<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACE 4700 and Cisco ACS aaa authentication in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054377#M21165</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;BTW, I have created a new bug for this CSCsv04319 so we can make the error message more explicit or accept the key even if all numeric.&lt;/P&gt;&lt;P&gt;Not sure yet which we way we will go.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for reporting the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 13 Oct 2008 07:17:39 GMT</pubDate>
    <dc:creator>Gilles Dufour</dc:creator>
    <dc:date>2008-10-13T07:17:39Z</dc:date>
    <item>
      <title>ACE 4700 and Cisco ACS aaa authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054374#M21162</link>
      <description>&lt;P&gt;ACE version Software&lt;/P&gt;&lt;P&gt;  loader:    Version 0.95&lt;/P&gt;&lt;P&gt;  system:    Version A1(7b) [build 3.0(0)A1(7b) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco ACS version 4.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to authenticate admin users with AAA authentication for ACE management.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is what I've done:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE-lab/Admin(config)# tacacs-server host 192.168.3.10 key 123456 port 49&lt;/P&gt;&lt;P&gt;warning: numeric key will not be encrypted&lt;/P&gt;&lt;P&gt;ACE-lab/Admin(config)# aaa group server tacacs+ cciesec&lt;/P&gt;&lt;P&gt;ACE-lab/Admin(config-tacacs+)# server ?&lt;/P&gt;&lt;P&gt;  &amp;lt;A.B.C.D&amp;gt;  TACACS+ server name&lt;/P&gt;&lt;P&gt;ACE-lab/Admin(config-tacacs+)# server 192.168.3.10&lt;/P&gt;&lt;P&gt;can not find the TACACS+ server&lt;/P&gt;&lt;P&gt;specified TACACS+ server not found, please configure it using tacacs-server host ... and then retry&lt;/P&gt;&lt;P&gt;ACE-lab/Admin(config-tacacs+)#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why am I getting this error?  I have full&lt;/P&gt;&lt;P&gt;connectivity between the ACE and the ACS&lt;/P&gt;&lt;P&gt;server.  Furthermore, the ACS server &lt;/P&gt;&lt;P&gt;works fine with other Cisco IOS devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help.  Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2008 19:28:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054374#M21162</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-10-10T19:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4700 and Cisco ACS aaa authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054375#M21163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can any ACE gurus help me out here?  Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 12 Oct 2008 19:59:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054375#M21163</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-10-12T19:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4700 and Cisco ACS aaa authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054376#M21164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the problem is the numeric key.&lt;/P&gt;&lt;P&gt;Change the key to something non-numeric.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2008 06:34:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054376#M21164</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2008-10-13T06:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4700 and Cisco ACS aaa authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054377#M21165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;BTW, I have created a new bug for this CSCsv04319 so we can make the error message more explicit or accept the key even if all numeric.&lt;/P&gt;&lt;P&gt;Not sure yet which we way we will go.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for reporting the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2008 07:17:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054377#M21165</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2008-10-13T07:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4700 and Cisco ACS aaa authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054378#M21166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks.  Now I have another problem.  I CAN&lt;/P&gt;&lt;P&gt;log into the ACE via tacacs+ account(s).  &lt;/P&gt;&lt;P&gt;However, I get error when I try going into&lt;/P&gt;&lt;P&gt;configuration mode:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE-lab login: ngx1&lt;/P&gt;&lt;P&gt;Password:&lt;/P&gt;&lt;P&gt;Cisco Application Control Software (ACSW)&lt;/P&gt;&lt;P&gt;TAC support: &lt;A class="jive-link-custom" href="http://www.cisco.com/tac" target="_blank"&gt;http://www.cisco.com/tac&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Copyright (c) 1985-2007 by Cisco Systems, Inc. All rights reserved.&lt;/P&gt;&lt;P&gt;The copyrights to certain works contained herein are owned by&lt;/P&gt;&lt;P&gt;other third parties and are used and distributed under license.&lt;/P&gt;&lt;P&gt;Some parts of this software are covered under the GNU Public&lt;/P&gt;&lt;P&gt;License. A copy of the license is available at&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.gnu.org/licenses/gpl.html" target="_blank"&gt;http://www.gnu.org/licenses/gpl.html&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;ACE-lab/Admin# conf t&lt;/P&gt;&lt;P&gt;               ^&lt;/P&gt;&lt;P&gt;% invalid command detected at '^' marker.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE-lab/Admin#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ngx1 account can access other Cisco &lt;/P&gt;&lt;P&gt;routers/switches just fine and can go into&lt;/P&gt;&lt;P&gt;enable mode just fine.  Only issue on the ACE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?  Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2008 09:40:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054378#M21166</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-10-13T09:40:26Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4700 and Cisco ACS aaa authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054379#M21167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ACE doesn't like the '=' in AV pair.&lt;/P&gt;&lt;P&gt;So you might have to do something like below to make sure you end up with the right role.