<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ANM 5.2 authentication failure in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/anm-5-2-authentication-failure/m-p/2145954#M39596</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I'm using tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Follow bellow the tacacs configuration from my switch:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authentication login no_tacacs enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ none&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ none&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 0 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting network default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting network acct_methods start-stop group rad_acct&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authentication login no_tacacs enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ none&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ none&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 0 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting network default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting network acct_methods start-stop group rad_acct&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Apr 2013 16:39:23 GMT</pubDate>
    <dc:creator>mello.thiago</dc:creator>
    <dc:date>2013-04-16T16:39:23Z</dc:date>
    <item>
      <title>ANM 5.2 authentication failure</title>
      <link>https://community.cisco.com/t5/application-networking/anm-5-2-authentication-failure/m-p/2145952#M39594</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm using the Cisco ANM 5.2 version and I'm trying to import the configurations from ACE modules of Cisco switches. The first step is to import the configuration from Cisco switch and the second one is to import the ACE module in the ANM software. I'm getting an authentication problem to import the configuration from Cisco switch and of course I cannot import the ACE as well. The switches and the ACE are using AAA authentication and I have created a specific username to authenticate and import the configurations in the ANM. If I remove the AAA configurations from the switches and ACE modules it works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has everyone some idea? Is there some problem with the AAA configurations in the switches or ACE module?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2013 12:29:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/anm-5-2-authentication-failure/m-p/2145952#M39594</guid>
      <dc:creator>mello.thiago</dc:creator>
      <dc:date>2013-04-16T12:29:45Z</dc:date>
    </item>
    <item>
      <title>ANM 5.2 authentication failure</title>
      <link>https://community.cisco.com/t5/application-networking/anm-5-2-authentication-failure/m-p/2145953#M39595</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, Are you using tacacs+ ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate useful posts and remember to mark any solved questions as answered. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 13:02:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/anm-5-2-authentication-failure/m-p/2145953#M39595</guid>
      <dc:creator>Bilal Nawaz</dc:creator>
      <dc:date>2013-04-16T13:02:58Z</dc:date>
    </item>
    <item>
      <title>Re: ANM 5.2 authentication failure</title>
      <link>https://community.cisco.com/t5/application-networking/anm-5-2-authentication-failure/m-p/2145954#M39596</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I'm using tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Follow bellow the tacacs configuration from my switch:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authentication login no_tacacs enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ none&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ none&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 0 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting network default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting network acct_methods start-stop group rad_acct&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authentication login no_tacacs enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ none&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ none&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 0 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting network default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting network acct_methods start-stop group rad_acct&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 16:39:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/anm-5-2-authentication-failure/m-p/2145954#M39596</guid>
      <dc:creator>mello.thiago</dc:creator>
      <dc:date>2013-04-16T16:39:23Z</dc:date>
    </item>
    <item>
      <title>Re: ANM 5.2 authentication failure</title>
      <link>https://community.cisco.com/t5/application-networking/anm-5-2-authentication-failure/m-p/2145955#M39597</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So I assume that ACS has been set up correctly to allow authentication? Can you confirm this please or show us the configurations made in ACS to allow aaa to work.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 17:27:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/anm-5-2-authentication-failure/m-p/2145955#M39597</guid>
      <dc:creator>Bilal Nawaz</dc:creator>
      <dc:date>2013-04-16T17:27:47Z</dc:date>
    </item>
    <item>
      <title>ANM 5.2 authentication failure</title>
      <link>https://community.cisco.com/t5/application-networking/anm-5-2-authentication-failure/m-p/2145956#M39598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Yes, the ACS is configured correctly. The username and password that I set up there can authenticate with any device in my environment through telnet or ssh.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2013 01:27:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/anm-5-2-authentication-failure/m-p/2145956#M39598</guid>
      <dc:creator>mello.thiago</dc:creator>
      <dc:date>2013-04-17T01:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: ANM 5.2 authentication failure</title>
      <link>https://community.cisco.com/t5/application-networking/anm-5-2-authentication-failure/m-p/2145957#M39599</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would configure like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ TACACS+&lt;/P&gt;&lt;P&gt; server x.x.x.x&lt;/P&gt;&lt;P&gt; server x.x.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login TACACS+ group tacacs+ group radius local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;tacacs-server host x.x.x.x&lt;/P&gt;&lt;P&gt;tacacs-server host x.x.x.x&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;tacacs-server key 7 XXXXXXXXXXXXX&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Where the tacacs-server key is the AAA key specified in ACS&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt;login authentication TACACS+&lt;/P&gt;&lt;P&gt;line vty 5 15&lt;/P&gt;&lt;P&gt; password 7 XXXXXXXXXXXXXX&lt;/P&gt;&lt;P&gt; login authentication FOS_TACACS+&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/9/2/9/135929-untitled.bmp" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;This is only the 6500 configuration, The ACE is a bit different and more complex in ACS as the shell profile needs to be tweaked to get it working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets just get tacacs working on the switch for now...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate useful posts and remember to mark any solved questions as answered. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2013 08:23:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/anm-5-2-authentication-failure/m-p/2145957#M39599</guid>
      <dc:creator>Bilal Nawaz</dc:creator>
      <dc:date>2013-04-17T08:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: ANM 5.2 authentication failure</title>
      <link>https://community.cisco.com/t5/application-networking/anm-5-2-authentication-failure/m-p/2145958#M39600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/7/4/9/135947-ANM%20error.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;I tried this configuration on the switch but it doesn't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I getting the same error in the ANM software as show above. The message is about a problem with authentication credentials. I have applied the configuration that you told me on the switch, the same username that I set up in the ACS and ANM works fine through telnet with this config.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2013 12:40:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/anm-5-2-authentication-failure/m-p/2145958#M39600</guid>
      <dc:creator>mello.thiago</dc:creator>
      <dc:date>2013-04-17T12:40:19Z</dc:date>
    </item>
    <item>
      <title>Re: ANM 5.2 authentication failure</title>
      <link>https://community.cisco.com/t5/application-networking/anm-5-2-authentication-failure/m-p/2145959#M39601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So I think I understand, TACACS+ is working for the 6500 and the ACE module, but its not working for the ANM...?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so, this document might be able to help you:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/application_networking_manager/5.2/user/guide/UG_admin.html"&gt;http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/application_networking_manager/5.2/user/guide/UG_admin.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate useful posts and remember to mark any solved questions as answered. Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Apr 2013 19:50:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/anm-5-2-authentication-failure/m-p/2145959#M39601</guid>
      <dc:creator>Bilal Nawaz</dc:creator>
      <dc:date>2013-04-19T19:50:20Z</dc:date>
    </item>
  </channel>
</rss>

