<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA on ACE in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/aaa-on-ace/m-p/1346968#M28035</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, its the second case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can login with my AAA credentials but not previleged.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please clear this a little more.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is the second case, in the ACS, dont forget to add the TACACS+ Settings / Custom Attributes: &lt;/P&gt;&lt;P&gt;shell:Admin*Admin default-domain (for default). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Tacacs+ settings, where do i have make thses changes?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Akhil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 17 Jul 2009 05:41:49 GMT</pubDate>
    <dc:creator>akhil.abrol</dc:creator>
    <dc:date>2009-07-17T05:41:49Z</dc:date>
    <item>
      <title>AAA on ACE</title>
      <link>https://community.cisco.com/t5/application-networking/aaa-on-ace/m-p/1346964#M28031</link>
      <description>&lt;P&gt;Dear experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to enable aaa authentication on Cisco ACE 4710 and unable to do that. Please help me with this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the config i have done on the ACE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server key 7 "vdepw@cffgG1tplDU"&lt;/P&gt;&lt;P&gt;tacacs-server host 172.18.124.20 key 7 "vdepw@cffgG1tplDU"&lt;/P&gt;&lt;P&gt;tacacs-server host 172.18.124.21 key 7 "vdepw@cffgG1tplDU"&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ TACACS+_Server_Group1&lt;/P&gt;&lt;P&gt;  server 172.18.124.20&lt;/P&gt;&lt;P&gt;  server 172.18.124.21&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default group TACACS+_Server_Group1 local&lt;/P&gt;&lt;P&gt;aaa authentication login error-enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I added the entry for ACE in ACS but still its not authenticating.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Akhil&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2009 06:15:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/aaa-on-ace/m-p/1346964#M28031</guid>
      <dc:creator>akhil.abrol</dc:creator>
      <dc:date>2009-07-16T06:15:52Z</dc:date>
    </item>
    <item>
      <title>Re: AAA on ACE</title>
      <link>https://community.cisco.com/t5/application-networking/aaa-on-ace/m-p/1346965#M28032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are the ACS IP Addresses reachable from your ACE? &lt;/P&gt;&lt;P&gt;Do you see failed attempts on your ACS? &lt;/P&gt;&lt;P&gt;Is your Tacacs server using port 49, which is used by the ACE by default?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Dario&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jul 2009 06:32:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/aaa-on-ace/m-p/1346965#M28032</guid>
      <dc:creator>dario.didio</dc:creator>
      <dc:date>2009-07-16T06:32:14Z</dc:date>
    </item>
    <item>
      <title>Re: AAA on ACE</title>
      <link>https://community.cisco.com/t5/application-networking/aaa-on-ace/m-p/1346966#M28033</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, ACS is reachable from all 4 ACEs. I specifically opened a policy in the firewall to check the traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cant see any failed attempts and yes the ACS server is using default port 49. i did a telnet test from ACE to ACS in 49 and it was successful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Akhil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jul 2009 06:35:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/aaa-on-ace/m-p/1346966#M28033</guid>
      <dc:creator>akhil.abrol</dc:creator>
      <dc:date>2009-07-16T06:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: AAA on ACE</title>
      <link>https://community.cisco.com/t5/application-networking/aaa-on-ace/m-p/1346967#M28034</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By not working, what do you mean? FOr example, does your username/password not work at all? Or the username/password does work but with limited privs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is the second case, in the ACS, dont forget to add the TACACS+ Settings / Custom Attributes:&lt;/P&gt;&lt;P&gt;shell:Admin*Admin default-domain (for default).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note - if you are doing IOS authorization on any other device which this user is a part of, ensure the "*" is there or you may get the ACE AAA functional, but now IOS devices will give you fits.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Jul 2009 19:10:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/aaa-on-ace/m-p/1346967#M28034</guid>
      <dc:creator>mherald</dc:creator>
