9ztE9LAC6fxLoflbO0T0sALp/ElW6f/9+g4xmV0H3sAzo/klU6d70t2QeuyiTie5hAdD9k2AyZ1bO0T0swEf30/9r7gG6vxkG+pyje1iA1+v19evrqZR0P/1U1PUkd7nR0b0h6B6W4fX0JV3l6Seh3lxudHRvCLoHAL+ge/NkonsA8Ai6N08mugcAj6B782SiewDwCLo3Tya6BwCPoHvzZKJ7APAIujdPJroHAI+ge/NkonsA8Mi78jtzSucGsy+mcbkoz4joHgD8UnV1LwQ/WF/6FKF7APALujdMEboHAL+ge8MUoXsA8Au6N0xRhe6nf38eAGwIuh+t++nfnAcA2+JE9/LXl95s2ZHugWkueAZdd9f37/cR3PX4efop//R7BnTqvZ/uIyPbGh/dr0G/fRegB711H7YfWv60f78BjNS9Leh+DbruvgDmzNJ9b9cfk3QfTe98HkQTPukUULaW+VpnI9E9uoddmKj73kfK3Kv7VPRnSRojlBiudTYS3aN72IXpkzlde594da9Xefqjleh+DUz2JIBhTNT98fet2n69D9Z925W7psRkrbOR6B7dwy7M1f3R0/jj78yp1T2TOWtjsicBDGPABPrJ2V16GujU9fj77i8nc8KYtFYUabvW2Uh0j+5hFwbsruF385b67TEMPlWriUT36B524cG7K7rXRKJ7dA+78ODdFd1rItE9uoddePDuiu41kege3cMuPHh3RfeaSHSP7mEXHry7ontNJLpH97ALn0+3PhVB99PHNn6tI97oHt3DVkz/8vopX44/fVRT1joC3aN7ANgCdI/uAWAL0D26B4AtQPfoHgC2AN2jewDYAnSP7gFgC9A9ugeALUD36B4AtgDdo3sA2AJ0j+4BYAvQPboHgC1A9+geALYA3Rvofvr34QEAaED3t5j+TXgAAHrQPQDARqB7AIAtQPcAAFuA7gEAtgDdAwBswf8BaQnxLDymqPkAAAAASUVORK5CYII=" alt="" /></p>
<p><a href="http://linkstate.files.wordpress.com/2011/03/ias_05.jpg"><img class="alignleft size-medium wp-image-53" title="IAS_05" src="http://linkstate.files.wordpress.com/2011/03/ias_05.jpg?w=300&#038;h=206" alt="" width="300" height="206" /></a>Now click &#8220;Configure Attribute&#8221;, Change the attribute number to 1,  lease the format as string and enter the below as the value (enter is  exactly as it appears in red below)</p>
<p><span style="color:#ff0000;">shell:priv-lvl=15</span></p>
<p><img src="image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAYoAAAEKCAIAAACDrIWfAAALQklEQVR4nO3dX26zyh0GYF92Id1EL+PtVN3EJ2+l2+lNpWzHvXBlcZg/DGZgfuDn1aMj2xlgIOE9kPhLbv/4178BAroNnwFAlnoCglJPQFDqCQgqU0+///0PwPHuP/flenqKiBybx59Haz0N71Hgq6yrp7/9/Z8AB1BPQFDqCVhh1XeO7j/3LUupJ2CF9u9Bv5ply1LD6undlMMP92czHz6N42d7rh1nJ2nR3CaJUk+z67G1e/heZO8v+tK2SvOv79GqNbQMPuCL6bW5jZ+mYz5ZxDcrmmkrzRqqVE9pkU1f6VBPG79Mj/wqz9bTYgG111P98fH72/FQh9oRgtheT+1Lda6nxquG6dP64Hq5ZBfMTqm0htLgxVWV1pxddvGsrh+3+sGpDCjtUcvKS0d1cV+4tmfhNm3tzV3LLWHPemo8K3q9WB+TTmzxbCxtN7uDle2mK6+f0ulH2w9F+wGs79HiCiuz5as8c/WUtkzL954WlzpxPc22O012YvWl6pvI7nVpo+my9VO6Pr5+KNqPVfrR6cw/Pgh8m2enerr41VN2u6UDOj0VS9N+5lLawVXzqc+wPr5+KNqP1fbj3Hi0ubZnjzcWDPje02df99tPm5YTpjKmfbWVAaXHLTOsj68fivZjtf04tx9tLuy5+epp95/c/a16c/TZidSyztJpk10wHdAy+dIild2p7F3jDOt7Xd/0bLulpUorL310NrJyTPgqz37fe1q85vq8nvY+BDFPg7ATO2ZukXefY3xWNFeop8r1RRxhp7f3xMLuOEd6Pp+PP49G03r6YKlY9QQEd/+5r7JlKfUEBKWegKBW1xPAYdQTEJR6AoJST0BQ6gkISj0BQaknICj1BASlnoCg1BMQlHoCglJPQFDqCQhKPQFBda6n9FcOp698tp5eeq15y3pey+63jxGOM2z3dfXUy+IMp38q5+N93Ps4xD/OfLP+N3fTr/iPv/rjnzbqCfZ2XD3N/ijo+wYnO2b2V/pKf7QvO6a02tmUZtuqz6cyw8oOztaZ3VZ2btn5VLZb2sd0W6V1VvZ6Nm04zEH1tHjilcZUXilturTaWTV0mU/7NCoTa3mlsulVM+9+zGE/u/zkLvuFPvsf9doTIz3NKpcA6Qn82bYW5zzbSnZwr3pKd/ODvWuZQ2Wv4UjH1VN2TH18y//JS1spncN7bKu+eK96qh/ttev5bK/hSHu976nX9UvllcU1V572mk/7NCoTyy5SqadVm95ST66eGOugevqd3DWkA2an02xYaal0zelpmT4tbas+n8q26tOYPkifltafDs5OZvFIljbdMofSInAY7xp31kFQ/d+WmWb4TtbnOXwyQJarJyAo9QQEpZ6AoNQTEFTnenr8eQAsaqmUR/d6uv/cASoaK2WXenqKiJSjnkQkaNSTiARNlHq63W5jDoCIRM34enr/q5GRh0FE4mV8Pb2inkRkFvUkIkGjnkQkaNSTiASNehKRoFFPIhI06klEgiZKPYmIzKKeRCRo1JOIBI16EpGgUU8iEjTqSUSCRj2JSNAMq6eWYcCXG1BPYytZRE6Uo+sJoBf1BASlnoCg1BMQlHoCglJPQFDqCQhKPQFBqScgKPUEBKWegKDUExCUegKC2quebrfbqpHt4ztuGojsoHp6Py11R0un9Brz8V4AR9qlntILIvUErHVcPb1fTB+8n75fTBefLjIdn266NGa26XSd9UWGf6rg2/Svp/pFU+lBtoxKr2Q3UVp/ZfHKNZ1WguHOWk/p1VZp/dnFKw9m11bDP0PwtXapp8qdWverp3Tr6ZjGeqrPAThY53pavEv6oBrSa5mdbu7UE4RyUD2lD9Kn6c1apZiyd3a/ScWsuoLLTkNPwSjeNQ4E1f/qKc3wnQTOyNUTEJR6AoJST0BQnevp8ecBsKilUh7d6+n+cweoaKyUXerpKSLflFW3bOpJRI7LqyJa8qoI9SQiB2VtRagnETkoZ62n93vHK/tW/6iIBM8p62naO+/HykjkYjl9PdVfFJHzZloR9X94e4J6er0+fTD97+yaq+X2UEQGZlYRlV8KEKienrnvPaV3eWkxTQtrNlhEoiWtiNIvLIlVT++UWulZLiP1JHKKZCsi+8uU1JOIHJq1FRGinlru6Z7qSeTkOWU9PQvve5q1T6WMfGtcJH7OWk+9op5EwuYb68mlk8gp8o31JCKnyO+aX0WpnkTkuJzm19G1DAO+3IB6GlvhInKiHF1PAL2oJyAo9QQEpZ6AoNQTEJR6AoJST0BQ6gkISj0BQaknICj1BASlnoCg9qqn7B9pqIxsH7/dkdsCPnZQPb2flqqhpTJ61Yp6glPYpZ7SCyL1BKx1XD29X0wf/P71rx5PVzJb4fSj2b9BWurEdM3tI4Eh+tdT/aKp9CBbRqVXsptY/NBsPS1bBAY6az2lV1v1xaeDK+uvrBY42C71VLlT6371lJ1AaXD71RMwXOd6WryW+aCeZlc92cGVaSzWU7r+0mqBIx1UT+mD9Gl6V1Uppvot2Oz17M1daf3Ziz7geN41DgQVop5uSYYfF2C4EPUEkFJPQFDqCQiqcz09/jwAFg34I+av1QFUNFbKLvX0FBEpRz3tktvtNnoKIqePetol6klke8LVU8uJ/RrTXgGLI0sD6gtOP5q+ZbRxbiJSylfUU+MKV70+66DZSPUksj3qqbbRVVdP7QuKSEtC1NP0SuRdPdlbp9mY56QI0hur9+O0zrJtkg747OZucUERacn4eqoUU701KhcsaXNlB5TGpxvKflOp8lg9iWzP+Hp6Vs/zZ64dPqun7Ov1Imu/epq9rp5EtidEPT0LjVC6UepVT6WtZy/o6ldPs7WpJ5HtGV9Pjbdy6Ssf1FO6VH1A+9WTmzuR7hlfT8/c95tmj2dXLtmSSi9wjqyn2STVk8j2hKinLgnVCKEmI3LSqKddEmoyIifNdepJRC4W9SQiQaOeRCRo1JOIBI16EpGgGVZPLcOALzegnsZWsoicKEfXE0Av6gkISj0BQaknICj1BASlnoCg1BMQlHoCglJPQFDqCQhKPQFBqScgKPUEBKWegKDUExCUegKCUk9AUOoJCEo9AUGpJyAo9QQEpZ6AoNQTEJR6AoJST0BQ6gkISj0BQaknICj1BASlnoCg1BMQlHoCglJPQFDqCQiqcz09/jwAFrVUyqNvPT1FRNpydD0B9KKegKDUExCUegKCUk9AUOoJCEo9AUGpJyAo9QQEpZ6AoNQTEJR6AoJST0BQ6olzuF096S6P+CUCx+X+c1/8pKsnzuF2u40+ofbK/edeqqfhh30nr95pHKaeiO5VT8On0d3rDFRPlWHqiejU05WoJy5FPV2JeuJS1NOVqCcuZe96yv4QrfS4o73rqf7DwY1r3rjXjcPUE9HtWk+zM+39NH3Q3a71VNqvPQ7aB3vdOEw9Ed3Aetqvm36PraddD9oHe904TD0R3ah62vUM/x1UT7PbvXcLz25m66+oJ/g/9bR9v0oDslWVjqm88tleNw5TT0Tn5m77fk1fn14KtVTP7a/ZeFjUE5fiW+Pb9yt9cVU9tax81V43DlNPRDe2ntIxvRz/k7u19eTmDhbsWk+/De97Sp92MeR9T4s3d9Mx6VLbj4Z64lL2rqdRvGt8cZh6Ijr1dCXqiUtRT1einrgU9XQl6olLUU9Xop64lFc9Pf48rkc91YepJ6K73W73n/tVleppeHXuWsqLn3T1xDncrp50l4eX5t4WP+nqCQhKPQFBqScgKPUEBKWegKDUExCUegKCUk9AUOoJCEo9AUGpJyAo9QQE1VpPw/99M/CFlutp+L9sBr7WQj0BRKCegKDUExCUegKCUk9AUP8Dv4tWJk7b4/oAAAAASUVORK5CYII=" alt="" /></p>
<p>If you wanted to assigned a different privilege level to someone, you can do it here. (i.e. several different AD groups to assign several different privilege levels). Ok everything untill you get back to the &#8220;Add Attribute&#8221; window, click Add to add you Vendor Specific Attribute, the window wont close, but it does add it, you now need to add another Attribute &#8211; &#8220;Service-Type&#8221; &#8211; Change the Attribute Value to &#8220;Login&#8221; and click OK, add this again and now click close, you should now see the below;</p>
<p><img src="image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAaEAAAHeCAIAAAC9viOBAAAYV0lEQVR4nO3dyY3jSptG4Vy2Ie1ELyvdabQThXSl3anNBeiO/oVwBRZjYHAOfnxeHAgSFQzGxCMqU6n8+p//+38AiMrX5S0AgOPgOACR4TgAkeE4AJHhOACRyTtu+OcPANyL71/fCxz3EhG5T35+/yx23OVWBoBGVjruv/77fwGgczgOQGQ4DsDZLPpp2vev7y17cRyAs2n/mf5bT1v2OtZxb6EeOlKH1j976PHRL2wMcC9SW32N0pfjJteHaU/eG9M72ZJLxVGvrWWgK42f3bHURwB1JrYaq22iuZLjUhuOt+zvuEpPJs+2WKldFhu1su6gpcIcBzSy3XHtex3iuPT6aHJn1n3Zi6N031ljpi0pHTTb1Ppxs10r7QLgw6vwrnPpe9WWd7j7v1edFUfdSqUds4UbHZc9RL2pjd2Z7SPNASlZx6Wqavl53Oxe+1/HHee4199Jiy3VTVphpSWz1WYbw3FAyl6OO+86btL6Ixw365psbS2Oa2xJe2N4DaiTdVyWHn8et91xK7RSqo3jgA7JOm7RddzZv1f9pLQx++ykz2k9pR3PdNzkuKVWzTYVwIfXfj+Pm7362+o4AFjKOltxHIB78Hq9fn7/NDJ23Iq9OA7A2Xz/+