<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IOS 15 not working with my TACACS server in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ios-15-not-working-with-my-tacacs-server/m-p/2272000#M183231</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, it seems you used the "&lt;/P&gt;&lt;P&gt;ip tacacs source-interface &lt;TUNNEL interfaface=""&gt;" command to source that traffic from the proper interface. let me know if that was the case.&lt;/TUNNEL&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Dec 2013 15:39:57 GMT</pubDate>
    <dc:creator>ccnwankpa</dc:creator>
    <dc:date>2013-12-17T15:39:57Z</dc:date>
    <item>
      <title>IOS 15 not working with my TACACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ios-15-not-working-with-my-tacacs-server/m-p/2271992#M182900</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I recently made some changes to the way my Tacacs server (ACS4.2) handled groups etc..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This all works fine and when I log onto my devices I get prompted for my credentials, which authenticate against AD. However, since I made these changes none of the devices on IOS 15 now authenticate. I am immediately prompted for a local password rather than a username and password..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand that the commands for Tacacs changeda bit in IOS15 but from what I have read and changed I'm still having trouble. Config below from once of the routers I'm having trouble with...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I missing something?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ ACS1&lt;/P&gt;&lt;P&gt; server name AUTH&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login ACS-List group ACS1 local&lt;/P&gt;&lt;P&gt;aaa authorization exec ACS-List group ACS1 local&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 ACS-List&lt;/P&gt;&lt;P&gt; action-type start-stop&lt;/P&gt;&lt;P&gt; group ACS1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;acacs-server directed-request&lt;/P&gt;&lt;P&gt;tacacs server AUTH&lt;/P&gt;&lt;P&gt; address ipv4 172.x.x.x&lt;/P&gt;&lt;P&gt; key 7 xxxxxxxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and on my VTY Lines... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; privilege level 15&lt;/P&gt;&lt;P&gt; password 7 151619050826222A2F&lt;/P&gt;&lt;P&gt; authorization exec ACS-List&lt;/P&gt;&lt;P&gt; accounting commands 15 ACS-List&lt;/P&gt;&lt;P&gt; accounting exec ACS-List&lt;/P&gt;&lt;P&gt; login authentication ACS-List&lt;/P&gt;&lt;P&gt; length 0&lt;/P&gt;&lt;P&gt; transport input telnet ssh&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:36:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ios-15-not-working-with-my-tacacs-server/m-p/2271992#M182900</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2019-03-11T03:36:27Z</dc:date>
    </item>
    <item>
      <title>IOS 15 not working with my TACACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ios-15-not-working-with-my-tacacs-server/m-p/2271993#M182917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The config seems to be fine. What is the full code on which you are experincing this issue with tacacs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jul 2013 14:22:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ios-15-not-working-with-my-tacacs-server/m-p/2271993#M182917</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-07-02T14:22:52Z</dc:date>
    </item>
    <item>
      <title>IOS 15 not working with my TACACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ios-15-not-working-with-my-tacacs-server/m-p/2271994#M182963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's &lt;/P&gt;&lt;P&gt; Version 15.1(4)M6, RELEASE SOFTWARE (fc2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS 4.2&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jul 2013 14:31:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ios-15-not-working-with-my-tacacs-server/m-p/2271994#M182963</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2013-07-02T14:31:26Z</dc:date>
    </item>
    <item>
      <title>IOS 15 not working with my TACACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ios-15-not-working-with-my-tacacs-server/m-p/2271995#M183023</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As you're getting prompt for local credentials, that indicates tacacs is not reachable from the device in question. Are you able to ping tacacs server? Could you please run the debugs and share:&lt;/P&gt;&lt;P&gt;debug aaa authen&lt;/P&gt;&lt;P&gt;debug tacacs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jul 2013 14:47:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ios-15-not-working-with-my-tacacs-server/m-p/2271995#M183023</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-07-02T14:47:02Z</dc:date>
    </item>
    <item>
      <title>IOS 15 not working with my TACACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ios-15-not-working-with-my-tacacs-server/m-p/2271996#M183064</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I ran those debugs, then tried to login on another telnet session -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:01:57.278: TPLUS: Queuing AAA Accounting request 1781 for processing&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:01:57.278: TPLUS: processing accounting request id 1781&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:01:57.278: TPLUS: Sending AV task_id=1997&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:01:57.278: TPLUS: Sending AV timezone=SIN&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:01:57.278: TPLUS: Sending AV service=shell&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:01:57.278: TPLUS: Sending AV start_time=1372777317&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:01:57.278: TPLUS: Sending AV priv-lvl=15&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:01:57.278: TPLUS: Sending AV cmd=terminal monitor &lt;CR&gt;&lt;/CR&gt;&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:01:57.278: TPLUS: Accounting request created for 1781(admin)&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:01:57.278: TPLUS: using previously set server 172.x.x.x from group ACS1&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:01:57.278: TPLUS(000006F5)/0/NB_WAIT/3120C74C: Started 5 sec timeout&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:01:57.630: TPLUS(000006F5)/0/NB_WAIT: socket event 2&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:01:57.630: TPLUS(000006F5)/0/NB_WAIT: wrote entire 144 bytes request&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:01:57.630: TPLUS(000006F5)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:01:57.630: TPLUS(000006F5)/0/READ: Would block while reading&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:01:57.990: TPLUS(000006F5)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:01:57.990: TPLUS(000006F5)/0/READ: read 0 bytes&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:01:57.990: TPLUS(000006F5)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:01:57.990: TPLUS(000006F5)/0/READ: errno 254&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:01:57.990: TPLUS(000006F5)/0/3120C74C: Processing the reply packet&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:11.658: AAA/BIND(000006F9): Bind i/f&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:11.658: AAA/AUTHEN/LOGIN (000006F9): Pick method list 'ACS-List'&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:11.658: TPLUS: Queuing AAA Authentication request 1785 for processing&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:11.658: TPLUS: processing authentication start request id 1785&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:11.662: TPLUS: Authentication start packet created for 1785()&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:11.662: TPLUS: Using server 172.x.x.x&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:11.662: TPLUS(000006F9)/0/NB_WAIT/3120C74C: Started 5 sec timeout&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:12.014: TPLUS(000006F9)/0/NB_WAIT: socket event 2&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:12.014: TPLUS(000006F9)/0/NB_WAIT: wrote entire 38 bytes request&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:12.014: TPLUS(000006F9)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:12.014: TPLUS(000006F9)/0/READ: Would block while reading&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:12.366: TPLUS(000006F9)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:12.366: TPLUS(000006F9)/0/READ: errno 254&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:12.366: TPLUS(000006F9)/0/3120C74C: Processing the reply packet&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:24.474: AAA/AUTHEN/LOGIN (000006F9): Pick method list 'ACS-List'&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:24.474: TPLUS: Queuing AAA Authentication request 1785 for processing&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:24.474: TPLUS: processing authentication start request id 1785&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:24.474: TPLUS: Authentication start packet created for 1785()&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:24.474: TPLUS: Using server 172.x.x.x&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:24.474: TPLUS(000006F9)/0/NB_WAIT/3120C74C: Started 5 sec timeout&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:24.826: TPLUS(000006F9)/0/NB_WAIT: socket event 2&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:24.826: TPLUS(000006F9)/0/NB_WAIT: wrote entire 38 bytes request&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:24.826: TPLUS(000006F9)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:24.826: TPLUS(000006F9)/0/READ: Would block while reading&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:25.178: TPLUS(000006F9)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:25.178: TPLUS(000006F9)/0/READ: errno 254&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 2 15:02:25.178: TPLUS(000006F9)/0/3120C74C: Processing the reply packet&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jul 2013 15:03:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ios-15-not-working-with-my-tacacs-server/m-p/2271996#M183064</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2013-07-02T15:03:54Z</dc:date>
    </item>
    <item>
      <title>IOS 15 not working with my TACACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ios-15-not-working-with-my-tacacs-server/m-p/2271997#M183095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm being prompted for username / password but when I try my AD account it fails. If I try the local credentials, it works.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Jul 2013 15:04:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ios-15-not-working-with-my-tacacs-server/m-p/2271997#M183095</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2013-07-02T15:04:59Z</dc:date>
    </item>
    <item>
      <title>IOS 15 not working with my TACACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ios-15-not-working-with-my-tacacs-server/m-p/2271998#M183144</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Got this working - the Issue was that the routers in question were vpn endpoints using GRE/IPSEC. When contacting TACAS server it sources from the tunnel subnet and not the actual physical Interface subnet. I added the subnet to TACACS group and now works fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jul 2013 11:16:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ios-15-not-working-with-my-tacacs-server/m-p/2271998#M183144</guid>
      <dc:creator>GRANT3779</dc:creator>
      <dc:date>2013-07-04T11:16:42Z</dc:date>
    </item>
    <item>
      <title>IOS 15 not working with my TACACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ios-15-not-working-with-my-tacacs-server/m-p/2271999#M183181</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for keep this thread updated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jul 2013 11:19:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ios-15-not-working-with-my-tacacs-server/m-p/2271999#M183181</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-07-04T11:19:42Z</dc:date>
    </item>
    <item>
      <title>IOS 15 not working with my TACACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/ios-15-not-working-with-my-tacacs-server/m-p/2272000#M183231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, it seems you used the "&lt;/P&gt;&lt;P&gt;ip tacacs source-interface &lt;TUNNEL interfaface=""&gt;" command to source that traffic from the proper interface. let me know if that was the case.&lt;/TUNNEL&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Dec 2013 15:39:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ios-15-not-working-with-my-tacacs-server/m-p/2272000#M183231</guid>
      <dc:creator>ccnwankpa</dc:creator>
      <dc:date>2013-12-17T15:39:57Z</dc:date>
    </item>
  </channel>
</rss>