      <dc:date>2009-07-16T19:10:54Z</dc:date>
    </item>
    <item>
      <title>Re: AAA on ACE</title>
      <link>https://community.cisco.com/t5/application-networking/aaa-on-ace/m-p/1346968#M28035</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, its the second case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can login with my AAA credentials but not previleged.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please clear this a little more.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is the second case, in the ACS, dont forget to add the TACACS+ Settings / Custom Attributes: &lt;/P&gt;&lt;P&gt;shell:Admin*Admin default-domain (for default). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Tacacs+ settings, where do i have make thses changes?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Akhil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jul 2009 05:41:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/aaa-on-ace/m-p/1346968#M28035</guid>
      <dc:creator>akhil.abrol</dc:creator>
      <dc:date>2009-07-17T05:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: AAA on ACE</title>
      <link>https://community.cisco.com/t5/application-networking/aaa-on-ace/m-p/1346969#M28036</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have to use a custom AV pair on TACACS server under user setup to make it work. ACE uses RBAC (role based Access Control) and for that you have to pass the context and User Role from Tacacs server to ACE to make it work.If there is no RBAC info is pushed from Tacacs server and user just get authenticated then the default role assigned by ACE is Network-Monitor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following steps (On tacacs server) will make it work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Select your user&lt;/P&gt;&lt;P&gt;2. goto tacas+ settings&lt;/P&gt;&lt;P&gt;3. Select " shell (exec)" checkbox&lt;/P&gt;&lt;P&gt;4. Select "custom attributes" checkbox&lt;/P&gt;&lt;P&gt;5. Type your context and role information in custom attrib box, using following format&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;shell:&lt;CONTEXTNAME&gt;*&lt;ROLE&gt; &lt;DOMAIN1&gt;&lt;/DOMAIN1&gt;&lt;/ROLE&gt;&lt;/CONTEXTNAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for e.g (if context name is Admin, domain is default-domain and you want to assign role "Admin" to this user )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;shell:Admin*Admin default-domain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For more information&lt;/P&gt;&lt;P&gt;Please read One of my old post on this topic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Network%20Infrastructure&amp;amp;topic=LAN%2C%20Switching%20and%20Routing&amp;amp;topicID=.ee71a04&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.2cc10b80/3#selected_message" target="_blank"&gt;http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&amp;amp;forum=Network%20Infrastructure&amp;amp;topic=LAN%2C%20Switching%20and%20Routing&amp;amp;topicID=.ee71a04&amp;amp;CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.2cc10b80/3#selected_message&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps&lt;/P&gt;&lt;P&gt;Syed Iftekhar Ahmed &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jul 2009 06:52:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/aaa-on-ace/m-p/1346969#M28036</guid>
      <dc:creator>Syed Iftekhar Ahmed</dc:creator>
      <dc:date>2009-07-17T06:52:51Z</dc:date>
    </item>
    <item>
      <title>Re: AAA on ACE</title>
      <link>https://community.cisco.com/t5/application-networking/aaa-on-ace/m-p/1346970#M28037</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thats why i wrote dear "Experts" &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually the custom attributes option was not enabled in the interface configuration. So i searched it and checked it there..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Akhil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Jul 2009 07:24:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/aaa-on-ace/m-p/1346970#M28037</guid>
      <dc:creator>akhil.abrol</dc:creator>
      <dc:date>2009-07-17T07:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: AAA on ACE</title>
      <link>https://community.cisco.com/t5/application-networking/aaa-on-ace/m-p/1346971#M28038</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After doing the changes, i cannot loging to my other network devices. Is there a way out for this or I need to create a seperate ID for ACE.?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Akhil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Jul 2009 06:42:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/aaa-on-ace/m-p/1346971#M28038</guid>
      <dc:creator>akhil.abrol</dc:creator>
      <dc:date>2009-07-18T06:42:17Z</dc:date>
    </item>
  </channel>
</rss>

