<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA on WebUI 4710 in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/aaa-on-webui-4710/m-p/1130980#M23307</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Exactly my issue too, which begs the question of what the "ft-port" command actually does if you don't need it to get FT working...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrew.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 22 Oct 2008 14:57:54 GMT</pubDate>
    <dc:creator>andrew.burns</dc:creator>
    <dc:date>2008-10-22T14:57:54Z</dc:date>
    <item>
      <title>AAA on WebUI 4710</title>
      <link>https://community.cisco.com/t5/application-networking/aaa-on-webui-4710/m-p/1130975#M23302</link>
      <description>&lt;P&gt;I have AAA configured and working on an ACE 4710 appliance for SSH. The web interface only works with the local database. I don't see anything in the security guide about the web interface (only states telnet and ssh). Anyone else seeing this?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Oct 2008 13:24:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/aaa-on-webui-4710/m-p/1130975#M23302</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2008-10-22T13:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: AAA on WebUI 4710</title>
      <link>https://community.cisco.com/t5/application-networking/aaa-on-webui-4710/m-p/1130976#M23303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Collin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It does work - I have two in our lab that I've set up for AAA and it works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check this out:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/ace_appliances/vA3_1_0/configuration/device_manager/guide/UGadmin.html#wp1244296" target="_blank"&gt;http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/ace_appliances/vA3_1_0/configuration/device_manager/guide/UGadmin.html#wp1244296&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I only have one local user (admin) and all others on ACS Server, using this test ACE config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host 1.2.3.4 key cisco&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ TACACS&lt;/P&gt;&lt;P&gt;  server 1.2.3.4&lt;/P&gt;&lt;P&gt;aaa authentication login default group TACACS local &lt;/P&gt;&lt;P&gt;aaa authentication login console none &lt;/P&gt;&lt;P&gt;aaa accounting default group TACACS local &lt;/P&gt;&lt;P&gt;aaa authentication login error-enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS Server needs some special config though, which is detailed here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/ace_appliances/vA3_1_0/configuration/security/guide/aaa.html#wp1411787" target="_blank"&gt;http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/ace_appliances/vA3_1_0/configuration/security/guide/aaa.html#wp1411787&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Andrew.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2008 14:12:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/aaa-on-webui-4710/m-p/1130976#M23303</guid>
      <dc:creator>andrew.burns</dc:creator>
      <dc:date>2008-10-22T14:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: AAA on WebUI 4710</title>
      <link>https://community.cisco.com/t5/application-networking/aaa-on-webui-4710/m-p/1130977#M23304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Andrew-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had the correct config, except for the following line-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa accounting default group TACACS local &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't understand how accounting would enable the WebUI AAA access, but it works now. Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Two ACEs in your lab? Lucky dog!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2008 14:22:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/aaa-on-webui-4710/m-p/1130977#M23304</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2008-10-22T14:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: AAA on WebUI 4710</title>
      <link>https://community.cisco.com/t5/application-networking/aaa-on-webui-4710/m-p/1130978#M23305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;that wouldn't be the first bit of CLI weirdness - I need two ACE's to validate that the FT works and I've yet to have an explanation of why I need to change the native VLAN to get FT working....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrew.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2008 14:29:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/aaa-on-webui-4710/m-p/1130978#M23305</guid>
      <dc:creator>andrew.burns</dc:creator>
      <dc:date>2008-10-22T14:29:50Z</dc:date>
    </item>
    <item>
      <title>Re: AAA on WebUI 4710</title>
      <link>https://community.cisco.com/t5/application-networking/aaa-on-webui-4710/m-p/1130979#M23306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had some trouble with FT as well and opened a case up. I was configuring FT as below-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface gigabitEthernet 1/3&lt;/P&gt;&lt;P&gt;  description FT Access Port&lt;/P&gt;&lt;P&gt;  speed 100M&lt;/P&gt;&lt;P&gt;  duplex FULL&lt;/P&gt;&lt;P&gt;  ft-port vlan 200  &lt;/P&gt;&lt;P&gt;  no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was receiving a ton of errors on my switch ports. I hard set everything, auto everything, and still a bunch of errors. I then tried to trunk on my switch ports and they came up just fine. In the WebUI I could not set the port to trunk or switch (both grayed out) and I got an error stating it was an FT port and you can't configure it. After some more troubleshooting, we found out that the ft-port command forces the port in trunk mode (TAC wanted the port in switchport mode). By removing the ft-port command, you can set the port to switchport and set it to whatever vlan you want. Here is my current working port config-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface gigabitEthernet 1/3&lt;/P&gt;&lt;P&gt;  description FT Access Port&lt;/P&gt;&lt;P&gt;  speed 100M&lt;/P&gt;&lt;P&gt;  duplex FULL&lt;/P&gt;&lt;P&gt;  switchport access vlan 200&lt;/P&gt;&lt;P&gt;  no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I asked for an explanation, they stated that the fact about the ft-port forces it to trunk and that option is there in case you want to trunk your FT traffic with your data traffic!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2008 14:39:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/aaa-on-webui-4710/m-p/1130979#M23306</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2008-10-22T14:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: AAA on WebUI 4710</title>
      <link>https://community.cisco.com/t5/application-networking/aaa-on-webui-4710/m-p/1130980#M23307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Exactly my issue too, which begs the question of what the "ft-port" command actually does if you don't need it to get FT working...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrew.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Oct 2008 14:57:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/aaa-on-webui-4710/m-p/1130980#M23307</guid>
      <dc:creator>andrew.burns</dc:creator>
      <dc:date>2008-10-22T14:57:54Z</dc:date>
    </item>
  </channel>
</rss>

