<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic NCS TACACS+ with ACS 4.2 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ncs-tacacs-with-acs-4-2/m-p/1732417#M241871</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found the solution, I forgot this line:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;gt; virtual-domain0=ROOT-DOMAIN&lt;/P&gt;&lt;P&gt;role0=Admin&lt;/P&gt;&lt;P&gt;task0=View Alerts and Events&lt;/P&gt;&lt;P&gt;task1=Device Reports&lt;/P&gt;&lt;P&gt;task2=RADIUS Servers&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dominic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 17 Sep 2011 12:17:13 GMT</pubDate>
    <dc:creator>Dominic Stalder (old profile)</dc:creator>
    <dc:date>2011-09-17T12:17:13Z</dc:date>
    <item>
      <title>NCS TACACS+ with ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/ncs-tacacs-with-acs-4-2/m-p/1732416#M241870</link>
      <description>&lt;P&gt;Hi there&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to configure TACACS+ authentication / authorization for NCS via ACS 4.2. For that I followed the configuration guide:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Configured the service for NCS with HTTP (see attachment)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Added the tasks to the user (see attachment)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I try to login on the NCS it fails, in the logs on the NCS I see the following lines:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;09/14/11 16:53:03.333 TRACE [system] [http-443-7] [TACACS+ AAAModule] Creating authorization socket&amp;nbsp;&amp;nbsp; - To Server:&amp;nbsp; 192.168.49.14&amp;nbsp; - For User:&amp;nbsp; netadmin &lt;/P&gt;&lt;P&gt;09/14/11 16:53:03.335 TRACE [system] [http-443-7] [TACACS+ AAAModule] Sending authorization request packet&amp;nbsp; - To Server:&amp;nbsp; 192.168.49.14&amp;nbsp; - For User:&amp;nbsp; netadmin &lt;/P&gt;&lt;P&gt;09/14/11 16:53:03.336 TRACE [system] [http-443-7] [TACACS+ AAAModule] Receiving authorization response packet&amp;nbsp; - From Server:&amp;nbsp; 192.168.49.14&amp;nbsp; - For User:&amp;nbsp; netadmin &lt;/P&gt;&lt;P&gt;09/14/11 16:53:03.343 TRACE [system] [http-443-7] [TACACS+ AAAModule] Retrieving authorization info from packet&amp;nbsp; - From Server:&amp;nbsp; 192.168.49.14&amp;nbsp; - For User:&amp;nbsp; netadmin &lt;/P&gt;&lt;P&gt;09/14/11 16:53:03.343 TRACE [system] [http-443-7] [TACACS+ AAAModule] Processing Cisco vendor custom attributes:&amp;nbsp; &lt;/P&gt;&lt;P&gt;(...)&lt;/P&gt;&lt;P&gt;09/14/11 16:53:03.406 TRACE [system] [http-443-7] [TACACS+ AAAModule] adding role: role0 = Admin &lt;/P&gt;&lt;P&gt;09/14/11 16:53:03.407 TRACE [system] [http-443-7] [TACACS+ AAAModule] Disconnecting from authorization socket&amp;nbsp; - From Server:&amp;nbsp; 192.168.49.14&amp;nbsp; - For User:&amp;nbsp; netadmin &lt;/P&gt;&lt;P&gt;09/14/11 16:53:03.431 TRACE [admin] [http-443-7] entry with (NCS)&lt;/P&gt;&lt;P&gt;09/14/11 16:53:03.432 TRACE [admin] [http-443-7] exit with (false)&lt;/P&gt;&lt;P&gt;09/14/11 16:53:03.432 TRACE [admin] [http-443-7] entry with (Demo)&lt;/P&gt;&lt;P&gt;09/14/11 16:53:03.432 TRACE [admin] [http-443-7] exit with (true)&lt;/P&gt;&lt;P&gt;09/14/11 16:53:03.715 TRACE [admin] [http-443-7] entry with (NCS)&lt;/P&gt;&lt;P&gt;09/14/11 16:53:03.715 TRACE [admin] [http-443-7] exit with (false)&lt;/P&gt;&lt;P&gt;09/14/11 16:53:03.715 TRACE [admin] [http-443-7] entry with (Demo)&lt;/P&gt;&lt;P&gt;09/14/11 16:53:03.716 TRACE [admin] [http-443-7] exit with (true)&lt;/P&gt;&lt;P&gt;09/14/11 16:53:03.722 TRACE [admin] [http-443-7] entry with (NCS)&lt;/P&gt;&lt;P&gt;09/14/11 16:53:03.722 TRACE [admin] [http-443-7] exit with (false)&lt;/P&gt;&lt;P&gt;09/14/11 16:53:03.723 TRACE [admin] [http-443-7] entry with (Demo)&lt;/P&gt;&lt;P&gt;09/14/11 16:53:03.723 TRACE [admin] [http-443-7] exit with (true)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;631531: loopback: Sep 14 2011 16:53:03.088 +0200: %XMP-7-DEBUG: %[ch=com.cisco.xmp.usermgmt][mid=10015]: [The query is :select p from XmpUser p where p.username='netadmin' and policyPartition = 'root']&lt;/P&gt;&lt;P&gt;631532: loopback: Sep 14 2011 16:53:03.088 +0200: %XMP-7-DEBUG: %[ch=com.cisco.xmp.usermgmt][mid=10015]: [getDmm invoked]&lt;/P&gt;&lt;P&gt;631533: loopback: Sep 14 2011 16:53:03.088 +0200: %XMP-7-METHOD_ENTRY_MESSAGE: %[ch=com.cisco.xmp.usermgmt][mid=10011]: Thread Id : [204], Entering Method : [executeDmmQuery], Class : [XmpUserMgmtDmmHelper].