<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Trouble with AAA IOS XR in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/trouble-with-aaa-ios-xr/m-p/2264139#M136018</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not sure your problem got resolved. But looks like the server is not in the same VRF.&lt;/P&gt;&lt;P&gt;Please mention the server group also in the same VRF. you will see packet traverse happily.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 Oct 2013 05:03:50 GMT</pubDate>
    <dc:creator>narvenka</dc:creator>
    <dc:date>2013-10-22T05:03:50Z</dc:date>
    <item>
      <title>Trouble with AAA IOS XR</title>
      <link>https://community.cisco.com/t5/network-access-control/trouble-with-aaa-ios-xr/m-p/2264130#M135981</link>
      <description>&lt;P&gt;We have an ASR 9010 with IOS XR, and we are making the configuration to connect to a tacacs+ server, this tacacs+ server works and is givins service to many other MPLS equipments. We have been following the guide:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 24pt; font-family: Univers-CondensedBold; "&gt;&lt;STRONG style="font-size: 24pt; font-family: Univers-CondensedBold; "&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P align="left"&gt;Configuring AAA Services on&lt;/P&gt;&lt;P&gt;Cisco ASR 9000 Series Routers&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 24pt; font-family: Univers-CondensedBold; "&gt;&lt;STRONG style="font-size: 24pt; font-family: Univers-CondensedBold; "&gt; &lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but we have had a lot of troubles, in fact we have loose the administration of the box, at this moment the only lines that are in the ASR900 are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The config of tacacs:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs source-interface Loopback10 vrf OAM&lt;/P&gt;&lt;P&gt;tacacs-server host 150.119.1.110 port 49&lt;/P&gt;&lt;P&gt;key 7 0505110E317F0E&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;the config of AAA:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization commands console none&lt;/P&gt;&lt;P&gt;aaa authentication login console local&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local line&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Communication up between the tacacs+ and the ASR:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASR TO TACACS+&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:ED_MEX_1#&lt;STRONG&gt;ping vrf OAM 150.119.1.110&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Tue Jun 11 13:33:27.477 UTC&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 150.119.1.110, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;!!!!!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:ED_MEX_1#&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TACACS+ TO ASR:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs@tacti:~$ &lt;STRONG&gt;ping 172.16.162.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;PING 172.16.162.1 (172.16.162.1) 56(84) bytes of data.&lt;/P&gt;&lt;P&gt;64 bytes from 172.16.162.1: icmp_req=1 ttl=252 time=1.35 ms&lt;/P&gt;&lt;P&gt;64 bytes from 172.16.162.1: icmp_req=2 ttl=252 time=0.605 ms&lt;/P&gt;&lt;P&gt;64 bytes from 172.16.162.1: icmp_req=3 ttl=252 time=0.587 ms&lt;/P&gt;&lt;P&gt;64 bytes from 172.16.162.1: icmp_req=4 ttl=252 time=0.787 ms&lt;/P&gt;&lt;P&gt;64 bytes from 172.16.162.1: icmp_req=5 ttl=252 time=0.649 ms&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:ED_MEX_1(config)#&lt;STRONG&gt;do sh tacac&lt;/STRONG&gt;&lt;BR /&gt;Tue Jun 11 19:41:23.918 UTC&lt;/P&gt;&lt;P&gt;Server: 150.119.1.110/49 opens=0 closes=0 aborts=0 errors=0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; packets in=0 packets out=0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; status=up single-connect=false&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:ED_MEX_1(config)#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;RP/0/RSP0/CPU0:ED_MEX_1#sh ver&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Tue Jun 11 13:37:26.105 UTC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco IOS XR Software, Version 4.2.3[Default]&lt;/P&gt;&lt;P&gt;Copyright (c) 2012 by Cisco Systems, Inc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ROM: System Bootstrap, Version 0.62(c) 1994-2012 by Cisco Systems,&amp;nbsp; Inc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ED_MEX_1 uptime is 3 days, 23 hours, 42 minutes&lt;/P&gt;&lt;P&gt;System image file is "disk0:asr9k-os-mbi-4.2.3.CSCuc79084-1.0.0/0x100305/mbiasr9k-rsp3.vm&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cisco ASR9K Series (Intel 686 F6M14S4) processor with 6291456K bytes of memory.&lt;/P&gt;&lt;P&gt;Intel 686 F6M14S4 processor at 2128MHz, Revision 2.174&lt;/P&gt;&lt;P&gt;ASR 9010 AC Chassis with PEM Version 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4 Management Ethernet&lt;/P&gt;&lt;P&gt;20 DWDM controller(s)&lt;/P&gt;&lt;P&gt;20 TenGigE&lt;/P&gt;&lt;P&gt;20 WANPHY controller(s)&lt;/P&gt;&lt;P&gt;40 GigabitEthernet&lt;/P&gt;&lt;P&gt;503k bytes of non-volatile configuration memory.&lt;/P&gt;&lt;P&gt;6271M bytes of hard disk.&lt;/P&gt;&lt;P&gt;11817968k bytes of disk0: (Sector size 512 bytes).&lt;/P&gt;&lt;P&gt;11817968k bytes of disk1: (Sector size 512 bytes).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we need a little help please.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;Maru&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:30:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trouble-with-aaa-ios-xr/m-p/2264130#M135981</guid>
      <dc:creator>MARIA EUGENIA RUIZ</dc:creator>
      <dc:date>2019-03-26T00:30:22Z</dc:date>
    </item>
    <item>
      <title>Trouble with AAA IOS XR</title>
      <link>https://community.cisco.com/t5/network-access-control/trouble-with-aaa-ios-xr/m-p/2264131#M135984</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Maru,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you see any logs on the TACACS+ server? Which version of AAA server are you using?Also do you have any ACL which is set on VTY?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Najaf&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Please rate when applicable or helpful !!!&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 01:46:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trouble-with-aaa-ios-xr/m-p/2264131#M135984</guid>
      <dc:creator>kcnajaf</dc:creator>
      <dc:date>2013-06-12T01:46:33Z</dc:date>
    </item>
    <item>
      <title>Trouble with AAA IOS XR</title>
