<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with TACACS+ using ASA5545, ACS 5.4 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241353#M144904</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can we check the debugs as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do add the following changes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server tacacs+ protocol tacacs+&lt;/P&gt;&lt;P&gt;no aaa-server tacacs+ (inside) host 10.x.x.x&lt;/P&gt;&lt;P&gt;aaa-server tacacs+ (inside) host 10.x.x.x &lt;/P&gt;&lt;P&gt;reactivation-mode timed&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;/P&gt;&lt;P&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 May 2013 17:50:27 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2013-05-15T17:50:27Z</dc:date>
    <item>
      <title>Problem with TACACS+ using ASA5545, ACS 5.4</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241350#M144815</link>
      <description>&lt;P&gt;I am trying to access an ASA 5545 using TACACS+.&amp;nbsp; I have the ASA configured as follows:&lt;/P&gt;&lt;P&gt;﻿&lt;/P&gt;&lt;P&gt;aaa-server tacacs+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server tacacs+ (inside) host 10.x.x.x&lt;/P&gt;&lt;P&gt;timeout 15&lt;/P&gt;&lt;P&gt;key *****&lt;/P&gt;&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication enable console LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication telnet console tacacs+ LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console tacacs+ LOCAL&lt;/P&gt;&lt;P&gt;aaa authenticaiton http console tacacs+ LOCAL&lt;/P&gt;&lt;P&gt;aaa authorization command tacacs+ LOCAL&lt;/P&gt;&lt;P&gt;aaa authorization exec authentication-server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have added the ASA in ACS with the correct IP and the correct key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I try to test the authentication via test aaa-server authentication tacacs+ host 10.x.x.x username cisco password cisco, I get:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ERROR: Authentication Server not responding: No error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas on how to fix this issue and allow tacacs authentication when logging into the ASA?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:26:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241350#M144815</guid>
      <dc:creator>deanlee10</dc:creator>
      <dc:date>2019-03-11T03:26:21Z</dc:date>
    </item>
    <item>
      <title>Problem with TACACS+ using ASA5545, ACS 5.4</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241351#M144848</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;could you please turn on the debugs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug tacacs&lt;/P&gt;&lt;P&gt;debug aaa authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also, are you able to ping the server using inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Provide show aaa-server output as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 May 2013 17:13:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241351#M144848</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-15T17:13:50Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with TACACS+ using ASA5545, ACS 5.4</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241352#M144870</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes, can ping successfully.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA # ping 10.x.x.x &lt;/P&gt;&lt;P&gt;Type escape sequence to abort. &lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 10.x.x.x, timeout is 2 seconds: &lt;/P&gt;&lt;P&gt;!!!!! &lt;/P&gt;&lt;P&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA# show aaa-server Server Group:&amp;nbsp;&amp;nbsp;&amp;nbsp; LOCAL &lt;/P&gt;&lt;P&gt;Server Protocol: Local database &lt;/P&gt;&lt;P&gt;Server Address:&amp;nbsp; None &lt;/P&gt;&lt;P&gt;Server port:&amp;nbsp;&amp;nbsp;&amp;nbsp; None &lt;/P&gt;&lt;P&gt;Server status:&amp;nbsp; ACTIVE, Last transaction at 17:33:50 UTC Wed May 15 2013 &lt;/P&gt;&lt;P&gt;Number of pending requests&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 &lt;/P&gt;&lt;P&gt;Average round trip time&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0ms &lt;/P&gt;&lt;P&gt;Number of authentication requests&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255 &lt;/P&gt;&lt;P&gt;Number of authorization requests&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 39 &lt;/P&gt;&lt;P&gt;Number of accounting requests&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 &lt;/P&gt;&lt;P&gt;Number of retransmissions&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 &lt;/P&gt;&lt;P&gt;Number of accepts&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 274 &lt;/P&gt;&lt;P&gt;Number of rejects&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20 &lt;/P&gt;&lt;P&gt;Number of challenges&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 &lt;/P&gt;&lt;P&gt;Number of malformed responses&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 &lt;/P&gt;&lt;P&gt;Number of bad authenticators&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 &lt;/P&gt;&lt;P&gt;Number of timeouts&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 &lt;/P&gt;&lt;P&gt;Number of unrecognized responses&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server Group:&amp;nbsp;&amp;nbsp;&amp;nbsp; tacacs+ &lt;/P&gt;&lt;P&gt;Server Protocol: tacacs+ &lt;/P&gt;&lt;P&gt;Server Address:&amp;nbsp; 10.x.x.x &lt;/P&gt;&lt;P&gt;Server port:&amp;nbsp;&amp;nbsp;&amp;nbsp; 49 &lt;/P&gt;&lt;P&gt;Server status:&amp;nbsp; FAILED, Server disabled at 17:33:30 UTC Wed May 15 2013 &lt;/P&gt;&lt;P&gt;Number of pending requests&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 &lt;/P&gt;&lt;P&gt;Average round trip time&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0ms &lt;/P&gt;&lt;P&gt;Number of authentication requests&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10 &lt;/P&gt;&lt;P&gt;Number of authorization requests&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6 &lt;/P&gt;&lt;P&gt;Number of accounting requests&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 &lt;/P&gt;&lt;P&gt;Number of retransmissions&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 &lt;/P&gt;&lt;P&gt;Number of accepts&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 &lt;/P&gt;&lt;P&gt;Number of rejects&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 &lt;/P&gt;&lt;P&gt;Number of challenges&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 &lt;/P&gt;&lt;P&gt;Number of malformed responses&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 &lt;/P&gt;&lt;P&gt;Number of bad authenticators&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 &lt;/P&gt;&lt;P&gt;Number of timeouts&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 16 &lt;/P&gt;&lt;P&gt;Number of unrecognized responses&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 May 2013 17:42:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241352#M144870</guid>
      <dc:creator>deanlee10</dc:creator>
