<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA problem in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207149#M116358</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/2/6/139620-Untitled.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;kindly note some other routers ,&amp;nbsp; i can login using ACS account&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 22 May 2013 10:50:41 GMT</pubDate>
    <dc:creator>Amira Saad</dc:creator>
    <dc:date>2013-05-22T10:50:41Z</dc:date>
    <item>
      <title>AAA problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207137#M116346</link>
      <description>&lt;P&gt;I have aaa server can be used to authenticate my router and switches but suddenly when i tried to login to some of my routers using ACS Accounts i got this message "% 1 is not an open connection" but when i remove the authentication using the ACS , i can login locally smothly without any problem &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:27:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207137#M116346</guid>
      <dc:creator>Amira Saad</dc:creator>
      <dc:date>2019-03-11T03:27:09Z</dc:date>
    </item>
    <item>
      <title>AAA problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207138#M116347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Amira,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you paste the activity you perform when you get this message. Also, when you get this message does the authentication is successful or not?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Subeh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 May 2013 17:00:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207138#M116347</guid>
      <dc:creator>Subeh Sharma</dc:creator>
      <dc:date>2013-05-21T17:00:21Z</dc:date>
    </item>
    <item>
      <title>AAA problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207139#M116348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From the problem description, it seems you are facing this issue only when we have AAA configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you attempt to connect and receive an error message "% 1 is not an open connection". Do you also see any corresponding hits on ACS as well?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you turn on the debugs when you have this problem and send it over for my analysis.&lt;/P&gt;&lt;P&gt;(Guess you are using tacacs in case not then use radius)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug tacacs&lt;/P&gt;&lt;P&gt;debug aaa authen&lt;/P&gt;&lt;P&gt;debug aaa autho&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from the router/switch, please provide;&lt;/P&gt;&lt;P&gt;show users&lt;/P&gt;&lt;P&gt;show line&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In case we need to delete any session on the line.&lt;/P&gt;&lt;P&gt;clear tcp line vty &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do provide show run and show version from the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 May 2013 00:17:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207139#M116348</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-22T00:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: AAA problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207140#M116349</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; HI&amp;nbsp; &lt;SPAN style="color: #000000; text-decoration: underline; "&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/people/subsharm" id="jive-5760028117846226189526" style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; outline: none; color: #000000; font-weight: bold; font-family: Arial, verdana, sans-serif;"&gt;Subeh&lt;/A&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&lt;/P&gt;&lt;P&gt;I just try to type the username and pass&amp;nbsp;&amp;nbsp; of my ACS account and this error messgae appear when i type the username and pass and it can not log me in to the router although i tried by my ACS account using the console and i can log in to the router &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 May 2013 06:16:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207140#M116349</guid>
      <dc:creator>Amira Saad</dc:creator>
      <dc:date>2013-05-22T06:16:19Z</dc:date>
    </item>
    <item>
      <title>Re: AAA problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207141#M116350</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jatin &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes i found hits in my ACS administration log &lt;/P&gt;&lt;P&gt;and when i type WHO , i found only my line VTY which i make debug from it&amp;nbsp; through it and attached my debug when authenticate using AAA account &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 May 2013 06:52:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207141#M116350</guid>
      <dc:creator>Amira Saad</dc:creator>
      <dc:date>2013-05-22T06:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: AAA problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207142#M116351</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why we are looking at tacacs administration logs? We need to check tacacs authentication logs i.e failed attempts in case we have ACS 4.x or tacacs authentication in case we have acs 5.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From debugs I can see authentication and authorization successful.&lt;/P&gt;&lt;P&gt;TPLUS: Received authen response status PASS (2)&lt;/P&gt;&lt;P&gt; AAA/AUTHOR/EXEC(00000043): Authorization successful&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I requested show run in my last post. can you please attach the same if not then please provide the below listed outputs:&lt;/P&gt;&lt;P&gt;show run | in aaa&lt;/P&gt;&lt;P&gt;show run | in tacacs&lt;/P&gt;&lt;P&gt;show run | beg line&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 May 2013 08:28:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207142#M116351</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-22T08:28:13Z</dc:date>
    </item>
    <item>
      <title>Re: AAA problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207143#M116352</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes i saw that the authentication is done good but my status was after cuting of power to all my data center and i was able to use my aaa account before this incident smoothly , attached the requested show&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 May 2013 08:39:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207143#M116352</guid>
      <dc:creator>Amira Saad</dc:creator>
      <dc:date>2013-05-22T08:39:39Z</dc:date>
    </item>
    <item>
