<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problems with TACACS+ on VRF in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084545#M215278</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;TT&gt;aaa group server tacacs+ TACACS+&lt;BR /&gt;&amp;nbsp; server-private 172.25.25.153 key 7 120D55421A5A0E05262A343C6325&lt;BR /&gt;&amp;nbsp; server-private 172.25.25.154 key 7 09581E5C11541513070D143E7B34&lt;BR /&gt;&amp;nbsp; ip vrf forwarding MANAGEMENT&lt;BR /&gt;&amp;nbsp; ip tacacs source-interface Vlan500 &lt;BR /&gt;!&lt;BR /&gt; &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;ip radius source-interface Vlan500 &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TT&gt;&lt;/P&gt;&lt;P&gt;&lt;TT&gt;! &lt;/TT&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; So add it in global config as well.&lt;/P&gt;&lt;P&gt;BTW: what device/IOS version are you running?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;HR /&gt;&lt;P&gt; &lt;BR /&gt;I hope you find this information useful, if it was satisfactory&amp;nbsp; for you, please mark the question as Answered. &lt;BR /&gt; &lt;BR /&gt;Please rate post you consider useful. &lt;BR /&gt;-James&lt;/P&gt;&lt;DIV id="nuan_ria_plugin"&gt;&lt;OBJECT height="0" id="plugin0" style="position: absolute; z-index: 1000;" type="application/x-dgnria" width="0"&gt;&lt;PARAM name="tabId" /&gt;&lt;PARAM name="counter" /&gt;&lt;/OBJECT&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 Dec 2012 02:02:24 GMT</pubDate>
    <dc:creator>jw.sl9</dc:creator>
    <dc:date>2012-12-06T02:02:24Z</dc:date>
    <item>
      <title>Problems with TACACS+ on VRF</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084544#M215277</link>
      <description>&lt;P&gt;Hello there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've configured a management VRF and am trying to get tacacs+ to work. I have done some debugging but I've come to the point where I don't know what I can do more/cant see where im going wrong. bnawaz is my tacacs enabled account and admin is a local account.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is debug out put and config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Queuing AAA Authentication request 103 for processing&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: processing authentication start request id 103&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Authentication start packet created for 103(bnawaz)&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Using server 172.25.25.153&lt;/P&gt;&lt;P&gt;1w2d: TPLUS(00000067)/0: Connect Error No route to host&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Choosing next server 172.25.25.154&lt;/P&gt;&lt;P&gt;1w2d: TPLUS(00000067)/0: Connect Error No route to host&lt;/P&gt;&lt;P&gt;1w2d: %AAA-3-BADSERVERTYPEERROR: Cannot process authentication server type radius (UNKNOWN)&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Queuing AAA Authentication request 103 for processing&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: processing authentication start request id 103&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Authentication start packet created for 103(bnawaz)&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Using server 172.25.25.153&lt;/P&gt;&lt;P&gt;1w2d: TPLUS(00000067)/0: Connect Error No route to host&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Choosing next server 172.25.25.154&lt;/P&gt;&lt;P&gt;1w2d: TPLUS(00000067)/0: Connect Error No route to host&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Queuing AAA Authentication request 103 for processing&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: processing authentication start request id 103&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Authentication start packet created for 103(bnawaz)&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Using server 172.25.25.153&lt;/P&gt;&lt;P&gt;1w2d: TPLUS(00000067)/0: Connect Error No route to host&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Choosing next server 172.25.25.154&lt;/P&gt;&lt;P&gt;1w2d: TPLUS(00000067)/0: Connect Error No route to host&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Queuing AAA Authentication request 103 for processing&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: processing authentication start request id 103&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Authentication start packet created for 103(bnawaz)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1w2d: TAC+: Using default tacacs server-group "tacacs+" list.