      <dc:date>2013-05-15T17:42:26Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with TACACS+ using ASA5545, ACS 5.4</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241353#M144904</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can we check the debugs as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do add the following changes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server tacacs+ protocol tacacs+&lt;/P&gt;&lt;P&gt;no aaa-server tacacs+ (inside) host 10.x.x.x&lt;/P&gt;&lt;P&gt;aaa-server tacacs+ (inside) host 10.x.x.x &lt;/P&gt;&lt;P&gt;reactivation-mode timed&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;/P&gt;&lt;P&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 May 2013 17:50:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241353#M144904</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-15T17:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with TACACS+ using ASA5545, ACS 5.4</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241354#M144941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; There is no output when I enter turn debugging on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I entered the commands you recommeneded.&amp;nbsp; No change.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 May 2013 18:04:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241354#M144941</guid>
      <dc:creator>deanlee10</dc:creator>
      <dc:date>2013-05-15T18:04:22Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with TACACS+ using ASA5545, ACS 5.4</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241355#M144982</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: arial black,avant garde; font-size: 12pt; color: #333333;"&gt;Hi Dean&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial black,avant garde; font-size: 12pt; color: #333333;"&gt;&amp;nbsp; Can you run the following command:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial black,avant garde; font-size: 12pt; color: #333333;"&gt;#term mon &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial black,avant garde; font-size: 12pt; color: #333333;"&gt;take debugs and share the output.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial black,avant garde; font-size: 12pt; color: #333333;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial black,avant garde; font-size: 12pt; color: #333333;"&gt;Minakshi ( do rate the helpful posts:&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 May 2013 18:16:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241355#M144982</guid>
      <dc:creator>minkumar</dc:creator>
      <dc:date>2013-05-15T18:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with TACACS+ using ASA5545, ACS 5.4</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241356#M145013</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was able to get the tacacs working, however, now I am unable to enter the privilege level.&amp;nbsp; My tacacs account is privilege level 15.&amp;nbsp; Also, now my local username/password does not work to get into the device.&amp;nbsp; Anyway to get back in and also to solve the "enable" issue?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 May 2013 18:14:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241356#M145013</guid>
      <dc:creator>deanlee10</dc:creator>
      <dc:date>2013-05-16T18:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with TACACS+ using ASA5545, ACS 5.4</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241357#M145060</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: arial black,avant garde; font-size: 12pt; color: #333333;"&gt;Hi Dean,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial black,avant garde; font-size: 12pt; color: #333333;"&gt;&amp;nbsp;&amp;nbsp; Check in the passed authentication, which shell profile is being used by the user and push default privilege 15 under ACS 5.4.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial black,avant garde; font-size: 12pt; color: #333333;"&gt;It should work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial black,avant garde; font-size: 12pt; color: #333333;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial black,avant garde; font-size: 12pt; color: #333333;"&gt;Minakshi (Do rate the helpful posts &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; )&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 May 2013 18:34:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241357#M145060</guid>
      <dc:creator>minkumar</dc:creator>
      <dc:date>2013-05-16T18:34:51Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with TACACS+ using ASA5545, ACS 5.4</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241358#M145105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In order to access the security appliance you have to type enable followed by enable password unlike IOS devices. There you can land directly to privilege exec mode. Now, If your local credentials are not working than in that case my question would be; Is your tacacs still up and running? If yes, than it would always hit the tacacs at very first place and get failed. It will never check the local database. In order to test that tacacs should not be accessible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; - Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 May 2013 18:36:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241358#M145105</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-16T18:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with TACACS+ using ASA5545, ACS 5.4</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241359#M145140</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tacacs server is up and running.&amp;nbsp; Verified local credentials still work when tacacs is disabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What kind of problems could I be running into where I can login to the device via tacacs, but cannot enable to privilege exec mode using the same tacacs password?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 May 2013 18:57:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241359#M145140</guid>
      <dc:creator>deanlee10</dc:creator>
      <dc:date>2013-05-16T18:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with TACACS+ using ASA5545, ACS 5.4</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241360#M145164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you will not be able to access the device and execute the commands from privelege exec command. Why would you not be able to access using enable password if it's configured as to use as PAP password on tacacs 4.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 May 2013 19:38:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241360#M145164</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-16T19:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with TACACS+ using ASA5545, ACS 5.4</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241361#M145181</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I think there is a miscommunication:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The goal is for me to be able to ssh into the device using my tacacs credentials, which I can do.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I then want to be able to type "enable" and be prompted for my tacacs password, which I would then enter to access privilege exec mode, This is the part I am having problems with.&amp;nbsp; I am currently unable to enter privilege exec mode with my tacacs password.&amp;nbsp; If this is not possible, then that's fine, I can access it with the local password, but I am looking for help to be able to accomplish this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 May 2013 20:12:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241361#M145181</guid>