l7Elr04DkBkOA5AZNY7DgBuAccBiAzHAYgMxwGIDMcBiAzHAYgMxwGIDMcBiAzHAYgMxwGIzCGOe0nEmOKNMYBH5ALHtRwVd+T71/f7jik2gP3wGdUSOzvO5AXmvVZMsQHsiveozhbgOMzjFDWAHcJx2A2nqAHskEc4rvRvFtN/gZHdXirWcogj+nL+ADZy4Sk6+S9z58xFyAGsbCk99X44vm2p/+RRnS1we8ctGuul87HCibscd69996KHU3SvuXjsALYMXVZn9aHmuFPnb3a4Nzpur3Ze0oYt9HCKctzqAZxcCnBcBMelb3Aq5T+37a942Wori+lzP92YVlLat9TIE+C4Ww9gZVlOxnOy/Cq32XPtklGdLRDccdkpTDcuOpGyKyOrqtLDSttmqypVciidOG6c81ty6wFMb4fCSk4LtKzPC196ZwsEd9zkrKi8TNUrLG2s1NCyMdu2lspP5vJT9MK+xxjAHR2X7nLtspwtENlxdV9UipUephvrNVQuwWaXV73NJ3P5KXpVx0MO4O6Ou2p2Hue4FvVsdFz7pVbJtlscd+HZ3tUpeke6GsDsnY2Ou2SCnuK48du97LyOCyx1XOkQky2la7dZG6ZtK1WVrfM0ujpF70gPA5jdstRuLS/wJ4/qbIF7Ow7n4GP6BrBDOA674RQ1gB3CcdgNp+gKdviCNGnI7LrlOMzDcUsxVqdRuZTzPcAPijk6OZef+c+h8o7V9wA/CN9DeyYG+UzOc5x57RlvNs/EOJ8Jx+HPwHHnctU4Vz6eduYn1/r5lBzHPQiOOxOOO7PXkR3XPpQbB33F7r19KP98x339naOPdfkIj7nEcdm/5LlkiDjuvKHc+GdAAdT24RLHBTjEOvpxXOVvGdO/d5zUU/njxfoWjjtwRrNlZovN7n7oLufAcWdy7et9dtm3/G1parf2v1Ht869WozkuO+6TPyeuvBBlJ3hylNlXs9ldsi05bR1c7rjGiUjHcFys/9Hu1nHjMUnHv8Vf6S6lvU4jpuMaZzQ9GUpzXC/TMouNu6RHOYdrfx432Tg7RNmZnS3Zz2hf4rjsa8BkQCqD3DLOaW3ZLRy3z4yWJq99IttfvkozPamnvsu1L3ddXcfVR3Vfx10y2pe8p0m3lLpfv7/XltMI67iWV63GF6vG3TfuwnFLJ4LjVg/1eGQmp0lafvbFflwm3atUz2kEdNzsq1Y6Wxtfmg7d5Rxu4bjslvbXsH5G2+cQz+RBjhvKdmt5aSqVqewy3tK4y6McVxqcFRORHepuR5vjziSg47CCm/6dw1WS2sjtxvnWcBz+DDd03OR6beA4FOA4/Blu6LhbY5zPhOPwZ+C4czHOZ3KG4zZ9X6pIxFx+5j+Hkxx3eT8BPBOOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxCZTh2XfjH/OrLf3L+6ksmWHb+HtofvsD26DdlBi9TBq9q2aN/sv9GITY+O2/1L+jdWUnJcPy3s59CzLyoth1vRpIOqPWHEsnUu6s5Sx+3el85d2bvjdoHjTjs0x+1SJ8ftyG0cV/rPcvUtn/dH6f+gK9VfOeJkS6XyShsqZRrbU6q25UDZela0v6W27PhkR3Uy9dkxnxwx24zSLouW0GyF6YiVFsPssbJNWtSd9mNlV1pll/HDeuUtrb2QHh1XWg2T++1bxhOQnel01ldXXln32eOme7UfPT10S2NKW9a1v15bY/2zldSfqu+yaFRbKmx8akXH13Wn5Vjjh+O0DE57RyrHvZBOHdcy2elszRqk7ppSVfUt65ZyveWljiw9UPsQLW3/7LitOEOyQ5qekNmTp+U0axmf+kyV+lhZaY1zUTn6ijIt/VrRzXXzdTn3dlypcGUO6jPdMpGTLe0roHHLbNdWV1vf0l5tS6tWnCGVSpb2YsUst1Q4e6zVy3V3x832a0U3V8/XtfTouOy87qKh4d+Xmtkj9uO4vaptXKAXOu4zNUslUt9l0ai2VJjt2iLHbTn6ohbWB2FFN9snpR/f9ei44d9Fk7qptLG0ZXbKK/XPbikdJduGdLlkq1ratdluNg7a0vbXx61UbX0e08KV9mdnsLTLoiWU7XV2xNKW1wetcvRKA0oFls57dgYr3azfqQ9ItrVX0anjStPZTz0AbsGDHNfbywuAE7iN4wBgBRwHIDL9Os77SgDb4TgAkenUcekvxQFgBXdyXMuHm0pbSg/rxUofgxo3slIYwOX06LiSRyYbF23JPiwdZbae9mYAuJZbOq6yZZxssZKAshdxlcu39CIuWxjAtXTquFlVNW7Jbp8tVq+5fklYqR/A+XTnuJIyOnmvmu7uvSrQM7dx3HD17xwqjSwVJjvgcrpzHADsCMcBiAzHAYgMxwGIDMcBiAzHAYgMxwGIDMcBiAzHAYgMxwGIDMcBiEyPjmv/M09/Aw+gzg0cN/sn7i2O40HgmXTnuNK3Gw0cB2A593DcZ2N6Zxh9tVHWhpNdhuSrkNJnL58VAHvRl+Pql2+lO/VvqZxsaXwKQAye6Lj6dR+ASHTnuIqAdr+Omxz68skAsDsdOS61TElP7Y6b/ORutvDl8wFgX27guPRO+rDya4RsJX7nADyEjhwHALtze8d9Jbl8TAH0w+0dBwAVOA5AZDgOQGQ6ctzP7x8AmGXRZdNPV477/vUNABXaldKp417Sd8xRe4zVEYnguPbW42TMkbHqAY7DUZgjY9UDHIejMEfGqgcCOm7y1wv+mOEqSnNU+VvjRUSa2e1jFWk09iWm47JfLYeT4bgzxyrSaOwLx+EoGq+1V09QpJndPlaRRmNfYjpuyH1L0pB8UdL4YfYLlKybLaw4b9MJqkxN6fuv7jhxO45VWvjhi/lZjpstU1koWMrS8zbd2HIO17fchS3XceNet4zP0wjruKEwx5Nrt9Iu6cUCllL/XWF9dtYZLaTjSv3KjlXpdeLJizmy44byd/a2X8dhNSscly1TL/9Mx5V6HWM09oXj/qR3XN7vwuxnvtILk9IErd5yF/Yaq/FKtpjfBHfckFNeOv3ZO4+9tt+LpedtOuzZ8zN951XZ6y5sGatZuz18MQd0HDrBHBmrHuA4HIU5MlY9cHvHXf4NfKhgjozVtdzecQBQ4faOm/+KPBF5cDhORCInlOO+vr4m3Uu3tGTRXp/fyq84UPag7zvbK+w8X38nfbZUOFustP01N0F7TV/ahh0Lr9h36SqaLVkZwMa96jN+XDguk3Ur4/zz5NapWKn+MHu/xX315VGqqj23dtzqg7a/eFy1tkM57rWTdHZ89Tvu0HfPrMUqU5n6qPH6rt6Gll2W1rZL4RX7Xu649FmOO9Zxk1eVzwooXUuX9qpfbpTqSauabVKpDWHSs+MqC+C1bdlk10ZL2psxKfPKraW0bY1jXp+mbLPTFp68mB/huOzEZFdD+5bxU+lqW1RVaTmWuhMjX39nvD29nz3fWgq8chOUbUZ238nGlmWT3avStZZU7Na4nEoNaO/O7IHaZzOt/NBEc9yrMBmTCdiiodffi2xSprRjpQGlQ2SLhcmstkobs9srJ3N942wDli6byl5bTvK6LEoLrDIspbaVlnqlQGOzW7Yfkac4LlumXr6+pXTcxh05rqKtyelaL1wvMLuxsc51i2RHx7U3rLJ9heNKR08fprOWrae+/YgEdFw6grsv1krNGyuvLLVgvsvOUcu5Ojvmpe1Lp68fx82uitnlNNuj2bbNTkG95Yv22jePcNxr9DqTFhhvTIuV9irVnK2nXmxcefZMm+wYI0sdlx2H2WF/zQ1gvdpJnUuXTXavdROaLpVSM8bb00WVLVaqMzsmLYVLz16ymGM67trE85HEyDNXJsftn2euJOk/z1yZHCcikcNxIhI5HCcikRPQcRt/d7Nix6+/s+64T0t90Eq/j0u3l8qn+9absbojpTZfVXjjXvESzXHtv9XePZbUolSsVH9Y+uREtnx9PbRU1Z7eHCfvRHbcybEQF2XWYhU91T/eVdleb0PLLktrO7+wTPIUx6UffSydSJMyi971ZB9+ql1aYez07LjSGhhP5aR8fa/0qe2Oqyyn8QBm2/yoRHPcqzD3k/vZcyBdGdldXuU1l324usLY+fo74+3p/dWOe+XWQ7YZ2X0nG7O+q+w4u9gaU6q53pJSm5+WgI77JPviOWuctEClksqqbXFc9iR/SGa1VdqY3V5xXH3jbAMal82rsN5mu9aSjY5bd9AweYrjSk+9kqVQcVx9KFc4rl5h7FSGK1X/JY5r90jjFo67JNEcN3sVkPXLurVbOfRny6IT5lHJTkHpZC6NVbsEK5WXduG4GInmuNfoQqCycdZx2XqyNWcryVa7tMLYWeq40rSO77dMfVp/pdpJnfV10rjXikn/+jullmePm23zoxLQcf3E8pJLYrGNw3GHpH7FIbJ71l0hPiEcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRw3EiEjkcJyKRc3vHtTd9+OfP0vIIz3tJjM8Et/3frpvfRnp0XKPOl5aX8Pm8Fbj8pHXbfrvulL+9444oj/BMloTbe90und+lq6L0FMfhNriOu+Pt+E7L/LaXn+xVeqoXx319fe3SYQTGddytbz+kJ3t2fpeuitJTXTju6+uL4zCL67g73o7vvMme70Ngx339m106jMC4jrv17Yd9T/neHfc1yi4dRmBcx93xdnznTemsj+m4wXUcmnEdd+vbD8+6jhv3eZcOIzCu4+54O77z5nE/j/t0e5cOIzCu4259++GJv1fdscMIjOu4O96O77TMb3v5yV6lpzgOt8F13K1vl87v0lVReorjcBtcx93xdnynZX7by0/2Kj11geN+fv80srQ8wuM67o636+b3ro4DNtLDSeu2/Xbp/N7bce3tBvBY7uq4l4hIW27pOADYHY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQmY4c9xU9pY6f+Rcw56e0vK5u17Ep9Rrn05fjrl6ZR+X713fdcZevg/OX1zN7jfPpznGXj8hBQ8xxeo1L4LiThpjj9BqX0K/j3lK4++3AcRyHS+nUcRUj3Ih3LzhOr3EhnTpuOxWnpE8dqtQzHTf58vtsgc/tCezuuNkO9gDHdUWnjtsunR4cd/513M/vn8mvdLMF3gc9wRFHOG7cuz41x3Fd0anjNjL5iVj22fqW3Yf4TMc1FpgtvFffd+z1pM0ndGHfXuN8OnXcRulkHZd+HLflA7rbm9GD48bv7z6XPye83TvTcZM3sOOHk56mJcdPZcvs1WucT6eO28LYJmOdTTZmix03xOf/PG68cfj37wo+jvvcHnoddMLP4971TPo4jN7Vfp4a/ywyLfmpf7zLurfDHNcVnTpui3T6cdzlP48bbxzfH98e0fFxe875edzEfePeTe5k361P9JfWtlevcT6dOm4L2b8Sfc51XOX3DEMUx6UP01+2LHVcukv6arG91zifTh23Wjql3yc86jqusjG24z4bs09VHPfZq1TbXr3G+XTquNVUfmc6+zuH9KJvF/dd9fO47E/Z0wuWYXQaZ38Mv73vO/a65LhxH4d/329mHZeWLNWcltnea5xPp47zdw6rKb3Jmmz8PJV9uFerdndcumO2j6W+jO+kb0LThyveqNZ7jfPp1HH78pXk/CE+wXGTi7jJpdwl7Ou4bAcv7+OiXuN8OnWc67h1vHK5cAR2v47LdvDaPi7qNc6nU8cNV39fyF63w+nvVbviiPeq/cNxXdGv48LAcXqNC+nOcaWfudwajtNrXEVfjvv+9R2VuuMut/ChftdrXEhlOn78X659U+r45f49Gr3GhXTkOADYHY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQGY4DEBmOAxAZjgMQmZMc9/P7BwAu4XDHff/6BoALOdZxANAhHAcgMhwHIDIcByAyHAcgMhwHIDIchz/DP39eoZP9VMHVjTo2uvyB4/BnCD2tpU+H6nIkzvgMMG5N4Gl1wj+5ywPH4U3gaXXCP7nLA8fhTeBpdcI/ucsDx+FN4Gl1wj+5ywPH4c3R0/o1ynhj9v6+HHrCZ/u114j12eWNjTxoojkOMxw6rZNl/XmY3jmC4074Ur+OGLROury9kRyHa7jQcYcKbjjRcYcOWiddTlu4tJ0ch2u4ynFHC264wnGTd68fF0zem9e33NFx6Tv37JbhgEt4jsMMHLe9X6UClTO8cUs/Xc72PSuser84Dmfjver2fo23jy9eWvz19Xc2DgvHpU9x3NPxO4ft/Uo3LnJcS+WXd3ncvNL70Ja+cxzO5lrHpWV25OTfqy513B3fq5aMvKhf+/6kguMww+Wfj0sf7sX5n4+bfa86LpPutX00LnRc2otSv/adbo7DDIGn1Yf+T+vyonfcHIdTCTytHLd7l79yGZodt++71HqXB47Dm8DTynFP7vLAcXgTeFqd8E/u8sBxeBN4Wp3wT+7ywHF4E3hanfBP7vLAcXjzer1+fv9EpXTCX94wXT66ywPH4c33r+/Y6PIzuzxwHIDYcByAyHAcgMhwHIDIcByAyHAcgMhwHIDIcByAyCx23OWfZgaARSxw3OWfYwaAFbQ6DgBiwHEAIsNxACLDcQAiw3EAIsNxACLzHyNdIkSy3X0tAAAAAElFTkSuQmCC" alt="" /></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><strong>And that is you Policy Done!</strong></p>