&lt;/P&gt;&lt;P&gt;1w2d: TAC+: Opening TCP/IP to 172.25.25.153/49 timeout=5&lt;/P&gt;&lt;P&gt;1w2d: TAC+: TCP/IP open to 172.25.25.153/49 failed -- Destination unreachable; gateway or host down&lt;/P&gt;&lt;P&gt;1w2d: TAC+: Opening TCP/IP to 172.25.25.154/49 timeout=5&lt;/P&gt;&lt;P&gt;1w2d: TAC+: TCP/IP open to 172.25.25.154/49 failed -- Destination unreachable; gateway or host down&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Queuing AAA Accounting request 101 for processing&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: processing accounting request id 101&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Sending AV task_id=250&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Sending AV timezone=GMT&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Sending AV service=shell&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Sending AV priv-lvl=15&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Sending AV cmd=show running-config &amp;lt;cr&amp;gt;&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Accounting request created for 101(admin)&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Using server 172.25.25.153&lt;/P&gt;&lt;P&gt;1w2d: TPLUS(00000065)/0: Connect Error No route to host&lt;/P&gt;&lt;P&gt;1w2d: TPLUS: Choosing next server 172.25.25.154&lt;/P&gt;&lt;P&gt;1w2d: TPLUS(00000065)/0: Connect Error No route to host&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ TACACS+&lt;/P&gt;&lt;P&gt; server-private 172.25.25.153 key 7 120D55421A5A0E05262A343C6325&lt;/P&gt;&lt;P&gt; server-private 172.25.25.154 key 7 09581E5C11541513070D143E7B34&lt;/P&gt;&lt;P&gt; ip vrf forwarding MANAGEMENT&lt;/P&gt;&lt;P&gt; ip tacacs source-interface Vlan500&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login TACACS+ group tacacs+ group radius local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;ip vrf MANAGEMENT&lt;/P&gt;&lt;P&gt; rd 99:500&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan500&lt;/P&gt;&lt;P&gt; ip vrf forwarding MANAGEMENT&lt;/P&gt;&lt;P&gt; ip address 172.25.99.4 255.255.255.240&lt;/P&gt;&lt;P&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;no ip http server&lt;/P&gt;&lt;P&gt;no ip http secure-server&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;ip route vrf MANAGEMENT 0.0.0.0 0.0.0.0 172.25.99.1 &lt;SPAN style="color: #ff0000;"&gt;[THE DEFAULT GW]&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; login authentication FOS_TACACS+&lt;/P&gt;&lt;P&gt; transport input ssh&lt;/P&gt;&lt;P&gt;line vty 5 15&lt;/P&gt;&lt;P&gt; login authentication FOS_TACACS+&lt;/P&gt;&lt;P&gt; transport input ssh&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DMZ-3560-2#ping vrf MANAGEMENT 172.25.25.153&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 172.25.25.153, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;!!!!!&lt;/P&gt;&lt;P&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/3/8 ms&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:51:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084544#M215277</guid>
      <dc:creator>Bilal Nawaz</dc:creator>
      <dc:date>2019-03-11T02:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with TACACS+ on VRF</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084545#M215278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;TT&gt;aaa group server tacacs+ TACACS+&lt;BR /&gt;&amp;nbsp; server-private 172.25.25.153 key 7 120D55421A5A0E05262A343C6325&lt;BR /&gt;&amp;nbsp; server-private 172.25.25.154 key 7 09581E5C11541513070D143E7B34&lt;BR /&gt;&amp;nbsp; ip vrf forwarding MANAGEMENT&lt;BR /&gt;&amp;nbsp; ip tacacs source-interface Vlan500 &lt;BR /&gt;!&lt;BR /&gt; &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;ip radius source-interface Vlan500 &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/TT&gt;&lt;/P&gt;&lt;P&gt;&lt;TT&gt;! &lt;/TT&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; So add it in global config as well.&lt;/P&gt;&lt;P&gt;BTW: what device/IOS version are you running?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;HR /&gt;&lt;P&gt; &lt;BR /&gt;I hope you find this information useful, if it was satisfactory&amp;nbsp; for you, please mark the question as Answered. &lt;BR /&gt; &lt;BR /&gt;Please rate post you consider useful. &lt;BR /&gt;-James&lt;/P&gt;&lt;DIV id="nuan_ria_plugin"&gt;&lt;OBJECT height="0" id="plugin0" style="position: absolute; z-index: 1000;" type="application/x-dgnria" width="0"&gt;&lt;PARAM name="tabId" /&gt;&lt;PARAM name="counter" /&gt;&lt;/OBJECT&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2012 02:02:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084545#M215278</guid>
      <dc:creator>jw.sl9</dc:creator>
      <dc:date>2012-12-06T02:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with TACACS+ on VRF</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084546#M215279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi James,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch Ports Model&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SW Version&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SW Image&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;------ ----- -----&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ----------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ----------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;*&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 26&amp;nbsp;&amp;nbsp;&amp;nbsp; WS-C3560-24TS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 15.0(2)SE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; C3560-IPSERVICESK9-M&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried the ip radius source-interface command, but unfortunately didnt work. I read somewhere that it may be trying to use the global routing table hence the "Connect Error No route to host" output from the debug. Perhaps a limitation? not sure?&lt;/P&gt;&lt;P&gt;Used the global routing table without VRF and it works fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2012 08:33:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084546#M215279</guid>