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;shell:Admin*Admin default-domain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;instead of&lt;/P&gt;&lt;P&gt;shell:Admin=Admin default-domain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2008 10:09:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054379#M21167</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2008-10-13T10:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4700 and Cisco ACS aaa authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054380#M21168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;where do I find that in Cisco ACS?  I am not &lt;/P&gt;&lt;P&gt;using any AV pair.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why is ACE so different that Cisco IOS &lt;/P&gt;&lt;P&gt;routers or ASA?  If I am not configuring&lt;/P&gt;&lt;P&gt;AAA authorization on the device, why should&lt;/P&gt;&lt;P&gt;it matter with shell Admin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also setup the grop which ngx1 account in&lt;/P&gt;&lt;P&gt;Cisco ACS, by default, is permitted to use&lt;/P&gt;&lt;P&gt;ALL services but it is not working either.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2008 10:24:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054380#M21168</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-10-13T10:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4700 and Cisco ACS aaa authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054381#M21169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please read One of my old post on this topic.&lt;/P&gt;&lt;P&gt;It has answers to your questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Network%20Infrastructure&amp;amp;topic=LAN%2C%20Switching%20and%20Routing&amp;amp;topicID=.ee71a04&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.2cc10b80/3#selected_message" target="_blank"&gt;http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Network%20Infrastructure&amp;amp;topic=LAN%2C%20Switching%20and%20Routing&amp;amp;topicID=.ee71a04&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.2cc10b80/3#selected_message&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Syed Iftekhar Ahmed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2008 15:31:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054381#M21169</guid>
      <dc:creator>Syed Iftekhar Ahmed</dc:creator>
      <dc:date>2008-10-13T15:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4700 and Cisco ACS aaa authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054382#M21170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok.  This is what I did:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On your Tacacs Server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Select group that ngx1 user belongs to,&lt;/P&gt;&lt;P&gt;2. Scroll down to tacacs+ setting&lt;/P&gt;&lt;P&gt;3. check "shell(exec)" option&lt;/P&gt;&lt;P&gt;4. check "custom attributes"&lt;/P&gt;&lt;P&gt;5. In the custom attributes window add the custom AV-Pair info in the following format:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;shell:Admin*Admin default-domain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;restart ACS service.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to login again and same result.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone know why?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2008 16:47:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054382#M21170</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-10-13T16:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4700 and Cisco ACS aaa authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054383#M21171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Run the following command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show user-account&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Within this command output what role do you see for the user you are logged in as.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since its not working I suspect it would say&lt;/P&gt;&lt;P&gt;"Network Monitor" (default). If that is the&lt;/P&gt;&lt;P&gt;case then most likely cause is the Cisco AV-Pair information is not entered correctly. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syed Iftekhar Ahmed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2008 17:04:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054383#M21171</guid>
      <dc:creator>Syed Iftekhar Ahmed</dc:creator>
      <dc:date>2008-10-13T17:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4700 and Cisco ACS aaa authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054384#M21172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ACE-lab/Admin# sh user-account | b ngx1&lt;/P&gt;&lt;P&gt;user:ngx1&lt;/P&gt;&lt;P&gt;        roles: Network-Monitor&lt;/P&gt;&lt;P&gt;        domain: default-domain&lt;/P&gt;&lt;P&gt;        Context: Admin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;account created through REMOTE authentication&lt;/P&gt;&lt;P&gt;Local login not possible&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE-lab/Admin#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now how do I go about fixing it?  I followed &lt;/P&gt;&lt;P&gt;the instructions you suggested steps by steps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Oct 2008 17:50:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054384#M21172</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-10-13T17:50:14Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4700 and Cisco ACS aaa authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054385#M21173</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can gurus in this forum help me resolve this&lt;/P&gt;&lt;P&gt;issue?  Thank you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Oct 2008 11:29:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054385#M21173</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-10-15T11:29:19Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4700 and Cisco ACS aaa authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054386#M21174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if your ACS setup has the correct line&lt;/P&gt;&lt;P&gt;shell:Admin*Admin default-domain  with the correct names (case sensitive) then it should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If everything looks good do&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug aaa aaa-req&lt;/P&gt;&lt;P&gt;debug aaa events&lt;/P&gt;&lt;P&gt;debug aaa error&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to login and see what you get.