<p><strong><br />
</strong></p>
<p>Now. time to add a client to the IAS and configure the Cisco Device.</p>
<p>1) Add a client to your radius &#8211; In the IAS MMC, right-click on the &#8220;Radius Clients&#8221; branch and choose &#8220;New Radius Client&#8221; Enter the Display anem and IP address of the device, click next. Change the Vendor to &#8220;Cisco&#8221; and enter your shared secret (keep a note of this for later)</p>
<p>2) Configure the Cisco Device.</p>
<p>First, you need to configure the device to use AAA by entering the command</p>
<p><span style="color:#000080;"><code>aaa new-model</code></span></p>
<p>Then you need to configure the AAA Groups, There are 3 parts to AAA</p>
<p>Authentication &#8211; Who is allowed to login<br />
Authorization -  What are you allowed to do once you have logged in<br />
Accounting &#8211; What are you doing once you are logged in</p>
<p>We are only going to be concerned with the first to A&#8217;s &#8211; Authentication and Authorization, enter the following commands;</p>
<p><span style="color:#000080;"><code>aaa authentication login default local group radius<br />
aaa authorization exec default local group radius</code></span></p>
<p>This will create a authentication list called &#8220;default&#8221; you can name it what you want, but if you use default you don&#8217;t need to modify anything else.</p>
<p>The list defines what source the router users to authenticate you &#8211; i.e. Local usernames first, then the radius server.</p>
<p>Next you need to configure the Radius Server;</p>
<p><span style="color:#000080;"><code>radius-server host 10.10.10.10 auth-port 1645 acct-port 1646 key SHAREDSECRE</code>T</span></p>
<p>the Host IP is the IP of the server, and the Key is the shared secret you entered into IAS.</p>
<p>If you device has multiple interfaces or routes to the IAS server, you might want to configure a source interface (i.e. the interface with the IP you entered into IAS);</p>
<p><span style="color:#000080;"><code>ip radius source-interface Vlan1</code></span></p>
<p>And thats it, you should be done! give it a go.</p>
<p>The only extra is if you used your own name for the AAA List, you configure your VTY lines to user this list, type the following;</p>