      <dc:creator>Bilal Nawaz</dc:creator>
      <dc:date>2012-12-06T08:33:22Z</dc:date>
    </item>
    <item>
      <title>Problems with TACACS+ on VRF</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084547#M215280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bilal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your configuration looks fine. I think this is a issue with the IOS. I have another work around which you could try to fix this. Try putting a static route on the global routing table for the ACS ip address and point it towards the VRF interface as the exit interface. You are basically fooling the router here by offering a route for ACS on the global routing table. A typical static route would be as below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip route 172.25.25.153 255.255.255.255 &lt;X.X.X.X&gt;&lt;/X.X.X.X&gt;&lt;/STRONG&gt; where x.x.x.x is router interface ip address which is part of your VRF named MANAGMENT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Give a try and let us know how it goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Najaf&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Please rate when applicable or helpful !!!&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2012 11:02:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084547#M215280</guid>
      <dc:creator>kcnajaf</dc:creator>
      <dc:date>2012-12-06T11:02:31Z</dc:date>
    </item>
    <item>
      <title>Problems with TACACS+ on VRF</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084548#M215281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Najaf,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also tried static default routes to the gateway as well as static routes towards both ACS servers but still didnt seem to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In terms of tacacs, the global routing table wouldn't know about the VRF network nor the interface.&lt;/P&gt;&lt;P&gt;i.e when doing a show ip route (when you have a vrf) no routes are displayed of connected interfaces or networks which is expected....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 172.25.25.153 255.255.255.255 vlan500 didn't work too.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2012 11:38:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084548#M215281</guid>
      <dc:creator>Bilal Nawaz</dc:creator>
      <dc:date>2012-12-06T11:38:57Z</dc:date>
    </item>
    <item>
      <title>Problems with TACACS+ on VRF</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084549#M215282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bilal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you provide the Show ip route output from global routing table and vrf table? Also you where able to ping the acs servers after adding the static route with all other configuration intact (configuration exactly same as what you have initially posted. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Najaf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2012 12:04:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084549#M215282</guid>
      <dc:creator>kcnajaf</dc:creator>
      <dc:date>2012-12-06T12:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with TACACS+ on VRF</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084550#M215283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/2/2/5/117522-DMZ.JPG" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;Even if I change the "ip route 172.25.25.153 255.255.255.255 172.25.99.1" to&lt;/P&gt;&lt;P&gt;172.25.25.153 255.255.255.255 172.25.99.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still doesn't work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2012 13:46:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084550#M215283</guid>
      <dc:creator>Bilal Nawaz</dc:creator>
      <dc:date>2012-12-06T13:46:59Z</dc:date>
    </item>
    <item>
      <title>Problems with TACACS+ on VRF</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084551#M215284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bilal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try applying the static route as&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ip route 172.25.25.153 255.255.255.255 Vlan500 172.25.99.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and verify if the rotue is coming in the global routing table.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it showing up on the routing table try enabling the debug which you have enabled on the initial post and verify if you are getting the same message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Najaf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2012 18:53:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084551#M215284</guid>
      <dc:creator>kcnajaf</dc:creator>