      <link>https://community.cisco.com/t5/network-access-control/trouble-with-aaa-ios-xr/m-p/2264132#M135990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; hi Najaf, thanks for reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; The version is:&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:tacacs@tacti:/etc/tacacs+/bin$"&gt;tacacs@tacti:/etc/tacacs+/bin$&lt;/A&gt; &lt;/P&gt;&lt;P&gt;tac_plus -v&lt;/P&gt;&lt;P&gt;tac_plus version F4.0.4.19&lt;/P&gt;&lt;P&gt;ACLS&lt;/P&gt;&lt;P&gt;FIONBIO&lt;/P&gt;&lt;P&gt;LIBWRAP&lt;/P&gt;&lt;P&gt;LINUX&lt;/P&gt;&lt;P&gt;LITTLE_ENDIAN&lt;/P&gt;&lt;P&gt;LOG_DAEMON&lt;/P&gt;&lt;P&gt;MAXSESS&lt;/P&gt;&lt;P&gt;MAXSESS_FINGER&lt;/P&gt;&lt;P&gt;PAM&lt;/P&gt;&lt;P&gt;NO_PWAGE&lt;/P&gt;&lt;P&gt;REAPCHILD&lt;/P&gt;&lt;P&gt;RETSIGTYPE RETSIGTYPE&lt;/P&gt;&lt;P&gt;SHADOW_PASSWORDS&lt;/P&gt;&lt;P&gt;SIGTSTP&lt;/P&gt;&lt;P&gt;SIGTTIN&lt;/P&gt;&lt;P&gt;SIGTTOU&lt;/P&gt;&lt;P&gt;SO_REUSEADDR&lt;/P&gt;&lt;P&gt;STRERROR&lt;/P&gt;&lt;P&gt;TAC_PLUS_PORT&lt;/P&gt;&lt;P&gt;UENABLE&lt;/P&gt;&lt;P&gt;__STDC__&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:tacacs@tacti:/etc/tacacs+/bin$"&gt;tacacs@tacti:/etc/tacacs+/bin$&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the tacacs+ server does not known about the asr trying to connect, the tacacs+ server doen not reflects any message in its debug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is not any access list over the line vty.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maru.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 02:16:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trouble-with-aaa-ios-xr/m-p/2264132#M135990</guid>
      <dc:creator>MARIA EUGENIA RUIZ</dc:creator>
      <dc:date>2013-06-12T02:16:14Z</dc:date>
    </item>
    <item>
      <title>Trouble with AAA IOS XR</title>
      <link>https://community.cisco.com/t5/network-access-control/trouble-with-aaa-ios-xr/m-p/2264133#M135996</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Maru,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Personally i have not worked on UNIX based tacacs:-(. Still it would worth checking below points.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; Your sourcing the tacacs traffic from loopback 10. So have you checked pinging the tacacs server with source as loopback10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; I assume you already added loopback 10 ip address as a aaa client on your tacacs box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; sh tacacs output shows there is no packets send or received. Have you checked with "debug aaa authetication" and see if there is any usual infromation which you are able to get.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Najaf&lt;/P&gt;&lt;P&gt;&lt;EM style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;Please rate when applicable or helpful !!!&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 04:00:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trouble-with-aaa-ios-xr/m-p/2264133#M135996</guid>
      <dc:creator>kcnajaf</dc:creator>
      <dc:date>2013-06-12T04:00:51Z</dc:date>
    </item>
    <item>
      <title>Re: Trouble with AAA IOS XR</title>
      <link>https://community.cisco.com/t5/network-access-control/trouble-with-aaa-ios-xr/m-p/2264134#M136001</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you're not seeing any message or logs on tacacs server then it's highly possible that your tacacs is unreachable via Loopback10 or the TCP port 49 is blocked somewhere in between. What all devices we have in the route? Is there any firewall? Was this working before?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please turn on the following debugs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug tacacs&lt;/P&gt;&lt;P&gt;debug aaa authen&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Run the command from ASR CLI (if available)&lt;/P&gt;&lt;P&gt;test aaa group tacacs+ username password leg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paste the output here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; *Do rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 08:44:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trouble-with-aaa-ios-xr/m-p/2264134#M136001</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-06-12T08:44:01Z</dc:date>
    </item>
    <item>
      <title>Trouble with AAA IOS XR</title>
      <link>https://community.cisco.com/t5/network-access-control/trouble-with-aaa-ios-xr/m-p/2264135#M136006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Najaf,&lt;/P&gt;&lt;P&gt;sure we tryed the ping since the loop10, and it works:!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:ED_MEX_1#sh run int loop 10&lt;BR /&gt;Wed Jun 12 09:11:57.314 UTC&lt;BR /&gt;&lt;STRONG&gt;interface Loopback10&lt;/STRONG&gt;&lt;BR /&gt; &lt;STRONG&gt;vrf OAM&lt;/STRONG&gt;&lt;BR /&gt; ipv4 address 172.16.162.1 255.255.255.255&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:ED_MEX_1#&lt;STRONG&gt;ping vrf OAM&lt;/STRONG&gt;&lt;BR /&gt;Wed Jun 12 09:12:03.304 UTC&lt;BR /&gt;Protocol [ipv4]:&lt;BR /&gt;Target IP address: 150.119.1.110&lt;BR /&gt;Repeat count [5]:&lt;BR /&gt;Datagram size [100]:&lt;BR /&gt;Timeout in seconds [2]:&lt;BR /&gt;Extended commands? [no]: y&lt;BR /&gt;Source address or interface: 172.16.162.1&lt;BR /&gt;Type of service [0]:&lt;BR /&gt;Set DF bit in IP header? [no]:&lt;BR /&gt;Validate reply data? [no]:&lt;BR /&gt;Data pattern [0xABCD]:&lt;BR /&gt;Loose, Strict, Record, Timestamp, Verbose[none]:&lt;BR /&gt;Sweep range of sizes? [no]:&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 150.119.1.110, timeout is 2 seconds:&lt;BR /&gt;&lt;STRONG&gt;!!!!!&lt;/STRONG&gt;&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms&lt;BR /&gt;RP/0/RSP0/CPU0:ED_MEX_1#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in the case of the tacacs box, there is communication between them so we don´t have to do anything else, only if the tacacs box doesnot see the ASR we insert te net to the box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the tacacs+ server doesnot reflect any debug, but the asr send all this message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:12.284 : exec[65847]: Getting details on ttyname '/dev/vty1'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:12.286 : exec[65847]: Failed to read vty1/username from SysDB&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:12.361 : exec[65847]: Composing an authentication message&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:12.366 : exec[65847]: Authentication not configured, for this line, using 'default' methodlist&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:12.366 : exec[65847]: Reading SysDB path 'authentication/login/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:12.366 : exec[65847]: Using authentication methodlist 'default'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:12.366 : exec[65847]: Looking host address in ________/________/vty/1/state/connection/host&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:12.367 : exec[65847]: Looking host family in ________/________/vty/1/state/connection/family&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:12.368 : exec[65847]: Got remote address 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:12.368 : exec[65847]: Add remote addr attribute - 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:12.368 : exec[65847]: Sending the authentication request message to server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:12.369 : exec[65847]: Interpreting the authentication reply from the server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:12.369 : exec[65847]: Reply buffer length: 348 - 24 = 324 bytes&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:12.369 : exec[65847]: Unpacking the AV list from the reply data&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:12.372 : exec[65847]: Extracting results from the server's reply&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:12.372 : exec[65847]: Authenticating user:&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:12.372 : exec[65847]: Authentication status: GETUSER&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:12.372 : exec[65847]: Malloc prompt length=37&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:21.722 : exec[65847]: Composing an authentication message&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:21.725 : exec[65847]: Authentication not configured, for this line, using 'default' methodlist&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:21.725 : exec[65847]: Reading SysDB path 'authentication/login/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:21.725 : exec[65847]: Using authentication methodlist 'default'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:21.725 : exec[65847]: Add remote addr attribute - 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:21.726 : exec[65847]: Sending the authentication request message to server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:21.729 : exec[65847]: Interpreting the authentication reply from the server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:21.729 : exec[65847]: Reply buffer length: 388 - 24 = 364 bytes&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:21.729 : exec[65847]: Unpacking the AV list from the reply data&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:21.729 : exec[65847]: Extracting results from the server's reply&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:21.729 : exec[65847]: Authenticating user: ASRadmin&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:21.729 : exec[65847]: Authentication status: GETPASS&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 23:12:21.729 : exec[65847]: Malloc prompt length=10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we tryed adding more sentenses of aaa but it does not work yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maru&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 14:21:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trouble-with-aaa-ios-xr/m-p/2264135#M136006</guid>
      <dc:creator>MARIA EUGENIA RUIZ</dc:creator>
      <dc:date>2013-06-12T14:21:47Z</dc:date>
    </item>
    <item>
      <title>Trouble with AAA IOS XR</title>
      <link>https://community.cisco.com/t5/network-access-control/trouble-with-aaa-ios-xr/m-p/2264136#M136010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jatin Katyal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;between both of them, tacacs+ and ASR communication exists, i´ve put the pings up in the previous answers.&lt;/P&gt;&lt;P&gt;There is not any firewall, this was not working before, is a new implementation of integration of ASR 9010.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when we put the config of&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;aaa authentication login default group tacacs+&lt;/STRONG&gt; we receibe this message, in wich does not appear the need of ingress the username and password:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GW_MEX_2#telnet 172.16.14.6&lt;BR /&gt;&lt;STRONG&gt;Trying 172.16.14.6 ... Open&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;% Authentication failed&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[Connection to 172.16.14.6 closed by foreign host]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the config of aaa that we have at this moment is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs source-interface Loopback10 vrf OAM&lt;/P&gt;&lt;P&gt;tacacs-server host 150.119.1.110 port 49&lt;/P&gt;&lt;P&gt; key 7 11070E0407214B&lt;/P&gt;&lt;P&gt; timeout 30&lt;/P&gt;&lt;P&gt; single-connection&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ maru&lt;/P&gt;&lt;P&gt; server 150.119.1.110&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+&lt;/P&gt;&lt;P&gt;aaa authentication login default group root-system&lt;/P&gt;&lt;P&gt;aaa authentication login default local&lt;/P&gt;&lt;P&gt;aaa authentication login default line&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.293 : exec[65847]: Reading SysDB path 'authentication/login/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.293 : exec[65847]: Using authentication methodlist 'default'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.293 : exec[65847]: Add remote addr attribute - 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.294 : exec[65847]: Sending the authentication request message to server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.297 : exec[65847]: Interpreting the authentication reply from the server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.297 : exec[65847]: Reply buffer length: 504 - 24 = 480 bytes&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.297 : exec[65847]: Unpacking the AV list from the reply data&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.298 : exec[65847]: Extracting results from the server's reply&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.298 : exec[65847]: Authenticating user: ASRadmin&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.298 : exec[65847]: Authentication status: PASS&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.298 : exec[65847]: Read task map size: 72 ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.298 : exec[65847]: Read user group string, length: 12&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.298 : exec[65847]: %SECURITY-login-6-AUTHEN_SUCCESS : Successfully authenticated user 'ASRadmin' from '172.16.14.5' on 'vty1'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.298 : exec[65847]: Getting details on ttyname '/dev/vty1'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.301 : exec[65847]: Reading SysDB path 'authorization/exec/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.304 : exec[65847]: Add remote addr attribute - 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.307 : exec[65847]: Reading SysDB path 'accounting/exec/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.310 : exec[65847]: Add remote addr attribute - 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.324 : exec[65847]: Getting details on ttyname '/dev/vty1'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.327 : exec[65847]: Username: ASRadmin, len 9&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:24.542 : config[65844]: Reading SysDB path 'authorization/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:24.546 : config[65844]: Reading SysDB path 'accounting/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:24.622 : nvgen[65850]: Getting details on ttyname '/dev/vty0'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:24.625 : nvgen[65850]: Username: ASRadmin, len 9&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:41.447 : config[65844]: Reading SysDB path 'authorization/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:41.451 : config[65844]: Reading SysDB path 'accounting/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:47.399 : config[65844]: Reading SysDB path 'authorization/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:47.403 : config[65844]: Reading SysDB path 'accounting/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:54.120 : config[65844]: Reading SysDB path 'authorization/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:54.124 : config[65844]: Reading SysDB path 'accounting/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:56:09.636 : config[65844]: Reading SysDB path 'authorization/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:56:09.640 : config[65844]: Reading SysDB path 'accounting/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:57:12.724 : config[65844]: Reading SysDB path 'authorization/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:57:12.728 : config[65844]: Reading SysDB path 'accounting/commands/default' ...&lt;/P&gt;&lt;P&gt;tacacs source-interface Loopback10 vrf OAM&lt;BR /&gt;tacacs-server host 150.119.1.110 port 49&lt;BR /&gt; key 7 11070E0407214B&lt;BR /&gt; timeout 30&lt;BR /&gt; single-connection&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ maru&lt;BR /&gt; server 150.119.1.110&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and we put and erase this lines of aaa:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+&lt;BR /&gt;aaa authentication login default group root-system&lt;BR /&gt;aaa authentication login default local&lt;BR /&gt;aaa authentication login default line&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the debug of authentication is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.293 : exec[65847]: Reading SysDB path 'authentication/login/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.293 : exec[65847]: Using authentication methodlist 'default'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.293 : exec[65847]: Add remote addr attribute - 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.294 : exec[65847]: Sending the authentication request message to server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.297 : exec[65847]: Interpreting the authentication reply from the server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.297 : exec[65847]: Reply buffer length: 504 - 24 = 480 bytes&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.297 : exec[65847]: Unpacking the AV list from the reply data&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.298 : exec[65847]: Extracting results from the server's reply&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.298 : exec[65847]: Authenticating user: ASRadmin&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.298 : exec[65847]: Authentication status: PASS&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.298 : exec[65847]: Read task map size: 72 ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.298 : exec[65847]: Read user group string, length: 12&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.298 : exec[65847]: %SECURITY-login-6-AUTHEN_SUCCESS : Successfully authenticated user 'ASRadmin' from '172.16.14.5' on 'vty1'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.298 : exec[65847]: Getting details on ttyname '/dev/vty1'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.301 : exec[65847]: Reading SysDB path 'authorization/exec/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.304 : exec[65847]: Add remote addr attribute - 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.307 : exec[65847]: Reading SysDB path 'accounting/exec/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.310 : exec[65847]: Add remote addr attribute - 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.324 : exec[65847]: Getting details on ttyname '/dev/vty1'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:19.327 : exec[65847]: Username: ASRadmin, len 9&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:24.542 : config[65844]: Reading SysDB path 'authorization/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:24.546 : config[65844]: Reading SysDB path 'accounting/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:24.622 : nvgen[65850]: Getting details on ttyname '/dev/vty0'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:24.625 : nvgen[65850]: Username: ASRadmin, len 9&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:41.447 : config[65844]: Reading SysDB path 'authorization/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:41.451 : config[65844]: Reading SysDB path 'accounting/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:47.399 : config[65844]: Reading SysDB path 'authorization/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:47.403 : config[65844]: Reading SysDB path 'accounting/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:54.120 : config[65844]: Reading SysDB path 'authorization/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:55:54.124 : config[65844]: Reading SysDB path 'accounting/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:56:09.636 : config[65844]: Reading SysDB path 'authorization/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:56:09.640 : config[65844]: Reading SysDB path 'accounting/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:57:12.724 : config[65844]: Reading SysDB path 'authorization/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 11 21:57:12.728 : config[65844]: Reading SysDB path 'accounting/commands/default' ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:ED_MEX_1#sh tacacs&lt;BR /&gt;Wed Jun 12 09:43:22.557 UTC&lt;/P&gt;&lt;P&gt;Server: 150.119.1.110/49 opens=0 closes=0 aborts=0 errors=0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; packets in=0 packets out=0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; status=up single-connect=false&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:ED_MEX_1#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;putting the lines:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:ED_MEX_1(config)#RP/0/RSP0/CPU0:Jun 