<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Nexus Allows TACACS and Local Authentication Concurrently in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/nexus-allows-tacacs-and-local-authentication-concurrently/m-p/1674218#M233062</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Tarik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The folks in the lab were able to duplicate the problem.&amp;nbsp; Since we would rather provide Cisco logging info from the lab and not the production environment, they are going to open a TAC case on my behalf.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once a solution is provided, I will update this forum post for the benefit of the community.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Erik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 08 Jun 2011 06:17:04 GMT</pubDate>
    <dc:creator>efairbanks</dc:creator>
    <dc:date>2011-06-08T06:17:04Z</dc:date>
    <item>
      <title>Nexus Allows TACACS and Local Authentication Concurrently</title>
      <link>https://community.cisco.com/t5/network-access-control/nexus-allows-tacacs-and-local-authentication-concurrently/m-p/1674216#M233058</link>
      <description>&lt;P&gt;Community,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am experiencing an issue where NX-OS on our 5010s is allowing both Local AND TACACS authentication concurrently.&amp;nbsp; If I don't configure any aaa authorization commands, the locally logged in user has unmitigated access to the device.&amp;nbsp; Once I enable aaa authroization, all commands issued by the locally logged in user are denied by ACS, but they can still log in to the device.&amp;nbsp; When I comb through the logs on the ACS server, I see successful logins when TACACS credentials are used, and also the failed attempts when the locally configured credentials are used.&amp;nbsp; On the switch, however, I receive "%TACACS-3-TACACS_ERROR_MESSAGE:&amp;nbsp; All servers failed to respond" when using locally configured credentials on the switch itself.&amp;nbsp; We are running ACS v4.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See attachment for configuration information from the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for any assistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Erik&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:08:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nexus-allows-tacacs-and-local-authentication-concurrently/m-p/1674216#M233058</guid>
      <dc:creator>efairbanks</dc:creator>
      <dc:date>2019-03-11T01:08:34Z</dc:date>
    </item>
    <item>
      <title>Nexus Allows TACACS and Local Authentication Concurrently</title>
      <link>https://community.cisco.com/t5/network-access-control/nexus-allows-tacacs-and-local-authentication-concurrently/m-p/1674217#M233060</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I wanted to know what the reason for the failed attempts are in the acs logs? If you can set the logging to full and then search for the username in the TCS.logs after you repro the issue and then download the support bundle. This will show you if ACS is failing the user or if ACS is returning error messages to the Nexus thus failing over to local authentication. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keep in mind when setting the logging to full and downloading the package.cab file will restart the services on the box. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jun 2011 07:45:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nexus-allows-tacacs-and-local-authentication-concurrently/m-p/1674217#M233060</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2011-06-07T07:45:56Z</dc:date>
    </item>
    <item>
      <title>Nexus Allows TACACS and Local Authentication Concurrently</title>
      <link>https://community.cisco.com/t5/network-access-control/nexus-allows-tacacs-and-local-authentication-concurrently/m-p/1674218#M233062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Tarik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The folks in the lab were able to duplicate the problem.&amp;nbsp; Since we would rather provide Cisco logging info from the lab and not the production environment, they are going to open a TAC case on my behalf.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once a solution is provided, I will update this forum post for the benefit of the community.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Erik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jun 2011 06:17:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nexus-allows-tacacs-and-local-authentication-concurrently/m-p/1674218#M233062</guid>
      <dc:creator>efairbanks</dc:creator>
      <dc:date>2011-06-08T06:17:04Z</dc:date>
    </item>
    <item>
      <title>Nexus Allows TACACS and Local Authentication Concurrently</title>
      <link>https://community.cisco.com/t5/network-access-control/nexus-allows-tacacs-and-local-authentication-concurrently/m-p/1674219#M233064</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Erik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am experiencing the same problem on my Nexus 5548 and 7010 switches.&amp;nbsp; Have you made any progress on your case with TAC?&amp;nbsp; I would be most interested to find out more.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Sep 2011 20:38:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nexus-allows-tacacs-and-local-authentication-concurrently/m-p/1674219#M233064</guid>
      <dc:creator>John Galietta</dc:creator>
      <dc:date>2011-09-12T20:38:35Z</dc:date>
    </item>
    <item>
      <title>Nexus Allows TACACS and Local Authentication Concurrently</title>
      <link>https://community.cisco.com/t5/network-access-control/nexus-allows-tacacs-and-local-authentication-concurrently/m-p/1674220#M233065</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Erik-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I encountered the same issue.&amp;nbsp; Any update from TAC on what the issue was?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Nathan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Oct 2011 20:14:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nexus-allows-tacacs-and-local-authentication-concurrently/m-p/1674220#M233065</guid>
      <dc:creator>Nathan Eger</dc:creator>
      <dc:date>2011-10-05T20:14:05Z</dc:date>
    </item>
    <item>
      <title>Nexus Allows TACACS and Local Authentication Concurrently</title>
      <link>https://community.cisco.com/t5/network-access-control/nexus-allows-tacacs-and-local-authentication-concurrently/m-p/1674221#M233066</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Erik.&lt;/P&gt;&lt;P&gt;I encountered the same issue. Any update from TAC?&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Andrea&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Nov 2011 10:35:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nexus-allows-tacacs-and-local-authentication-concurrently/m-p/1674221#M233066</guid>
      <dc:creator>andrea.meconi</dc:creator>
      <dc:date>2011-11-15T10:35:23Z</dc:date>
    </item>
    <item>
      <title>Nexus Allows TACACS and Local Authentication Concurrently</title>
      <link>https://community.cisco.com/t5/network-access-control/nexus-allows-tacacs-and-local-authentication-concurrently/m-p/1674222#M233067</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes...sorry....I did get this working.&amp;nbsp; If you configure the AAA authentication line with the tacacs option, but omit the "local" parameter, you will achieve your desired results - localmauthentican will work only if tactics fails.&amp;nbsp; Not sure if this is a bug or a code difficiency...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Nov 2011 10:42:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/nexus-allows-tacacs-and-local-authentication-concurrently/m-p/1674222#M233067</guid>
      <dc:creator>efairbanks</dc:creator>
      <dc:date>2011-11-15T10:42:32Z</dc:date>
    </item>
  </channel>
</rss>