&lt;/P&gt;&lt;P&gt;631534: loopback: Sep 14 2011 16:53:03.088 +0200: %XMP-7-METHOD_EXIT_MESSAGE: %[ch=com.cisco.xmp.usermgmt][mid=10012]: Thread Id : [204], Exiting Method : [executeDmmQuery], Class : [XmpUserMgmtDmmHelper].&lt;/P&gt;&lt;P&gt;631535: loopback: Sep 14 2011 16:53:03.088 +0200: %XMP-7-USER0206: %[ch=com.cisco.xmp.usermgmt][mid=206]: Cannot find user: [netadmin]&lt;/P&gt;&lt;P&gt;631536: loopback: Sep 14 2011 16:53:03.089 +0200: %XMP-7-DEBUG: %[ch=com.cisco.xmp.usermgmt][mid=10015]: [userNotFound=true]&lt;/P&gt;&lt;P&gt;631537: loopback: Sep 14 2011 16:53:03.089 +0200: %XMP-7-DEBUG: %[ch=com.cisco.xmp.usermgmt][mid=10015]: [No Fallback Related Exception. Hence falling back to next provider]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anybody know what is wrong with my configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot in advance and best regards&lt;/P&gt;&lt;P&gt;Dominic&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:24:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ncs-tacacs-with-acs-4-2/m-p/1732416#M241870</guid>
      <dc:creator>Dominic Stalder (old profile)</dc:creator>
      <dc:date>2019-03-11T01:24:13Z</dc:date>
    </item>
    <item>
      <title>NCS TACACS+ with ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/ncs-tacacs-with-acs-4-2/m-p/1732417#M241871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found the solution, I forgot this line:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;gt; virtual-domain0=ROOT-DOMAIN&lt;/P&gt;&lt;P&gt;role0=Admin&lt;/P&gt;&lt;P&gt;task0=View Alerts and Events&lt;/P&gt;&lt;P&gt;task1=Device Reports&lt;/P&gt;&lt;P&gt;task2=RADIUS Servers&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dominic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Sep 2011 12:17:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ncs-tacacs-with-acs-4-2/m-p/1732417#M241871</guid>
      <dc:creator>Dominic Stalder (old profile)</dc:creator>
      <dc:date>2011-09-17T12:17:13Z</dc:date>
    </item>
    <item>
      <title>NCS TACACS+ with ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/ncs-tacacs-with-acs-4-2/m-p/1732418#M241872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dominic,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having the same issue, I'm trying to configure ACS with NCS but no luck. What configuration guide are you using?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any help will be greatly appreciated.-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2012 00:34:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ncs-tacacs-with-acs-4-2/m-p/1732418#M241872</guid>
      <dc:creator>esomarriba</dc:creator>
      <dc:date>2012-03-20T00:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: NCS TACACS+ with ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/ncs-tacacs-with-acs-4-2/m-p/1732419#M241873</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Esomarriba&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here you can see my working configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. You need to configure the new NCS service under the Interface Configuration &amp;gt; TACACS+ (as for WCS too):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/1/4/5/81541-Interface_Config.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. You need to configure the NCS attributes under the Group or User Configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/9/6/5/81569-User_Config.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;The important line is the first one "virtual-domain0=ROOT-DOMAIN", I did forgot this first but now it is working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps you to solve your problem, otherwise just ask. Do not forget to rate the answers &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Dominic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Mar 2012 08:52:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ncs-tacacs-with-acs-4-2/m-p/1732419#M241873</guid>
