<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic local Authentication fails in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/local-authentication-fails/m-p/1897949#M170090</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Aduado&lt;/P&gt;&lt;P&gt;thanks for the reply, I understand what you say, but even the AACS server is not responding this fails.&lt;/P&gt;&lt;P&gt;what we did, we took another switch and configure the same way as the failing device .&lt;/P&gt;&lt;P&gt;then we placed a firewall between the switch and the ACS server and block any request from the switch going to the &lt;/P&gt;&lt;P&gt;ACS server. we could see the firewall is dropping the request send via switch to the ACS and been dropped.&lt;/P&gt;&lt;P&gt;however the switch is not falling back to the local authentication&lt;/P&gt;&lt;P&gt;when we provide the local username/pass it just keeps on asking for username and password&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the IOS is 12.2(33)SXI3 (s72033_rp-ADVIPSERVICESK9_WAN-VM), could not find any bugs relate to this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks you for the support &lt;/P&gt;&lt;P&gt;Lancellot&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 21 May 2012 10:04:19 GMT</pubDate>
    <dc:creator>Lance Wendel</dc:creator>
    <dc:date>2012-05-21T10:04:19Z</dc:date>
    <item>
      <title>local Authentication fails</title>
      <link>https://community.cisco.com/t5/network-access-control/local-authentication-fails/m-p/1897947#M170088</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have strang situation, when you try to authenticate with the local username and password, switch keeps bouncing back for user name and password&lt;/P&gt;&lt;P&gt;though I have given the correct information&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*****************************************************&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ none&lt;/P&gt;&lt;P&gt;aaa authorization exec no_tac none&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ none&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;*************************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you fails to authenticate with the ACS server, router/Switch will look for local authentication, correct.&lt;/P&gt;&lt;P&gt;I have created a user &amp;amp; a password localy on the device. when try to enter the local username/pass switch keeps bouncing back for username and password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;kindly help please&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;&lt;P&gt;Lance&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:06:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-authentication-fails/m-p/1897947#M170088</guid>
      <dc:creator>Lance Wendel</dc:creator>
      <dc:date>2019-03-11T02:06:01Z</dc:date>
    </item>
    <item>
      <title>local Authentication fails</title>
      <link>https://community.cisco.com/t5/network-access-control/local-authentication-fails/m-p/1897948#M170089</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; If you fail to authenticate with ACS server then ACS will tell the device to deny access to that particular user. The device won't look for local authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only way it will look for local authentication is if ACS is not responding at all.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 May 2012 06:15:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-authentication-fails/m-p/1897948#M170089</guid>
      <dc:creator>Eduardo Aliaga</dc:creator>
      <dc:date>2012-05-19T06:15:40Z</dc:date>
    </item>
    <item>
      <title>local Authentication fails</title>
      <link>https://community.cisco.com/t5/network-access-control/local-authentication-fails/m-p/1897949#M170090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Aduado&lt;/P&gt;&lt;P&gt;thanks for the reply, I understand what you say, but even the AACS server is not responding this fails.&lt;/P&gt;&lt;P&gt;what we did, we took another switch and configure the same way as the failing device .&lt;/P&gt;&lt;P&gt;then we placed a firewall between the switch and the ACS server and block any request from the switch going to the &lt;/P&gt;&lt;P&gt;ACS server. we could see the firewall is dropping the request send via switch to the ACS and been dropped.&lt;/P&gt;&lt;P&gt;however the switch is not falling back to the local authentication&lt;/P&gt;&lt;P&gt;when we provide the local username/pass it just keeps on asking for username and password&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the IOS is 12.2(33)SXI3 (s72033_rp-ADVIPSERVICESK9_WAN-VM), could not find any bugs relate to this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks you for the support &lt;/P&gt;&lt;P&gt;Lancellot&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 May 2012 10:04:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-authentication-fails/m-p/1897949#M170090</guid>
      <dc:creator>Lance Wendel</dc:creator>
      <dc:date>2012-05-21T10:04:19Z</dc:date>
    </item>
  </channel>
</rss>

