<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tacacs authentication problem. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-problem/m-p/1944112#M211888</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Can you please capture sniffer trace while the issue is happenning on the ACS side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also provide the tacacs+ key to decrypt the tacaacs+ payload.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 20 May 2012 09:48:15 GMT</pubDate>
    <dc:creator>maldehne</dc:creator>
    <dc:date>2012-05-20T09:48:15Z</dc:date>
    <item>
      <title>Tacacs authentication problem.</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-problem/m-p/1944108#M211883</link>
      <description>&lt;P&gt;Hy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a network with several layer 2 (c2960) attached to a layer 3 switch (c3750). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All these switches are behind a firewall (ASA 5510) and the firewall is connected to a router c3810.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an ACS v.4.x to use as a Tacacs server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In all the equipments I have aaa authentication with tacacs and vlans.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To test the tacacs authentication in the switch, I created a bypass to the firewall and connected the network (using a management vlan) to the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With this scenario the tacacs authentication works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I disconnect the bypass, all the traffic cross over the firewall. But I will not have the tacacs working anymore with the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do not understand why!!?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have another problem, this time with the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured the tacacs and the aaa in the firewall, as advised by Cisco.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it seems that it doesn’t work!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this two cases only the local authentication works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you help me, please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Rui Oliveira&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:05:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-problem/m-p/1944108#M211883</guid>
      <dc:creator>rcapao</dc:creator>
      <dc:date>2019-03-11T02:05:35Z</dc:date>
    </item>
    <item>
      <title>Tacacs authentication problem.</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-problem/m-p/1944109#M211885</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What can you see in the failed attempts when are you trying to login to the swtich?&lt;/P&gt;&lt;P&gt;Also what can you see in the failed attempts when you are not able to logint to the FW?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2012 04:07:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-problem/m-p/1944109#M211885</guid>
      <dc:creator>maldehne</dc:creator>
      <dc:date>2012-05-16T04:07:50Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs authentication problem.</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-problem/m-p/1944110#M211886</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am doing tests in a Lab. &lt;/P&gt;&lt;P&gt;So, the addresses presented here are not Internet routable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I´m doing the tests with a switch that has the IP address 10.183.0.60.&lt;/P&gt;&lt;P&gt;My ACS has IP 172.16.20.10 and the standard port for tacacs is tcp/49.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I send the logging file that I take from my firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Rui&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 May 2012 16:12:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-problem/m-p/1944110#M211886</guid>
      <dc:creator>rcapao</dc:creator>
      <dc:date>2012-05-18T16:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs authentication problem.</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-problem/m-p/1944111#M211887</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am doing tests in a Lab. &lt;/P&gt;&lt;P&gt;So, the addresses presented here are not Internet routable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration for the tacacs at the ASA is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server TACACS protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TACACS (OUT_MANGMT) host 172.16.20.10&lt;/P&gt;&lt;P&gt; key mykey&lt;/P&gt;&lt;P&gt;aaa authentication enable console LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication serial console LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication telnet console TACACS LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication http console TACACS LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console TACACS LOCAL&lt;/P&gt;&lt;P&gt;aaa authorization command LOCAL&lt;/P&gt;&lt;P&gt;aaa accounting enable console TACACS&lt;/P&gt;&lt;P&gt;aaa accounting telnet console TACACS&lt;/P&gt;&lt;P&gt;aaa accounting ssh console TACACS&lt;/P&gt;&lt;P&gt;aaa local authentication attempts max-fail 5&lt;/P&gt;&lt;P&gt;aaa authorization exec LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I´m doing the tests with an ASA with a the IP address 10.183.0.61.&lt;/P&gt;&lt;P&gt;And this address is seen from the outside, but I do a NAT between the 10.183.0.61 and the IP address 192.168.100.2 in the TCP/23.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Besides that I have an interface called OUT_MANGMT, with IP address 192.168.100.2 .&lt;/P&gt;&lt;P&gt;I have another interface that a called GESTAO, with IP address 10.183.0.61.&lt;/P&gt;&lt;P&gt;This interface GESTAO is connected to a management vlan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My ACS has IP 172.16.20.10 and the standard port for tacacs is tcp/49.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I send the logging file that I take from my firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Rui&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 May 2012 22:47:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-problem/m-p/1944111#M211887</guid>
      <dc:creator>rcapao</dc:creator>
      <dc:date>2012-05-18T22:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs authentication problem.</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-problem/m-p/1944112#M211888</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Can you please capture sniffer trace while the issue is happenning on the ACS side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also provide the tacacs+ key to decrypt the tacaacs+ payload.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 20 May 2012 09:48:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-problem/m-p/1944112#M211888</guid>
      <dc:creator>maldehne</dc:creator>
      <dc:date>2012-05-20T09:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs authentication problem.</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-problem/m-p/1944113#M211889</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cannot do that, because de ACS is in a network that I do not control.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, it will be very, very, difficult to sniff the traffic for that network, particularly to and from the ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But, I think this problem in not in the ACS. Because if I put all the switch doing authentication without crossing over the firewall (using the bypass) I will have no problem in authenticating with the tacacs server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the other end, if I use the firewall to cross over to the tacacs server, I will not succeed in authenticating with that server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With these observations, I take that I could have some kind of problem in the ASA that do not let me to authenticate properly with the tacacs server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I am doing something wrong, what is it? It´s configuration? It´s network design?&lt;/P&gt;&lt;P&gt;Can someone help me with this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Rui &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 May 2012 10:05:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-problem/m-p/1944113#M211889</guid>
      <dc:creator>rcapao</dc:creator>
      <dc:date>2012-05-21T10:05:46Z</dc:date>
    </item>
  </channel>
</rss>