12 09:45:51.674 : exec[65848]: Getting details on ttyname '/dev/vty1'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.678 : exec[65848]: Failed to read vty1/username from SysDB&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.749 : exec[65848]: Composing an authentication message&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.754 : exec[65848]: Authentication not configured, for this line, using 'default' methodlist&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.754 : exec[65848]: Reading SysDB path 'authentication/login/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.755 : exec[65848]: Using authentication methodlist 'default'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.755 : exec[65848]: Looking host address in ________/________/vty/1/state/connection/host&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.759 : exec[65848]: Looking host family in ________/________/vty/1/state/connection/family&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.762 : exec[65848]: Got remote address 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.762 : exec[65848]: Add remote addr attribute - 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.762 : exec[65848]: Sending the authentication request message to server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.765 : exec[65848]: Interpreting the authentication reply from the server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.765 : exec[65848]: Reply buffer length: 388 - 24 = 364 bytes&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.765 : exec[65848]: Unpacking the AV list from the reply data&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.768 : exec[65848]: Extracting results from the server's reply&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.768 : exec[65848]: Authenticating user: dev-vty1&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.768 : exec[65848]: Authentication status: GETPASS&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.768 : exec[65848]: Malloc prompt length=10&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.055 : exec[65848]: Composing an authentication message&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.058 : exec[65848]: Authentication not configured, for this line, using 'default' methodlist&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.058 : exec[65848]: Reading SysDB path 'authentication/login/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.061 : exec[65848]: Using authentication methodlist 'default'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.061 : exec[65848]: Add remote addr attribute - 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.061 : exec[65848]: Sending the authentication request message to server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.062 : exec[65848]: Interpreting the authentication reply from the server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.062 : exec[65848]: Reply buffer length: 424 - 24 = 400 bytes&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.062 : exec[65848]: Unpacking the AV list from the reply data&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.062 : exec[65848]: Extracting results from the server's reply&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.062 : exec[65848]: Authenticating user: dev-vty1&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.062 : exec[65848]: Authentication status: FAIL&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.609 : exec[65848]: Composing an authentication message&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.612 : exec[65848]: Authentication not configured, for this line, using 'default' methodlist&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.612 : exec[65848]: Reading SysDB path 'authentication/login/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.612 : exec[65848]: Using authentication methodlist 'default'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.613 : exec[65848]: Looking host address in ________/________/vty/1/state/connection/host&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.616 : exec[65848]: Looking host family in ________/________/vty/1/state/connection/family&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.619 : exec[65848]: Got remote address 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.619 : exec[65848]: Add remote addr attribute - 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.619 : exec[65848]: Sending the authentication request message to server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.622 : exec[65848]: Interpreting the authentication reply from the server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.622 : exec[65848]: Reply buffer length: 388 - 24 = 364 bytes&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.622 : exec[65848]: Unpacking the AV list from the reply data&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.622 : exec[65848]: Extracting results from the server's reply&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.622 : exec[65848]: Authenticating user: dev-vty1&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.622 : exec[65848]: Authentication status: GETPASS&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.622 : exec[65848]: Malloc prompt length=10&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.667 : exec[65848]: Composing an authentication message&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.670 : exec[65848]: Authentication not configured, for this line, using 'default' methodlist&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.670 : exec[65848]: Reading SysDB path 'authentication/login/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.670 : exec[65848]: Using authentication methodlist 'default'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.670 : exec[65848]: Add remote addr attribute - 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.671 : exec[65848]: Sending the authentication request message to server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.674 : exec[65848]: Interpreting the authentication reply from the server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.674 : exec[65848]: Reply buffer length: 420 - 24 = 396 bytes&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.674 : exec[65848]: Unpacking the AV list from the reply data&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.674 : exec[65848]: Extracting results from the server's reply&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.674 : exec[65848]: Authenticating user: dev-vty1&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.674 : exec[65848]: Authentication status: FAIL&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.218 : exec[65848]: Composing an authentication message&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.221 : exec[65848]: Authentication not configured, for this line, using 'default' methodlist&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.221 : exec[65848]: Reading SysDB path 'authentication/login/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.221 : exec[65848]: Using authentication methodlist 'default'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.222 : exec[65848]: Looking host address in ________/________/vty/1/state/connection/host&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.222 : exec[65848]: Looking host family in ________/________/vty/1/state/connection/family&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.225 : exec[65848]: Got remote address 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.225 : exec[65848]: Add remote addr attribute - 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.225 : exec[65848]: Sending the authentication request message to server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.228 : exec[65848]: Interpreting the authentication reply from the server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.228 : exec[65848]: Reply buffer length: 388 - 24 = 364 bytes&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.228 : exec[65848]: Unpacking the AV list from the reply data&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.228 : exec[65848]: Extracting results from the server's reply&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.228 : exec[65848]: Authenticating user: dev-vty1&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.228 : exec[65848]: Authentication status: GETPASS&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.228 : exec[65848]: Malloc prompt length=10&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa authentication login default group maru&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa authentication login default local&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa authentication login default line&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in fact i also create a taskgrou and usergroup called maru that have permissions of many things.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;taskgroup maru&lt;/P&gt;&lt;P&gt; task read bgp&lt;/P&gt;&lt;P&gt; task write bgp&lt;/P&gt;&lt;P&gt; task execute aaa&lt;/P&gt;&lt;P&gt; description taca&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;usergroup maru&lt;/P&gt;&lt;P&gt; taskgroup maru&lt;/P&gt;&lt;P&gt; description taca&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the last, was following the guide mentiones initially.&lt;/P&gt;&lt;P&gt;we have this result:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GW_MEX_2#telnet 172.16.14.6&lt;BR /&gt;Trying 172.16.14.6 ... Open&lt;/P&gt;&lt;P&gt;Password:&lt;BR /&gt;Password:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and the debug in the ASR aplying debug tacacs and debug aaa authen is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:ED_MEX_1(config)#RP/0/RSP0/CPU0:Jun 12 09:45:51.674 : exec[65848]: Getting details on ttyname '/dev/vty1'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.678 : exec[65848]: Failed to read vty1/username from SysDB&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.749 : exec[65848]: Composing an authentication message&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.754 : exec[65848]: Authentication not configured, for this line, using 'default' methodlist&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.754 : exec[65848]: Reading SysDB path 'authentication/login/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.755 : exec[65848]: Using authentication methodlist 'default'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.755 : exec[65848]: Looking host address in ________/________/vty/1/state/connection/host&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.759 : exec[65848]: Looking host family in ________/________/vty/1/state/connection/family&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.762 : exec[65848]: Got remote address 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.762 : exec[65848]: Add remote addr attribute - 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.762 : exec[65848]: Sending the authentication request message to server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.765 : exec[65848]: Interpreting the authentication reply from the server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.765 : exec[65848]: Reply buffer length: 388 - 24 = 364 bytes&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.765 : exec[65848]: Unpacking the AV list from the reply data&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.768 : exec[65848]: Extracting results from the server's reply&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.768 : exec[65848]: Authenticating user: dev-vty1&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.768 : exec[65848]: Authentication status: GETPASS&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:51.768 : exec[65848]: Malloc prompt length=10&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.055 : exec[65848]: Composing an authentication message&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.058 : exec[65848]: Authentication not configured, for this line, using 'default' methodlist&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.058 : exec[65848]: Reading SysDB path 'authentication/login/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.061 : exec[65848]: Using authentication methodlist 'default'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.061 : exec[65848]: Add remote addr attribute - 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.061 : exec[65848]: Sending the authentication request message to server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.062 : exec[65848]: Interpreting the authentication reply from the server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.062 : exec[65848]: Reply buffer length: 424 - 24 = 400 bytes&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.062 : exec[65848]: Unpacking the AV list from the reply data&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.062 : exec[65848]: Extracting results from the server's reply&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.062 : exec[65848]: Authenticating user: dev-vty1&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.062 : exec[65848]: Authentication status: FAIL&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.609 : exec[65848]: Composing an authentication message&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.612 : exec[65848]: Authentication not configured, for this line, using 'default' methodlist&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.612 : exec[65848]: Reading SysDB path 'authentication/login/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.612 : exec[65848]: Using authentication methodlist 