<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problems with tacacs Authorisation with ACS5.3 and Catalyst 3750 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-authorisation-with-acs5-3-and-catalyst/m-p/2049911#M209955</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is currently your show run | inc aaa?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 24 Aug 2012 20:02:04 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2012-08-24T20:02:04Z</dc:date>
    <item>
      <title>Problems with tacacs Authorisation with ACS5.3 and Catalyst 3750s</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-authorisation-with-acs5-3-and-catalyst/m-p/2049907#M209799</link>
      <description>&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I am in the process of upgrading the ACS from 4.1.1. to 5.3, &lt;/P&gt;&lt;P&gt;I have Catalyst 3750s with various levels of IOS and with ACS 4.1.1 there were no problems&lt;/P&gt;&lt;P&gt;AAA config on switches as below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication login console local&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 0 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now with ACS5.3&amp;nbsp; I find that switches running 122-35.SE5 (ipbase) no problems, all ok&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but switches running later IOS 122-50.SE5, 122-55.SE5, and 15,0.1 I&amp;nbsp;&amp;nbsp;&amp;nbsp; users with the privilege level of 15 fails authorization most of the time.&lt;/P&gt;&lt;P&gt;users with privilege&amp;nbsp; level 7 no problems&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on advise from various&amp;nbsp; entries on the support forums as below but did not make any difference&lt;/P&gt;&lt;P&gt;can anybody help with this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication login console local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group radius&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default if-authenticated&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 0 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:27:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-authorisation-with-acs5-3-and-catalyst/m-p/2049907#M209799</guid>
      <dc:creator>Richard Bradfield</dc:creator>
      <dc:date>2019-03-11T02:27:15Z</dc:date>
    </item>
    <item>
      <title>Problems with tacacs Authorisation with ACS5.3 and Catalyst 3750</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-authorisation-with-acs5-3-and-catalyst/m-p/2049908#M209801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;these many commands are not required. Esp dot1x authentication commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what is the configuration you have done on the ACS 5.3? that is the place we have to see.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check the logs when the Users are getting failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nitesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2012 13:43:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-authorisation-with-acs5-3-and-catalyst/m-p/2049908#M209801</guid>
      <dc:creator>saxenanitesh8522</dc:creator>
      <dc:date>2012-08-23T13:43:58Z</dc:date>
    </item>
    <item>
      <title>Problems with tacacs Authorisation with ACS5.3 and Catalyst 3750</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-authorisation-with-acs5-3-and-catalyst/m-p/2049909#M209813</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nitesh is correct,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In ACS 5.3 the default command set is set to deny all. However this may not appear until you select the customize button in your authorization profile to make the "Command Set" option visible, there you will be able to set the condition to use the command set you want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2012 17:49:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-authorisation-with-acs5-3-and-catalyst/m-p/2049909#M209813</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-08-23T17:49:14Z</dc:date>
    </item>
    <item>
      <title>Problems with tacacs Authorisation with ACS5.3 and Catalyst 3750</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-authorisation-with-acs5-3-and-catalyst/m-p/2049910#M209854</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Tarik,&lt;/P&gt;&lt;P&gt; I think the problem is with the Cat 3750 as I can login into a switch running 122-35.SE5 ok, but when I log into a switch running 122-50.Se5 I get 'Authorization failed' message, this is for a user with a privilege level of 15. But no prblems with user with a privilege level of 7,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There must be a difference in the way Tacacs is handled betwen the different levels of OS in the Switch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Aug 2012 21:47:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-authorisation-with-acs5-3-and-catalyst/m-p/2049910#M209854</guid>
      <dc:creator>Richard Bradfield</dc:creator>
      <dc:date>2012-08-23T21:47:03Z</dc:date>
    </item>
    <item>
      <title>Problems with tacacs Authorisation with ACS5.3 and Catalyst 3750</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-authorisation-with-acs5-3-and-catalyst/m-p/2049911#M209955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is currently your show run | inc aaa?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2012 20:02:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-authorisation-with-acs5-3-and-catalyst/m-p/2049911#M209955</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-08-24T20:02:04Z</dc:date>
    </item>
    <item>
      <title>Problems with tacacs Authorisation with ACS5.3 and Catalyst 3750</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-authorisation-with-acs5-3-and-catalyst/m-p/2049912#M210008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; We opened a case with Cisco TAC, and after much looking around came to the conclusion the problem was:&lt;/P&gt;&lt;P&gt;the "tacacs-server host xx.xx.xx.xx&amp;nbsp; single-connection" command on the Cat 3750's&lt;/P&gt;&lt;P&gt;removed the "single-connection" from the command&amp;nbsp; and now&amp;nbsp; authorization ok no longer intermittent&lt;/P&gt;&lt;P&gt;We have had these switches some time and the "single-connection " is no longer required.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Aug 2012 02:19:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-authorisation-with-acs5-3-and-catalyst/m-p/2049912#M210008</guid>
      <dc:creator>Richard Bradfield</dc:creator>
      <dc:date>2012-08-25T02:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with tacacs Authorisation with ACS5.3 and Catalyst</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-authorisation-with-acs5-3-and-catalyst/m-p/2049913#M210055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for he response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Aug 2012 18:00:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-authorisation-with-acs5-3-and-catalyst/m-p/2049913#M210055</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-08-25T18:00:54Z</dc:date>
    </item>
  </channel>
</rss>