      <title>Re: AAA problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207144#M116353</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The configuration looks fine. I see the vty lines are configured for line password and privilege but aaa commands shows you have local method in place.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;did you try to clear the tcp session?&lt;/P&gt;&lt;P&gt;can you run turn on the debugs &lt;STRONG style="text-decoration: underline; "&gt;( we don't need debug aaa accounting)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;debug tacacs&lt;/P&gt;&lt;P&gt;debug aaa authentication&lt;/P&gt;&lt;P&gt;debug aaa authorization&lt;/P&gt;&lt;P&gt;run the below listed command with tacacs username and password.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;test aaa group tacacs+ &lt;USENAME&gt; &lt;PASSWORD&gt; leg&lt;/PASSWORD&gt;&lt;/USENAME&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 May 2013 09:22:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207144#M116353</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-22T09:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: AAA problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207145#M116354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;when i tried to clear TCP line vty , i got the following :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*May 22 10:12:19.463: AAA/AUTHOR: auth_need : user= 'blombank' ruser= 'HQ_VocieGW1'rem_addr= '10.30.28.1' priv= 15 list= '' AUTHOR-TYPE= 'command'&lt;/P&gt;&lt;P&gt;*May 22 10:12:19.463: TPLUS: Queuing AAA Accounting request 50 for processing&lt;/P&gt;&lt;P&gt;*May 22 10:12:19.463: TPLUS: processing accounting request id 50&lt;/P&gt;&lt;P&gt;*May 22 10:12:19.463: TPLUS: Sending AV task_id=297&lt;/P&gt;&lt;P&gt;*May 22 10:12:19.467: TPLUS: Sending AV timezone=UTC&lt;/P&gt;&lt;P&gt;*May 22 10:12:19.467: TPLUS: Sending AV service=shell&lt;/P&gt;&lt;P&gt;*May 22 10:12:19.467: TPLUS: Sending AV priv-lvl=15&lt;/P&gt;&lt;P&gt;*May 22 10:12:19.467: TPLUS: Sending AV cmd=clear tcp line vty 0 &lt;CR&gt;&lt;/CR&gt;&lt;/P&gt;&lt;P&gt;*May 22 10:12:19.467: TPLUS: Accounting request created for 50(blombank)&lt;/P&gt;&lt;P&gt;*May 22 10:12:19.467: TPLUS: using previously set server 10.7.11.112 from group tacacs+&lt;/P&gt;&lt;P&gt;*May 22 10:12:19.467: TPLUS(00000032)/0/NB_WAIT/78472D48: Started 5 sec timeout&lt;/P&gt;&lt;P&gt;*May 22 10:12:19.467: TPLUS(00000032)/0/NB_WAIT: socket event 2&lt;/P&gt;&lt;P&gt;*May 22 10:12:19.467: TPLUS(00000032)/0/NB_WAIT: wrote entire 126 bytes request&lt;/P&gt;&lt;P&gt;*May 22 10:12:19.467: TPLUS(00000032)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;*May 22 10:12:19.467: TPLUS(00000032)/0/READ: Would block while reading&lt;/P&gt;&lt;P&gt;*May 22 10:12:19.551: TPLUS(00000032)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;*May 22 10:12:19.551: TPLUS(00000032)/0/READ: read entire 12 header bytes (expect 5 bytes data)&lt;/P&gt;&lt;P&gt;*May 22 10:12:19.551: TPLUS(00000032)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;[confirm]&lt;/P&gt;&lt;P&gt;*May 22 10:12:19.551: TPLUS(00000032)/0/READ: read entire 17 bytes response&lt;/P&gt;&lt;P&gt;*May 22 10:12:19.551: TPLUS(00000032)/0/78472D48: Processing the reply packet&lt;/P&gt;&lt;P&gt;*May 22 10:12:19.551: TPLUS: Received accounting response with status PASS&lt;/P&gt;&lt;P&gt;[confirm]&lt;/P&gt;&lt;P&gt;%Clear TCP failed: line 706 doesn't exist or doesn't have TCP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and attached the debug output &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 May 2013 09:58:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207145#M116354</guid>
      <dc:creator>Amira Saad</dc:creator>
      <dc:date>2013-05-22T09:58:50Z</dc:date>
    </item>
    <item>
      <title>AAA problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207146#M116355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the attached debugs were not captured correctly. I don't see the authentication and authorization debugs for a test.&lt;/P&gt;&lt;P&gt;What did you see on the router, when you ran the test command?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 May 2013 10:15:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207146#M116355</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-22T10:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: AAA problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207147#M116356</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the test command can not be applied on router &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOTE : some of other router which authenticate using ACS account is working but others not &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;kindly find attached &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 May 2013 10:24:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207147#M116356</guid>
      <dc:creator>Amira Saad</dc:creator>
      <dc:date>2013-05-22T10:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: AAA problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207148#M116357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please check ACS user/group setup and see if there is some auto-command configured?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 May 2013 10:33:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207148#M116357</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-22T10:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: AAA problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207149#M116358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/2/6/139620-Untitled.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;kindly note some other routers ,&amp;nbsp; i can login using ACS account&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 May 2013 10:50:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207149#M116358</guid>
      <dc:creator>Amira Saad</dc:creator>
      <dc:date>2013-05-22T10:50:41Z</dc:date>
    </item>
    <item>
      <title>Re: AAA problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207150#M116359</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you jatin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you very much &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;really when i removed the auto command check box all is ok now with me &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 May 2013 12:38:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207150#M116359</guid>
      <dc:creator>Amira Saad</dc:creator>
      <dc:date>2013-05-22T12:38:04Z</dc:date>
    </item>
    <item>
      <title>Re: AAA problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207151#M116360</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Amira,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, I see this coming in your tacacs authorization Response and I am not sure why we are pushing this value in autocmd. Also mark this thread resolved so that other's can take benefit out of it, in case they are facing the same issue.&lt;/P&gt;&lt;P&gt;have a blessed day.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 May 2013 12:42:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem/m-p/2207151#M116360</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-22T12:42:18Z</dc:date>
    </item>
  </channel>
</rss>

