<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cannot login into Router using TACACS+ in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cannot-login-into-router-using-tacacs/m-p/1916478#M217130</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What version code is running on your router and what version of ACS are you running? Is this a new installation or did this start all of a sudden?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also what is the source interface for the tacacs request? You may need to specify the source interface to send the tacacs request from.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 17 Mar 2012 22:05:24 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2012-03-17T22:05:24Z</dc:date>
    <item>
      <title>Cannot login into Router using TACACS+</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-login-into-router-using-tacacs/m-p/1916477#M217088</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cannot log into my OSPF router using TACACS+ below are the debug messages&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;.Mar 16 16:20:29: TPLUS(0000004F)/0/NB_WAIT/661E1170: timed out, clean up&lt;/P&gt;&lt;P&gt;.Mar 16 16:20:29: TPLUS(0000004F)/0/661E1170: Processing the reply packet&lt;/P&gt;&lt;P&gt;.Mar 16 16:24:46: TAC+: Using default tacacs server-group "TACACS-SERVERS" list.&lt;/P&gt;&lt;P&gt;.Mar 16 16:24:46: TAC+: Opening TCP/IP to x.x.x.x/49 timeout=5&lt;/P&gt;&lt;P&gt;.Mar 16 16:24:51: TAC+: TCP/IP open to x.x.x.x/49 failed -- Connection timed out; remote host not responding&lt;/P&gt;&lt;P&gt;.Mar 16 16:24:51: TPLUS: Queuing AAA Accounting request 75 for processing&lt;/P&gt;&lt;P&gt;.Mar 16 16:24:51: TPLUS: processing accounting request id 75&lt;/P&gt;&lt;P&gt;.Mar 16 16:24:51: TPLUS: Sending AV task_id=627&lt;/P&gt;&lt;P&gt;.Mar 16 16:24:51: TPLUS: Sending AV timezone=EDT&lt;/P&gt;&lt;P&gt;.Mar 16 16:24:51: TPLUS: Sending AV service=shell&lt;/P&gt;&lt;P&gt;.Mar 16 16:24:51: TPLUS: Sending AV start_time=1331929491&lt;/P&gt;&lt;P&gt;.Mar 16 16:24:51: TPLUS: Sending AV priv-lvl=1&lt;/P&gt;&lt;P&gt;.Mar 16 16:24:51: TPLUS: Sending AV cmd=show logging &amp;lt;cr&amp;gt;&lt;/P&gt;&lt;P&gt;.Mar 16 16:24:51: TPLUS: Accounting request created for 75(backup)&lt;/P&gt;&lt;P&gt;.Mar 16 16:24:51: TPLUS: Using server x.x.x.x&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;.Mar 16 16:20:29: TPLUS(0000004F)/0/NB_WAIT/661E1170: timed out, clean up&lt;BR /&gt;.Mar 16 16:20:29: TPLUS(0000004F)/0/661E1170: Processing the reply packet&lt;BR /&gt;.Mar 16 16:24:46: TAC+: Using default tacacs server-group "TACACS-SERVERS" list.&lt;BR /&gt;.Mar 16 16:24:46: TAC+: Opening TCP/IP to x.x.x.x/49 timeout=5&lt;BR /&gt;.Mar 16 16:24:51: TAC+: TCP/IP open to x.x.x.x/49 failed -- Connection timed out; remote host not responding&lt;BR /&gt;.Mar 16 16:24:51: TPLUS: Queuing AAA Accounting request 75 for processing&lt;BR /&gt;.Mar 16 16:24:51: TPLUS: processing accounting request id 75&lt;BR /&gt;.Mar 16 16:24:51: TPLUS: Sending AV task_id=627&lt;BR /&gt;.Mar 16 16:24:51: TPLUS: Sending AV timezone=EDT&lt;BR /&gt;.Mar 16 16:24:51: TPLUS: Sending AV service=shell&lt;BR /&gt;.Mar 16 16:24:51: TPLUS: Sending AV start_time=1331929491&lt;BR /&gt;.Mar 16 16:24:51: TPLUS: Sending AV priv-lvl=1&lt;BR /&gt;.Mar 16 16:24:51: TPLUS: Sending AV cmd=show logging &amp;lt;cr&amp;gt;&lt;BR /&gt;.Mar 16 16:24:51: TPLUS: Accounting request created for 75(backup)&lt;BR /&gt;.Mar 16 16:24:51: TPLUS: Using server x.x.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have comfirmed the IP on the server. The router can ping the TACACS+ server and telnet over port 49. I have confirmed the ip has a route. I have deleted / readded the entry on the ACS server. I have verfiied the TACACS+ key several times. &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:54:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-login-into-router-using-tacacs/m-p/1916477#M217088</guid>
      <dc:creator>nfordhk</dc:creator>
      <dc:date>2019-03-11T01:54:49Z</dc:date>
    </item>
    <item>
      <title>Cannot login into Router using TACACS+</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-login-into-router-using-tacacs/m-p/1916478#M217130</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What version code is running on your router and what version of ACS are you running? Is this a new installation or did this start all of a sudden?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also what is the source interface for the tacacs request? You may need to specify the source interface to send the tacacs request from.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Mar 2012 22:05:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-login-into-router-using-tacacs/m-p/1916478#M217130</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-03-17T22:05:24Z</dc:date>
    </item>
    <item>
      <title>Cannot login into Router using TACACS+</title>
      <link>https://community.cisco.com/t5/network-access-control/cannot-login-into-router-using-tacacs/m-p/1916479#M217175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nicholas,&lt;/P&gt;&lt;P&gt;As Tarik wrote, be sure that the remote server is aware of the source-interface configured on the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you try to telnet to the server?&lt;/P&gt;&lt;P&gt;telnet 1.1.1.1 49 /source-interface&lt;TACACS source="" interface=""&gt;&lt;/TACACS&gt;&lt;/P&gt;&lt;P&gt;You should be able to see "CONNECT".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also try to use the test aaa command, and see if your user get successfully authenticated.&lt;/P&gt;&lt;P&gt;'test aaa group tacacs &lt;USERNAME&gt; &lt;PASSWORD&gt; legacy'&lt;/PASSWORD&gt;&lt;/USERNAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Mar 2012 10:24:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cannot-login-into-router-using-tacacs/m-p/1916479#M217175</guid>
      <dc:creator>mavespig</dc:creator>
      <dc:date>2012-03-19T10:24:43Z</dc:date>
    </item>
  </channel>
</rss>