<p><span style="color:#000080;"><code>line vty 0 15<br />
login authentication MYLISTNAME</code></span></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/linkstate.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/linkstate.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/linkstate.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/linkstate.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/linkstate.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/linkstate.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/linkstate.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/linkstate.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/linkstate.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/linkstate.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/linkstate.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/linkstate.wordpress.com/44/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/linkstate.wordpress.com/44/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/linkstate.wordpress.com/44/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=linkstate.wordpress.com&amp;blog=21547659&amp;post=44&amp;subd=linkstate&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://linkstate.wordpress.com/2011/03/31/using-active-directory-for-radius-authentication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/acc3b04b131de4577956673f74cd7ca4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">rekordze</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/03/ias_011.jpg?w=300" medium="image">
			<media:title type="html">IAS_01</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/03/ias_02.jpg?w=300" medium="image">
			<media:title type="html">IAS_02</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/03/ias_03.jpg?w=260" medium="image">
			<media:title type="html">IAS_03</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/03/ias_04.jpg?w=300" medium="image">
			<media:title type="html">IAS_04</media:title>
		</media:content>

		<media:content url="http://linkstate.files.wordpress.com/2011/03/ias_05.jpg?w=300" medium="image">
			<media:title type="html">IAS_05</media:title>
		</media:content>
	</item>
	</channel>
</rss>