      <dc:creator>Dominic Stalder (old profile)</dc:creator>
      <dc:date>2012-03-20T08:52:36Z</dc:date>
    </item>
    <item>
      <title>NCS TACACS+ with ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/ncs-tacacs-with-acs-4-2/m-p/1732420#M241874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks, I was having the same issue and was having a hard time finding the solution!&amp;nbsp; This fixed it!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jun 2012 14:37:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ncs-tacacs-with-acs-4-2/m-p/1732420#M241874</guid>
      <dc:creator>trumpg</dc:creator>
      <dc:date>2012-06-19T14:37:42Z</dc:date>
    </item>
    <item>
      <title>NCS TACACS+ with ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/ncs-tacacs-with-acs-4-2/m-p/1732421#M241875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am trying to following the solution, but i was rejected by AD, i am getting &lt;/P&gt;&lt;H2 style="background-color: #ffffff; border-collapse: collapse; font-size: 2em; list-style: none; margin: 0px 100px 0px 0px; font-weight: normal; width: auto; font-family: Arial, verdana, sans-serif;"&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/message/3821878#3821878" style="border-collapse: collapse; font-size: 27px; list-style: none; outline: none; color: #ee6804; width: auto;"&gt;ACS error : External DB user invalid or bad password&lt;/A&gt; in acs 4.2. &lt;/H2&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in my ncs prime: i m getting the following error.&lt;/P&gt;&lt;P&gt;257777: loopback: Feb 06 2013 13:02:43.279 +0800: %XMP-7-DEBUG: %[ch=com.cisco.xmp.usermgmt][mid=10015]: [The&lt;/P&gt;&lt;P&gt; query is :select p from XmpUser p where p.username='s102069' and policyPartition = 'root']&lt;/P&gt;&lt;P&gt;257781: loopback: Feb 06 2013 13:02:43.280 +0800: %XMP-7-USER0206: %[ch=com.cisco.xmp.usermgmt][mid=206]: Can&lt;/P&gt;&lt;P&gt;not find user: [s102069]&lt;/P&gt;&lt;P&gt;257793: loopback: Feb 06 2013 13:02:43.332 +0800: %XMP-7-DEBUG: %[ch=com.cisco.xmp.usermgmt][mid=10015]: [&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [TacacsLoginModule] Attemp to authenticate user: s102069]&lt;/P&gt;&lt;P&gt;257796: loopback: Feb 06 2013 13:02:43.333 +0800: %XMP-7-DEBUG: %[ch=com.cisco.xmp.usermgmt][mid=10015]: [&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [TacacsLoginModule] user entered username: s102069]&lt;/P&gt;&lt;P&gt;258117: loopback: Feb 06 2013 13:02:43.458 +0800: %XMP-7-USER0206: %[ch=com.cisco.xmp.usermgmt][mid=206]: Can&lt;/P&gt;&lt;P&gt;not find user: [s102069]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the user id and password was able to login to WCS &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Feb 2013 06:58:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ncs-tacacs-with-acs-4-2/m-p/1732421#M241875</guid>
      <dc:creator>Xiao Yi Steven FAN</dc:creator>
      <dc:date>2013-02-06T06:58:42Z</dc:date>
    </item>
    <item>
      <title>NCS TACACS+ with ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/ncs-tacacs-with-acs-4-2/m-p/1732422#M241876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This steps also works on Cisco Prime Infrastructure, or &lt;SPAN style="font-size: 10pt;"&gt;necessarily need a cisco acs 5.x???&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Mar 2013 21:50:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ncs-tacacs-with-acs-4-2/m-p/1732422#M241876</guid>
      <dc:creator>Luis Garcia</dc:creator>
      <dc:date>2013-03-13T21:50:42Z</dc:date>
    </item>
    <item>
      <title>NCS TACACS+ with ACS 4.2</title>
      <link>https://community.cisco.com/t5/network-access-control/ncs-tacacs-with-acs-4-2/m-p/1732423#M241877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;with ACS 4 it should work as well&amp;nbsp; &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Mar 2013 19:08:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ncs-tacacs-with-acs-4-2/m-p/1732423#M241877</guid>
      <dc:creator>maldehne</dc:creator>
      <dc:date>2013-03-15T19:08:20Z</dc:date>
    </item>
  </channel>
</rss>

