<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA % Authorization failed. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-failed/m-p/2205706#M140249</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After the debug message *May&amp;nbsp; 2 09:48:45.440:&lt;STRONG&gt; AAA/AUTHOR (0x27): Pick method list 'default' - FAIL&lt;/STRONG&gt;* the control will passed to TACACS. From this log we are not clear that why it got failed in tacacs authorization. Looking at your configuration, its clear that you're expecting next prompt for enable password only if &lt;STRONG&gt;priv-lvl=15&lt;/STRONG&gt; is not being configured on ACS for the user/group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you also remove &lt;STRONG&gt;single-connection&lt;/STRONG&gt; from the below listed command and try again.&lt;/P&gt;&lt;P&gt;tacacs-server host 192.168.110.1 single-connection&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In case it doesn't work, send the complete output of following debugs if possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Debug aaa authentication&lt;/P&gt;&lt;P&gt;Debug aaa authorization&lt;/P&gt;&lt;P&gt;Debug tacacs authentication&lt;/P&gt;&lt;P&gt;Debug tacacs authorization&lt;/P&gt;&lt;P&gt;Debug tacacs events&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 May 2013 10:12:29 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2013-05-02T10:12:29Z</dc:date>
    <item>
      <title>AAA % Authorization failed.</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-failed/m-p/2205705#M140208</link>
      <description>&lt;P&gt;Even my credentials being accepted in the acs authorization failure, anyone have any idea what it could be?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; (Unauthorized use is prohibited)&lt;/P&gt;&lt;P&gt;username: tparrilha&lt;/P&gt;&lt;P&gt;password: &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;% Authorization failed.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logs of debug aaa &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*May&amp;nbsp; 2 09:48:30.840: AAA/AUTHOR/EXEC(00000026): Authorization FAILED&lt;/P&gt;&lt;P&gt;*May&amp;nbsp; 2 09:48:41.612: AAA/BIND(00000027): Bind i/f&amp;nbsp; &lt;/P&gt;&lt;P&gt;*May&amp;nbsp; 2 09:48:41.612: AAA/AUTHEN/LOGIN (00000027): Pick method list 'default' &lt;/P&gt;&lt;P&gt;*May&amp;nbsp; 2 09:48:45.440: AAA/AUTHOR (0x27): Pick method list 'default' - FAIL&lt;/P&gt;&lt;P&gt;*May&amp;nbsp; 2 09:48:45.456: AAA/AUTHOR/EXEC(00000027): &lt;STRONG&gt;Authorization FAILED&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ Bainet&lt;/P&gt;&lt;P&gt; server 172.20.244.10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication fail-message ^CCCC Sorry the password is wrong^C&lt;/P&gt;&lt;P&gt;aaa authentication login default group Bainet local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group Bainet enable none&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;P&gt;aaa authorization exec default group Bainet local &lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group Bainet local &lt;/P&gt;&lt;P&gt;aaa authorization commands 2 default group Bainet local &lt;/P&gt;&lt;P&gt;aaa authorization commands 3 default group Bainet local &lt;/P&gt;&lt;P&gt;aaa authorization commands 4 default group Bainet local &lt;/P&gt;&lt;P&gt;aaa authorization commands 5 default group Bainet local &lt;/P&gt;&lt;P&gt;aaa authorization commands 6 default group Bainet local &lt;/P&gt;&lt;P&gt;aaa authorization commands 7 default group Bainet local &lt;/P&gt;&lt;P&gt;aaa authorization commands 8 default group Bainet local &lt;/P&gt;&lt;P&gt;aaa authorization commands 9 default group Bainet local &lt;/P&gt;&lt;P&gt;aaa authorization commands 10 default group Bainet local &lt;/P&gt;&lt;P&gt;aaa authorization commands 11 default group Bainet local &lt;/P&gt;&lt;P&gt;aaa authorization commands 12 default group Bainet local &lt;/P&gt;&lt;P&gt;aaa authorization commands 13 default group Bainet local &lt;/P&gt;&lt;P&gt;aaa authorization commands 14 default group Bainet local &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group Bainet local &lt;/P&gt;&lt;P&gt;aaa authorization configuration default group Bainet &lt;/P&gt;&lt;P&gt;aaa accounting send stop-record authentication failure &lt;/P&gt;&lt;P&gt;aaa accounting exec default&lt;/P&gt;&lt;P&gt; action-type start-stop&lt;/P&gt;&lt;P&gt; group Bainet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa accounting commands 0 default&lt;/P&gt;&lt;P&gt; action-type start-stop&lt;/P&gt;&lt;P&gt; group Bainet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default&lt;/P&gt;&lt;P&gt; action-type start-stop&lt;/P&gt;&lt;P&gt; group Bainet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa accounting commands 2 default&lt;/P&gt;&lt;P&gt; action-type start-stop&lt;/P&gt;&lt;P&gt; group Bainet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa accounting commands 3 default&lt;/P&gt;&lt;P&gt; action-type start-stop&lt;/P&gt;&lt;P&gt; group Bainet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa accounting commands 4 default&lt;/P&gt;&lt;P&gt; action-type start-stop&lt;/P&gt;&lt;P&gt; group Bainet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa accounting commands 5 default&lt;/P&gt;&lt;P&gt; action-type start-stop&lt;/P&gt;&lt;P&gt; group Bainet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa accounting commands 6 default&lt;/P&gt;&lt;P&gt; action-type start-stop&lt;/P&gt;&lt;P&gt; group Bainet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa accounting commands 7 default&lt;/P&gt;&lt;P&gt; action-type start-stop&lt;/P&gt;&lt;P&gt; group Bainet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa accounting commands 8 default&lt;/P&gt;&lt;P&gt; action-type start-stop&lt;/P&gt;&lt;P&gt; group Bainet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa accounting commands 9 default&lt;/P&gt;&lt;P&gt; action-type start-stop&lt;/P&gt;&lt;P&gt; group Bainet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa accounting commands 10 default&lt;/P&gt;&lt;P&gt; action-type start-stop&lt;/P&gt;&lt;P&gt; group Bainet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa accounting commands 11 default&lt;/P&gt;&lt;P&gt; action-type start-stop&lt;/P&gt;&lt;P&gt; group Bainet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa accounting commands 12 default&lt;/P&gt;&lt;P&gt; action-type start-stop&lt;/P&gt;&lt;P&gt; group Bainet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa accounting commands 13 default&lt;/P&gt;&lt;P&gt; action-type start-stop&lt;/P&gt;&lt;P&gt; group Bainet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa accounting commands 14 default&lt;/P&gt;&lt;P&gt; action-type start-stop&lt;/P&gt;&lt;P&gt; group Bainet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default&lt;/P&gt;&lt;P&gt; action-type start-stop&lt;/P&gt;&lt;P&gt; group Bainet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa accounting network default&lt;/P&gt;&lt;P&gt; action-type start-stop&lt;/P&gt;&lt;P&gt; group Bainet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa accounting connection default&lt;/P&gt;&lt;P&gt; action-type start-stop&lt;/P&gt;&lt;P&gt; group Bainet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa accounting system default&lt;/P&gt;&lt;P&gt; action-type start-stop&lt;/P&gt;&lt;P&gt; group Bainet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip tacacs source-interface FastEthernet0/0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host 192.168.110.1 single-connection&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;tacacs-server key 7 11485807161B4A0E0524282B6972&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#show ver&lt;/P&gt;&lt;P&gt;RT-NAMIBE-NBE#show version &lt;/P&gt;&lt;P&gt;Cisco IOS Software, 2800 Software (C2800NM-ADVENTERPRISEK9_IVS_LI-M), Version 12.4(24)T4, RELEASE SOFTWARE (fc2)&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Technical Support: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/techsupport" target="_blank"&gt;http://www.cisco.com/techsupport&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Copyright (c) 1986-2010 by Cisco Systems, Inc.&lt;/P&gt;&lt;P&gt;Compiled Fri 03-Sep-10 05:39 by prod_rel_team&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ROM: System Bootstrap, Version 12.4(13r)T, RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RT-NAMIBE-NBE uptime is 12 weeks, 5 days, 23 hours, 56 minutes&lt;/P&gt;&lt;P&gt;System returned to ROM by power-on&lt;/P&gt;&lt;P&gt;System image file is "flash:c2800nm-adventerprisek9_ivs_li-mz.124-24.T4.bin"&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:23:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization-failed/m-p/2205705#M140208</guid>
      <dc:creator>thiago.tomen</dc:creator>
      <dc:date>2019-03-11T03:23:09Z</dc:date>
    </item>
    <item>
      <title>AAA % Authorization failed.</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-failed/m-p/2205706#M140249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After the debug message *May&amp;nbsp; 2 09:48:45.440:&lt;STRONG&gt; AAA/AUTHOR (0x27): Pick method list 'default' - FAIL&lt;/STRONG&gt;* the control will passed to TACACS. From this log we are not clear that why it got failed in tacacs authorization. Looking at your configuration, its clear that you're expecting next prompt for enable password only if &lt;STRONG&gt;priv-lvl=15&lt;/STRONG&gt; is not being configured on ACS for the user/group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you also remove &lt;STRONG&gt;single-connection&lt;/STRONG&gt; from the below listed command and try again.&lt;/P&gt;&lt;P&gt;tacacs-server host 192.168.110.1 single-connection&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In case it doesn't work, send the complete output of following debugs if possible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Debug aaa authentication&lt;/P&gt;&lt;P&gt;Debug aaa authorization&lt;/P&gt;&lt;P&gt;Debug tacacs authentication&lt;/P&gt;&lt;P&gt;Debug tacacs authorization&lt;/P&gt;&lt;P&gt;Debug tacacs events&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 May 2013 10:12:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization-failed/m-p/2205706#M140249</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-02T10:12:29Z</dc:date>
    </item>
    <item>
      <title>AAA % Authorization failed.</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-failed/m-p/2205707#M140281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It worked,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your help!!!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 May 2013 15:42:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization-failed/m-p/2205707#M140281</guid>
      <dc:creator>thiago.tomen</dc:creator>
      <dc:date>2013-05-09T15:42:05Z</dc:date>
    </item>
    <item>
      <title>AAA % Authorization failed.</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-failed/m-p/2205708#M140318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad to know. Thanks for updating Thiago &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 May 2013 15:46:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization-failed/m-p/2205708#M140318</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-09T15:46:03Z</dc:date>
    </item>
  </channel>
</rss>