      <dc:creator>deanlee10</dc:creator>
      <dc:date>2013-05-16T20:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with TACACS+ using ASA5545, ACS 5.4</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241362#M145205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what tacacs server are you using? If acs 4.x, check reports and activity ...you must be getting &lt;STRONG&gt;"enable privilege is too low&lt;/STRONG&gt;" (Most probable error)...after that you can go inside the user/group setup and set the enable privilege 15 under tacas+ settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 May 2013 20:31:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241362#M145205</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-16T20:31:54Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with TACACS+ using ASA5545, ACS 5.4</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241363#M145224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; As stated in the title, I am using ACS 5.4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I check the monitoring and reporting, I am getting the following error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;13031 TACACS+ authentication request missing user Password&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Description:&lt;/P&gt;&lt;P&gt;The TACACS+ authentication request did not provide a user password&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Resolution Steps:&lt;/P&gt;&lt;P&gt;The device is sending a TACACS+ authentication request that is missing informatino needed by ACS.&amp;nbsp; Check the device to verify it is working properly and has up-to-date software.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The device is working properly and has up-to-date software.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 May 2013 12:56:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241363#M145224</guid>
      <dc:creator>deanlee10</dc:creator>
      <dc:date>2013-05-17T12:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with TACACS+ using ASA5545, ACS 5.4</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241364#M145242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dean, My bad I missed that part. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would like to use enable password same as tacacs password. However, the command you have in ASA checking the enable password against asa local enable password. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can we replace this command &lt;/P&gt;&lt;P&gt;aaa authentication enable console LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with &lt;/P&gt;&lt;P&gt;aaa authentication enable console tacacs+ LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how it goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 May 2013 13:10:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241364#M145242</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-17T13:10:16Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with TACACS+ using ASA5545, ACS 5.4</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241365#M145255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Jatin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 'aaa authentication enable console tacacs+ LOCAL' is currently on the device.&amp;nbsp; I had it on the old command when I was still having problems even accessing the device via tacacs/ssh.&amp;nbsp; Based on the failure code in the previous reply, it seems like ACS is having trouble communicating with the ASA when it needs to authenticate the enable password - it's as if when you enter the password on the ASA, it's not getting all the way to the ACS to authenticate.&amp;nbsp; Is this just an error between the ACS version and the ASA software version?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 May 2013 13:53:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241365#M145255</guid>
      <dc:creator>deanlee10</dc:creator>
      <dc:date>2013-05-17T13:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with TACACS+ using ASA5545, ACS 5.4</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241366#M145265</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I actually recreated with ACS 5.4 and ASA 8.4(5) and its working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa# sh run aaa&lt;/P&gt;&lt;P&gt;aaa authentication telnet console TACACS LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console TACACS LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication enable console TACACS LOCAL&lt;/P&gt;&lt;P&gt;aaa accounting command privilege 15 TACACS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from policy elements&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/4/4/139445-enable-privilege.PNG" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 May 2013 14:10:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241366#M145265</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-17T14:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with TACACS+ using ASA5545, ACS 5.4</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241367#M145277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I also have the max privilege for the shell profile set to static/15.&amp;nbsp; The ASA I am running has 9.1(1).&amp;nbsp; Maybe there is a bug in the code?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 May 2013 14:23:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241367#M145277</guid>
      <dc:creator>deanlee10</dc:creator>
      <dc:date>2013-05-17T14:23:36Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with TACACS+ using ASA5545, ACS 5.4</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241368#M145290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hmm...you must have already checked but make sure we are hitting the right authorization rule in the accesspolicy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from access-policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/6/4/4/139446-access-policy.PNG" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 May 2013 14:33:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241368#M145290</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-17T14:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with TACACS+ using ASA5545, ACS 5.4</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241369#M145303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Jatin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know why this is the case, but when the ACS admin created my account, instead of creating a new account, he duplicated his account.&amp;nbsp; For some reason this made it so I couldn't enable using my tacacs.&amp;nbsp; He deleted my account and created it from scratch.&amp;nbsp; This fixed the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 May 2013 15:55:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-using-asa5545-acs-5-4/m-p/2241369#M145303</guid>
      <dc:creator>deanlee10</dc:creator>
      <dc:date>2013-05-17T15:55:45Z</dc:date>
    </item>
  </channel>
</rss>

