<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TACACS authentication fails for one of our network device in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-fails-for-one-of-our-network-device/m-p/1863741#M227421</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have Distributed deployment, and i found one of the Secondary instance is not connecting to domain. It giving following message " connection test to domain failed&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - clock skew error.&amp;nbsp; "&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Jan 2012 19:09:53 GMT</pubDate>
    <dc:creator>Santosh Shetty</dc:creator>
    <dc:date>2012-01-06T19:09:53Z</dc:date>
    <item>
      <title>TACACS authentication fails for one of our network device</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-fails-for-one-of-our-network-device/m-p/1863737#M227415</link>
      <description>&lt;P&gt;ACS 5.1 is failing to authenticate tacacs authentication to the ASA firewall, getting &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:41:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-fails-for-one-of-our-network-device/m-p/1863737#M227415</guid>
      <dc:creator>Santosh Shetty</dc:creator>
      <dc:date>2019-03-11T01:41:38Z</dc:date>
    </item>
    <item>
      <title>TACACS authentication fails for one of our network device</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-fails-for-one-of-our-network-device/m-p/1863738#M227417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you access the ACS 5.x CLI and execute "show application status acs" are all the services running?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, under the ACS 5.x GUI Users and Identity Stores &amp;gt; External Identity Stores &amp;gt; Active Directory which is the status of the ACS under Connectivity Status? Is it showing as Connected or Disconnected?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jan 2012 16:53:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-fails-for-one-of-our-network-device/m-p/1863738#M227417</guid>
      <dc:creator>camejia</dc:creator>
      <dc:date>2012-01-06T16:53:53Z</dc:date>
    </item>
    <item>
      <title>TACACS authentication fails for one of our network device</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-fails-for-one-of-our-network-device/m-p/1863739#M227419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Carlos,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I verified all services are running and also AD status is connected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All the device are able to authenticate using ACS except one which show up following error message in ACS log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "24444 Active Directory Operation has failed because of an unspecified errro in the ACS"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jan 2012 18:29:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-fails-for-one-of-our-network-device/m-p/1863739#M227419</guid>
      <dc:creator>Santosh Shetty</dc:creator>
      <dc:date>2012-01-06T18:29:01Z</dc:date>
    </item>
    <item>
      <title>TACACS authentication fails for one of our network device</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-fails-for-one-of-our-network-device/m-p/1863740#M227420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Santosh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wanted to verify the following as well. How many ACS servers do you have on your network? Is it only one ACS server acting as standalone? Or do you have a Distributed Deployment with Secondary ACS Servers?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have multiple ACS servers, can you access the Failure log again and verify which ACS Instance is authenticating the ASA request? If it is a different ACS instance can you check the AD status on that one as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will dig further on another options and I will be waiting for your response as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jan 2012 18:35:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-fails-for-one-of-our-network-device/m-p/1863740#M227420</guid>
      <dc:creator>camejia</dc:creator>
      <dc:date>2012-01-06T18:35:15Z</dc:date>
    </item>
    <item>
      <title>TACACS authentication fails for one of our network device</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-fails-for-one-of-our-network-device/m-p/1863741#M227421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have Distributed deployment, and i found one of the Secondary instance is not connecting to domain. It giving following message " connection test to domain failed&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - clock skew error.&amp;nbsp; "&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jan 2012 19:09:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-fails-for-one-of-our-network-device/m-p/1863741#M227421</guid>
      <dc:creator>Santosh Shetty</dc:creator>
      <dc:date>2012-01-06T19:09:53Z</dc:date>
    </item>
    <item>
      <title>TACACS authentication fails for one of our network device</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-fails-for-one-of-our-network-device/m-p/1863742#M227424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's what I suspected. You will have to deregister the secondary ACS from the Primary. Configure the appropriate Secondary ACS clock and timezone to match the AD Domain Controllers time. Both the clock change and the timezone change will restart the secondary ACS services for the changes to take effect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After the appropriate time has been configured we should "Test Connection" against AD from the ACS GUI on the secondary. As soon as it succeds we can proceed and save changes and also register the secondary back to the primary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should address the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jan 2012 19:26:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-fails-for-one-of-our-network-device/m-p/1863742#M227424</guid>
      <dc:creator>camejia</dc:creator>
      <dc:date>2012-01-06T19:26:08Z</dc:date>
    </item>
    <item>
      <title>TACACS authentication fails for one of our network device</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-fails-for-one-of-our-network-device/m-p/1863743#M227428</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&amp;nbsp; Carlos,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help, everything working finally.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jan 2012 05:47:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-fails-for-one-of-our-network-device/m-p/1863743#M227428</guid>
      <dc:creator>Santosh Shetty</dc:creator>
      <dc:date>2012-01-09T05:47:17Z</dc:date>
    </item>
  </channel>
</rss>