      <dc:date>2012-12-06T18:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with TACACS+ on VRF</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084552#M215285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone ever found a way to make this work without using the global routing table as the "management vrf" ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the same routing issues as the OP describes. Same config. Same debug output. Tried to use the vlan interface as source interface as well as a loopback in the management vrf. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;c3750e-universalk9-mz.122-58.SE2.bin but I also experience this with other IOS versions on switches running management in a vrf. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I required to configure an RD for the vrf the ip tacacs source-interface is using or is it not needed? Right now its just &lt;NOT set=""&gt;.&lt;/NOT&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Aleksander&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Feb 2014 20:59:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084552#M215285</guid>
      <dc:creator>aleksander.olsen</dc:creator>
      <dc:date>2014-02-18T20:59:54Z</dc:date>
    </item>
    <item>
      <title>I have indeed found a way to</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084553#M215286</link>
      <description>&lt;P&gt;I have indeed found a way to make this work (with some assistance). It works out that the aaa commands need to reference the TACACS+ group itself, not just default tacacs+ servers defined.&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Sat, 24 May 2014 13:00:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084553#M215286</guid>
      <dc:creator>Bilal Nawaz</dc:creator>
      <dc:date>2014-05-24T13:00:00Z</dc:date>
    </item>
    <item>
      <title>Hi, I have the same problem</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084554#M215287</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the same problem on an 6503-E (s3223-advipservicesk9_wan-mz.122-33.SXH3a.bin). The configuration with VRF on another 6509-E works but on this model, it not works (I ping the tacacs server with the VRF). Can you detail the way that you found ( the commands ?).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Nov 2014 10:33:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084554#M215287</guid>
      <dc:creator>dfrenay_olabs</dc:creator>
      <dc:date>2014-11-20T10:33:19Z</dc:date>
    </item>
    <item>
      <title>aaa group server tacacs+</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084555#M215288</link>
      <description>&lt;P&gt;aaa group server tacacs+ BILAL_TACACS+&lt;BR /&gt;&amp;nbsp;server name DC1_BILALACS01&lt;BR /&gt;&amp;nbsp;server name DC1_BILALACS02&lt;BR /&gt;&amp;nbsp;server name DC1_BILALACS03&lt;BR /&gt;&amp;nbsp;ip vrf forwarding mgmtVrf&lt;BR /&gt;&amp;nbsp;ip tacacs source-interface FastEthernet1&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default group tacacs+ local&lt;BR /&gt;aaa authentication login BILAL_TACACS+ group BILAL_TACACS+ group radius local&lt;BR /&gt;aaa authentication enable default group BILAL_TACACS+ group tacacs+ enable line&lt;BR /&gt;aaa authorization exec default group BILAL_TACACS+ local&amp;nbsp;&lt;BR /&gt;aaa authorization commands 15 default group BILAL_TACACS+ group tacacs+ local if-authenticated&amp;nbsp;&lt;BR /&gt;aaa accounting exec default start-stop group BILAL_TACACS+ group tacacs+&lt;BR /&gt;aaa accounting exec BILAL_TACACS+ start-stop group tacacs+&lt;BR /&gt;aaa accounting commands 15 default start-stop group BILAL_TACACS+ group tacacs+&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;ip route vrf mgmtVrf 0.0.0.0 0.0.0.0 10.10.10.10&lt;BR /&gt;ip tacacs source-interface FastEthernet1&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;tacacs server DC1_BILALACS01&lt;BR /&gt;&amp;nbsp;address ipv4 172.25.24.151&lt;BR /&gt;&amp;nbsp;key 7 xxxxxx&lt;BR /&gt;tacacs server DC1_BILALACS02&lt;BR /&gt;&amp;nbsp;address ipv4 172.25.24.152&lt;BR /&gt;&amp;nbsp;key 7 xxxxxx&lt;BR /&gt;tacacs server DC1_BILALACS03&lt;BR /&gt;&amp;nbsp;address ipv4 172.25.24.153&lt;BR /&gt;&amp;nbsp;key 7 xxxxxx&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt;&amp;nbsp;exec-timeout 0 0&lt;BR /&gt;&amp;nbsp;password 7 xxxxxx&lt;BR /&gt;&amp;nbsp;login authentication BILAL_TACACS+&lt;BR /&gt;&amp;nbsp;stopbits 1&lt;BR /&gt;line vty 0 4&lt;BR /&gt;&amp;nbsp;password 7 xxxxxx&lt;BR /&gt;&amp;nbsp;login authentication BILAL_TACACS+&lt;BR /&gt;&amp;nbsp;transport input ssh&lt;BR /&gt;line vty 5 15&lt;BR /&gt;&amp;nbsp;accounting commands 0 BILAL_TACACS+&lt;BR /&gt;&amp;nbsp;accounting commands 15 BILAL_TACACS+&lt;BR /&gt;&amp;nbsp;login authentication BILAL_TACACS+&lt;BR /&gt;&amp;nbsp;transport input ssh&lt;/P&gt;</description>
      <pubDate>Thu, 20 Nov 2014 11:28:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084555#M215288</guid>
      <dc:creator>Bilal Nawaz</dc:creator>
      <dc:date>2014-11-20T11:28:42Z</dc:date>
    </item>
    <item>
      <title>Thank you very much. In fact</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084556#M215291</link>
      <description>&lt;P&gt;Thank you very much. In fact this is near of my configuration, so the problem is somewhere else.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Nov 2014 12:59:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-tacacs-on-vrf/m-p/2084556#M215291</guid>
      <dc:creator>dfrenay_olabs</dc:creator>
      <dc:date>2014-11-20T12:59:43Z</dc:date>
    </item>
  </channel>
</rss>