'default'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.613 : exec[65848]: Looking host address in ________/________/vty/1/state/connection/host&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.616 : exec[65848]: Looking host family in ________/________/vty/1/state/connection/family&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.619 : exec[65848]: Got remote address 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.619 : exec[65848]: Add remote addr attribute - 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.619 : exec[65848]: Sending the authentication request message to server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.622 : exec[65848]: Interpreting the authentication reply from the server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.622 : exec[65848]: Reply buffer length: 388 - 24 = 364 bytes&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.622 : exec[65848]: Unpacking the AV list from the reply data&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.622 : exec[65848]: Extracting results from the server's reply&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.622 : exec[65848]: Authenticating user: dev-vty1&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.622 : exec[65848]: Authentication status: GETPASS&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:45:59.622 : exec[65848]: Malloc prompt length=10&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.667 : exec[65848]: Composing an authentication message&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.670 : exec[65848]: Authentication not configured, for this line, using 'default' methodlist&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.670 : exec[65848]: Reading SysDB path 'authentication/login/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.670 : exec[65848]: Using authentication methodlist 'default'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.670 : exec[65848]: Add remote addr attribute - 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.671 : exec[65848]: Sending the authentication request message to server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.674 : exec[65848]: Interpreting the authentication reply from the server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.674 : exec[65848]: Reply buffer length: 420 - 24 = 396 bytes&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.674 : exec[65848]: Unpacking the AV list from the reply data&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.674 : exec[65848]: Extracting results from the server's reply&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.674 : exec[65848]: Authenticating user: dev-vty1&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:03.674 : exec[65848]: Authentication status: FAIL&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.218 : exec[65848]: Composing an authentication message&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.221 : exec[65848]: Authentication not configured, for this line, using 'default' methodlist&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.221 : exec[65848]: Reading SysDB path 'authentication/login/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.221 : exec[65848]: Using authentication methodlist 'default'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.222 : exec[65848]: Looking host address in ________/________/vty/1/state/connection/host&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.222 : exec[65848]: Looking host family in ________/________/vty/1/state/connection/family&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.225 : exec[65848]: Got remote address 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.225 : exec[65848]: Add remote addr attribute - 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.225 : exec[65848]: Sending the authentication request message to server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.228 : exec[65848]: Interpreting the authentication reply from the server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.228 : exec[65848]: Reply buffer length: 388 - 24 = 364 bytes&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.228 : exec[65848]: Unpacking the AV list from the reply data&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.228 : exec[65848]: Extracting results from the server's reply&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.228 : exec[65848]: Authenticating user: dev-vty1&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.228 : exec[65848]: Authentication status: GETPASS&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 09:46:04.228 : exec[65848]: Malloc prompt length=10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;maybe i need to change the lines? are correct my aaa sentences?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maru&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 14:52:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trouble-with-aaa-ios-xr/m-p/2264136#M136010</guid>
      <dc:creator>MARIA EUGENIA RUIZ</dc:creator>
      <dc:date>2013-06-12T14:52:17Z</dc:date>
    </item>
    <item>
      <title>Trouble with AAA IOS XR</title>
      <link>https://community.cisco.com/t5/network-access-control/trouble-with-aaa-ios-xr/m-p/2264137#M136012</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try this:&lt;/P&gt;&lt;P&gt;telnet 172.16.14.6&lt;STRONG&gt; 49&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also remove single-connection from the config for now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;/P&gt;&lt;P&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 14:56:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trouble-with-aaa-ios-xr/m-p/2264137#M136012</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-06-12T14:56:22Z</dc:date>
    </item>
    <item>
      <title>Trouble with AAA IOS XR</title>
      <link>https://community.cisco.com/t5/network-access-control/trouble-with-aaa-ios-xr/m-p/2264138#M136016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jatin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ok I erase the single-connection and is like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:ED_MEX_1#sh tacacs&lt;BR /&gt;Wed Jun 12 10:31:18.634 UTC&lt;/P&gt;&lt;P&gt;Server: 150.119.1.110/49 opens=0 closes=0 aborts=0 errors=0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; packets in=0 packets out=0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; status=up &lt;STRONG&gt;single-connect=false&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:ED_MEX_1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and what happens was next:&lt;/P&gt;&lt;P&gt;GW_MEX_2#telnet 172.16.14.6&lt;BR /&gt;Trying 172.16.14.6 ... Open&lt;/P&gt;&lt;P&gt;Password:&lt;BR /&gt;Password:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;needs a password that is not the vty password defined &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the