Guest

Preview Tool

Cisco Bug: CSCvi72479 - ISR4K CWS - admission commands override (method-list vs bypass list)

Last Modified

Aug 10, 2018

Products (1)

  • Cisco 3G Wireless WAN

Known Affected Releases

15.5(3)S7.4

Description (partial)

Symptom:
IP Admisson with Bypass list + method-list  - everything get messed up

Conditions:
IP Admisson with Bypass list + method-list  - everything get messed up
 
ip admission virtual-ip 1.1.1.1 virtual-host proxy
ip admission name ssauth ntlm list BYPASS
ip admission name ssauth method-list authentication cws-list authorization cws-list
 
 
For the example above, if we configure at same time ?ip admission name ssauth ntlm list BYPASS? and ?ip admission name ssauth method-list authentication cws-list authorization cws-list?
In the show run we will see following:
 
aaa session-id common
ip admission virtual-ip 1.1.1.1 virtual-host proxy
ip admission name ssauth ntlm (missing list BYPASS)
ip admission name ssauth method-list authentication cws-list authorization cws-list list BYPASS
 
 
We can see above that two command mixed up and last one on the next reboot will be discarded with message:
 
 
%INIT: waited 0 seconds for NVRAM to be available
 
ip admission name ssauth method-list authentication cws-list authorization cws-list list BYPASS
    ^
% Invalid input detected at '^' marker.
 
 When router is up and running after reboot, following can be found in the startup/running config:
aaa session-id common
ip admission virtual-ip 1.1.1.1 virtual-host proxy
ip admission name ssauth ntlm
Bug details contain sensitive information and therefore require a Cisco.com account to be viewed.

Bug Details Include

  • Full Description (including symptoms, conditions and workarounds)
  • Status
  • Severity
  • Known Fixed Releases
  • Related Community Discussions
  • Number of Related Support Cases
Bug information is viewable for customers and partners who have a service contract. Registered users can view up to 200 bugs per month without a service contract.