Phil,<br><br>YES! it works....<br><br>Thank you very much.<br><br>--coroy <br><br><div><span class="gmail_quote">On 7/11/07, <b class="gmail_sendername">Phil Mayers</b> <<a href="mailto:p.mayers@imperial.ac.uk">p.mayers@imperial.ac.uk
</a>> wrote:</span><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">You've misconfigured your FreeRadius server to send attribute the Cisco
<br>can't obey, specifically the Filter-Id<br><br>The cisco sees the reply:<br><br>> *May 22 15:43:52.088: RADIUS: Filter-Id [11] 9<br><br>then says<br><br>> *May 22 15:43:52.088: RADIUS/DECODE: invalid ACL type; FAIL
<br><br>and sure enough, the ACL you are returning doesn't exist in the Cisco<br>config you show. Don't send back a Filter-Id reply unless the named ACL<br>exists. Either create the ACL, or don't send it.<br><br>
-<br>List info/subscribe/unsubscribe? See <a href="http://www.freeradius.org/list/users.html">http://www.freeradius.org/list/users.html</a><br></blockquote></div><br>