debug of tacas and aaa is this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:34:57.025 : config[65844]: Reading SysDB path 'accounting/commands/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:ED_MEX_1(config)#RP/0/RSP0/CPU0:Jun 12 10:34:59.653 : exec[65848]: Getting details on ttyname '/dev/vty1'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:34:59.657 : exec[65848]: Failed to read vty1/username from SysDB&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:34:59.726 : exec[65848]: Composing an authentication message&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:34:59.734 : exec[65848]: Authentication not configured, for this line, using 'default' methodlist&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:34:59.734 : exec[65848]: Reading SysDB path 'authentication/login/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:34:59.734 : exec[65848]: Using authentication methodlist 'default'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:34:59.735 : exec[65848]: Looking host address in ________/________/vty/1/state/connection/host&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:34:59.735 : exec[65848]: Looking host family in ________/________/vty/1/state/connection/family&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:34:59.736 : exec[65848]: Got remote address 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:34:59.736 : exec[65848]: Add remote addr attribute - 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:34:59.736 : exec[65848]: Sending the authentication request message to server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:34:59.740 : exec[65848]: Interpreting the authentication reply from the server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:34:59.740 : exec[65848]: Reply buffer length: 388 - 24 = 364 bytes&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:34:59.740 : exec[65848]: Unpacking the AV list from the reply data&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:34:59.742 : exec[65848]: Extracting results from the server's reply&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:34:59.742 : exec[65848]: Authenticating user: dev-vty1&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:34:59.742 : exec[65848]: Authentication status: GETPASS&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:34:59.742 : exec[65848]: Malloc prompt length=10&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:01.717 : exec[65848]: Composing an authentication message&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:01.720 : exec[65848]: Authentication not configured, for this line, using 'default' methodlist&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:01.720 : exec[65848]: Reading SysDB path 'authentication/login/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:01.720 : exec[65848]: Using authentication methodlist 'default'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:01.720 : exec[65848]: Add remote addr attribute - 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:01.721 : exec[65848]: Sending the authentication request message to server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:01.724 : exec[65848]: Interpreting the authentication reply from the server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:01.724 : exec[65848]: Reply buffer length: 424 - 24 = 400 bytes&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:01.724 : exec[65848]: Unpacking the AV list from the reply data&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:01.724 : exec[65848]: Extracting results from the server's reply&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:01.724 : exec[65848]: Authenticating user: dev-vty1&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:01.724 : exec[65848]: Authentication status: FAIL&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:02.269 : exec[65848]: Composing an authentication message&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:02.272 : exec[65848]: Authentication not configured, for this line, using 'default' methodlist&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:02.272 : exec[65848]: Reading SysDB path 'authentication/login/default' ...&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:02.272 : exec[65848]: Using authentication methodlist 'default'&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:02.273 : exec[65848]: Looking host address in ________/________/vty/1/state/connection/host&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:02.276 : exec[65848]: Looking host family in ________/________/vty/1/state/connection/family&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:02.279 : exec[65848]: Got remote address 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:02.279 : exec[65848]: Add remote addr attribute - 172.16.14.5 (length 11)&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:02.279 : exec[65848]: Sending the authentication request message to server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:02.283 : exec[65848]: Interpreting the authentication reply from the server&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:02.283 : exec[65848]: Reply buffer length: 388 - 24 = 364 bytes&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:02.283 : exec[65848]: Unpacking the AV list from the reply data&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:02.283 : exec[65848]: Extracting results from the server's reply&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:02.283 : exec[65848]: Authenticating user: dev-vty1&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:02.283 : exec[65848]: Authentication status: GETPASS&lt;/P&gt;&lt;P&gt;RP/0/RSP0/CPU0:Jun 12 10:35:02.283 : exec[65848]: Malloc prompt length=10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;normally which sentenses of aaa do you put??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maru&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jun 2013 15:37:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trouble-with-aaa-ios-xr/m-p/2264138#M136016</guid>
      <dc:creator>MARIA EUGENIA RUIZ</dc:creator>
      <dc:date>2013-06-12T15:37:22Z</dc:date>
    </item>
    <item>
      <title>Trouble with AAA IOS XR</title>
      <link>https://community.cisco.com/t5/network-access-control/trouble-with-aaa-ios-xr/m-p/2264139#M136018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not sure your problem got resolved. But looks like the server is not in the same VRF.&lt;/P&gt;&lt;P&gt;Please mention the server group also in the same VRF. you will see packet traverse happily.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Oct 2013 05:03:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/trouble-with-aaa-ios-xr/m-p/2264139#M136018</guid>
      <dc:creator>narvenka</dc:creator>
      <dc:date>2013-10-22T05:03:50Z</dc:date>
    </item>
  </channel>
</rss>

