<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS user unknown though username in Server in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359308#M224427</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I dont have any issue connecting VPN. SSL VPN is configured in that ASA only. VPN is connected but couldnt SSH ASA&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 28 Oct 2013 09:16:05 GMT</pubDate>
    <dc:creator>nirmalkumar</dc:creator>
    <dc:date>2013-10-28T09:16:05Z</dc:date>
    <item>
      <title>ACS user unknown though username in Server</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359305#M224418</link>
      <description>&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; All, Im facing very strange issue with my TACACS authentication. Normaly i connect my DC via SSL Anyconnect VPN then access all the Network devices, but since last week when i try to connect ASA i couldnt log in. I have user name in ACS server and the password authentication would redirect to RSA server. I can access other devices using my TACACS username and RSA passcode, but not only the ASA box. As rest of my team member can still access the ASA with their userid and passcode i dont think any issue in ASA box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The error log message in ACS server is ACS user unknown.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:02:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359305#M224418</guid>
      <dc:creator>nirmalkumar</dc:creator>
      <dc:date>2019-03-11T04:02:23Z</dc:date>
    </item>
    <item>
      <title>ACS user unknown though username in Server</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359306#M224421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If rest of your team can access the vpn via same ASA and ACS then yes could be an issues with user account itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you locate your account on the ACS. Please verify.&lt;/P&gt;&lt;P&gt;What ACS/Tacacs server are you using?&lt;/P&gt;&lt;P&gt;If you have your account there then please try delete and add it again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 08:50:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359306#M224421</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-10-28T08:50:42Z</dc:date>
    </item>
    <item>
      <title>ACS user unknown though username in Server</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359307#M224424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello Jatin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes I can see my username and its mapped to correct Group as well. I can even access other devices in DC with same username and RSA passcode. Im facing issue only with this ASA box. If there is some issue in ASA then other team member couldnt access but they can.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i see the failed authentication log in ACS it show ACS user unknown and the group is default&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 09:15:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359307#M224424</guid>
      <dc:creator>nirmalkumar</dc:creator>
      <dc:date>2013-10-28T09:15:00Z</dc:date>
    </item>
    <item>
      <title>ACS user unknown though username in Server</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359308#M224427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I dont have any issue connecting VPN. SSL VPN is configured in that ASA only. VPN is connected but couldnt SSH ASA&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 09:16:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359308#M224427</guid>
      <dc:creator>nirmalkumar</dc:creator>
      <dc:date>2013-10-28T09:16:05Z</dc:date>
    </item>
    <item>
      <title>ACS user unknown though username in Server</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359309#M224432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So you can use the same username and passcode to rest of network devices while connected through vpn and when you ssh to your ASA, it prompts you for username / passcode then shows authentication failed. On the ACS when you check the failed attempts you see "ACS username unknown" and group appear as default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 09:47:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359309#M224432</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-10-28T09:47:19Z</dc:date>
    </item>
    <item>
      <title>ACS user unknown though username in Server</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359310#M224440</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Yes exactly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FYI..SSL is configured in that ASA only, i dont have any issue connecting VPN, facing issue only with the management traffic. Rest of my team member can access the ASA box with their username and passcode, they are also in same Group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOTE : ACS verison is Cisco ACS 4.2&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 09:52:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359310#M224440</guid>
      <dc:creator>nirmalkumar</dc:creator>
      <dc:date>2013-10-28T09:52:13Z</dc:date>
    </item>
    <item>
      <title>Re: ACS user unknown though username in Server</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359311#M224445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Weird &lt;SPAN __jive_emoticon_name="confused" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt; ...f&lt;SPAN style="font-size: 10pt;"&gt;or testing purpose, can you add new user account to the same group and check. If that works, t&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;ry to delete your user account from ACS and re-add for testing purpose.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 09:56:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359311#M224445</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-10-28T09:56:01Z</dc:date>
    </item>
    <item>
      <title>ACS user unknown though username in Server</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359312#M224453</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I need to access ACS via SSL vpn with the TACACS credentials, if i delete and re-configure will it break the VPN connetion?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 10:00:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359312#M224453</guid>
      <dc:creator>nirmalkumar</dc:creator>
      <dc:date>2013-10-28T10:00:49Z</dc:date>
    </item>
    <item>
      <title>ACS user unknown though username in Server</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359313#M224462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Jatin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did what you said. i created a new&amp;nbsp; userid and selected Password authentication for ACS internal database and manually assigned password. When i try to conncet SSL it was successful and also I can access all other device with new usrname and static password except that ASA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 10:13:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359313#M224462</guid>
      <dc:creator>nirmalkumar</dc:creator>
      <dc:date>2013-10-28T10:13:05Z</dc:date>
    </item>
    <item>
      <title>ACS user unknown though username in Server</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359314#M224473</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you see the same error for the new userid as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please attach show run from the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 10:16:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359314#M224473</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-10-28T10:16:15Z</dc:date>
    </item>
    <item>
      <title>ACS user unknown though username in Server</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359315#M224484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Yes same error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cant access that ASA to get the running config. Accessing that remotely&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 10:19:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359315#M224484</guid>
      <dc:creator>nirmalkumar</dc:creator>
      <dc:date>2013-10-28T10:19:32Z</dc:date>
    </item>
    <item>
      <title>ACS user unknown though username in Server</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359316#M224494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To me it seems the shared secret being used on ASA to communicate with tacacs is mis-matched and that's a reason you&amp;nbsp; are getting "ACS user unknown". This should be a problem all users who are trying to do ssh on ASA and authenticating against tacacs server. Why share-secret could be an issue because the shared secret being used to encrypt the packet is not same while decryption and that's why we are seeing unknown username.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 12:34:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359316#M224494</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-10-28T12:34:22Z</dc:date>
    </item>
    <item>
      <title>ACS user unknown though username in Server</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359317#M224510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; If that is the case how come rest of my team member can access the device? Will this type of issue can affect single userid?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 12:40:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359317#M224510</guid>
      <dc:creator>nirmalkumar</dc:creator>
      <dc:date>2013-10-28T12:40:02Z</dc:date>
    </item>
    <item>
      <title>ACS user unknown though username in Server</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359318#M224531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My reasoning based on the last test we did with the new users. Other users also should not have access if shared secret is mismatched. However, it would be worth looking at shared secret on both the sides because unknown users only comes as an error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.] If we don't have user created in the defined database.&lt;/P&gt;&lt;P&gt;2.] Shared secret is wrong due to that ACS is looking up for a different user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Oct 2013 13:28:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-user-unknown-though-username-in-server/m-p/2359318#M224531</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-10-28T13:28:54Z</dc:date>
    </item>
  </channel>
</rss>