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Oct 2008 11:56:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054386#M21174</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2008-10-15T11:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4700 and Cisco ACS aaa authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054387#M21175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can log in fine with the AAA credential but&lt;/P&gt;&lt;P&gt;I can NOT run any debug aaa commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE-lab login: ngx1&lt;/P&gt;&lt;P&gt;Password:&lt;/P&gt;&lt;P&gt;Cisco Application Control Software (ACSW)&lt;/P&gt;&lt;P&gt;TAC support: &lt;A class="jive-link-custom" href="http://www.cisco.com/tac" target="_blank"&gt;http://www.cisco.com/tac&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Copyright (c) 1985-2007 by Cisco Systems, Inc. All rights reserved.&lt;/P&gt;&lt;P&gt;The copyrights to certain works contained herein are owned by&lt;/P&gt;&lt;P&gt;other third parties and are used and distributed under license.&lt;/P&gt;&lt;P&gt;Some parts of this software are covered under the GNU Public&lt;/P&gt;&lt;P&gt;License. A copy of the license is available at&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.gnu.org/licenses/gpl.html" target="_blank"&gt;http://www.gnu.org/licenses/gpl.html&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;ACE-lab/Admin# conf t&lt;/P&gt;&lt;P&gt;               ^&lt;/P&gt;&lt;P&gt;% invalid command detected at '^' marker.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE-lab/Admin# debug aaa aaa-req&lt;/P&gt;&lt;P&gt;               ^&lt;/P&gt;&lt;P&gt;% invalid command detected at '^' marker.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE-lab/Admin#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Oct 2008 12:35:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054387#M21175</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-10-15T12:35:46Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4700 and Cisco ACS aaa authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054388#M21176</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the debug AAA reveals in the attachment.  Can&lt;/P&gt;&lt;P&gt;someone help?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Oct 2008 12:43:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054388#M21176</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-10-15T12:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4700 and Cisco ACS aaa authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054389#M21177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you do not have any other access to the device ?&lt;/P&gt;&lt;P&gt;What about console ? Do you also run tacacs on console ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;G.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Oct 2008 12:43:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054389#M21177</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2008-10-15T12:43:46Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4700 and Cisco ACS aaa authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054390#M21178</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is what I did:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- configure AAA configuration on the ACE box,&lt;/P&gt;&lt;P&gt;2- go to my Cisco ACS and stop the ACS service.&lt;/P&gt;&lt;P&gt;That enables me to log into the ACE box with &lt;/P&gt;&lt;P&gt;"admin/admin",&lt;/P&gt;&lt;P&gt;3- enable Cisco ACS service on the ACS server,&lt;/P&gt;&lt;P&gt;4- Now I can log into the ACE box with ngx1&lt;/P&gt;&lt;P&gt;account.  However, I can not go into the &lt;/P&gt;&lt;P&gt;"conf t" mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Oct 2008 16:21:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054390#M21178</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-10-15T16:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4700 and Cisco ACS aaa authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054391#M21179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can anyone help?  Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Oct 2008 10:16:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054391#M21179</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-10-16T10:16:13Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4700 and Cisco ACS aaa authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054392#M21180</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;next thing is to get a sniffer trace of the TACACS exchange.&lt;/P&gt;&lt;P&gt;We'll need the key to decode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also try to upgrade to A1(8a) or A3(1.0).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally, a service request with the TAC seems appropriate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Oct 2008 10:39:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054392#M21180</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2008-10-16T10:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4700 and Cisco ACS aaa authentication</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054393#M21181</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found the following in the ACE 4700 release notes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSCsl48103-When the ACE is configured for TACACS+ authentication with a user context and the Cisco ACS sends the cisco-av-pair* attribute before the ACE custom shell attribute, you cannot log in to the ACE via TACACS+ and use the Admin role. Workaround: Do not use the ACE TACACS+ authentication for an Admin role. If you must use TACACS+ authentication for an Admin role, do not configure the Cisco ACS to send the cisco-av-pair* attribute. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/partner/docs/app_ntwk_services/data_center_app_services/ace_appliances/A1_x/release/note/RACEA1X.html" target="_blank"&gt;www.cisco.com/en/US/partner/docs/app_ntwk_services/data_center_app_services/ace_appliances/A1_x/release/note/RACEA1X.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ross&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Oct 2008 01:02:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4700-and-cisco-acs-aaa-authentication/m-p/1054393#M21181</guid>
      <dc:creator>rtanner</dc:creator>
      <dc:date>2008-10-31T01:02:13Z</dc:date>
    </item>
  </channel>
</rss>

