<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ACS can't find/authenticate internal user on 3550 switch in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-acs-can-t-find-authenticate-internal-user-on-3550-switch/m-p/1881610#M245856</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In ACS try sending following attributes as part of authorization for uses who can telnet/ssh to the router/switch.&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: Arial;"&gt;cisco-avpair = "shell:priv-lvl=15"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 01 May 2012 10:36:04 GMT</pubDate>
    <dc:creator>shoaibkhan</dc:creator>
    <dc:date>2012-05-01T10:36:04Z</dc:date>
    <item>
      <title>Cisco ACS can't find/authenticate internal user on 3550 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-can-t-find-authenticate-internal-user-on-3550-switch/m-p/1881609#M245838</link>
      <description>&lt;P&gt;I'm doing some testing with ACS server on my windows box and I can't seem to get a barebone radius authentication to work with ACS internal users. I tested the same configuration with TACACS and it works fine, so there's something missing or misconfigured in my setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a cisco 3550 switch that I want users to login using their ACS username/password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SW1&lt;/P&gt;&lt;P&gt;username cisco password 0 cisco&lt;/P&gt;&lt;P&gt;username admin password 0 admin&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group radius local&lt;/P&gt;&lt;P&gt;aaa authorization exec default group radius local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;radius-server host 172.16.1.115 auth-port 1645 acct-port 1646 key password&lt;/P&gt;&lt;P&gt;radius-server source-ports 1645-1646&lt;/P&gt;&lt;P&gt;radius-server key password&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Eventually it uses my local username/password in which I'm able to get in, but not sure why it says it can't find the user account.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the debugs from my Cisco switch and attached are the screenshots of my ACS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User Access Verification&lt;/P&gt;&lt;P&gt;Username: &lt;BR /&gt;2d18h: AAA: parse name=tty0 idb type=-1 tty=-1&lt;BR /&gt;2d18h: AAA: name=tty0 flags=0x11 type=4 shelf=0 slot=0 adapter=0 port=0 channel=0&lt;BR /&gt;2d18h: AAA/MEMORY: create_user (0x17478B0) user='NULL' ruser='NULL' ds0=0 port='tty0' rem_addr='async' authen_type=ASCII service=LOGIN priv=1 initial_task_id='0', vrf= (id=0)&lt;BR /&gt;2d18h: AAA/AUTHEN/START (1772888944): port='tty0' list='' action=LOGIN service=LOGIN&lt;BR /&gt;2d18h: AAA/AUTHEN/START (1772888944): using "default" list&lt;BR /&gt;2d18h: AAA/AUTHEN/START (1772888944): Method=radius (rad&lt;BR /&gt;Username: userius)&lt;BR /&gt;2d18h: AAA/AUTHEN (1772888944): status = GETUSER&lt;BR /&gt;Username: user2&lt;BR /&gt;Password: &lt;BR /&gt;2d18h: AAA/AUTHEN/CONT (1772888944): continue_login (user='(undef)')&lt;BR /&gt;2d18h: AAA/AUTHEN (1772888944): status = GETUSER&lt;BR /&gt;2d18h: AAA/AUTHEN (1772888944): Method=radius (radius)&lt;BR /&gt;2d18h: AAA/AUTHEN (1772888944): status = GETPASS&lt;/P&gt;&lt;P&gt;2d18h: AAA/AUTHEN/CONT (1772888944): continue_login (user='user2')&lt;BR /&gt;2d18h: AAA/AUTHEN (1772888944): status = GETPASS&lt;BR /&gt;2d18h: AAA/AUTHEN (1772888944): Method=radius (radius)&lt;BR /&gt;% Authentication failed.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 00:40:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-can-t-find-authenticate-internal-user-on-3550-switch/m-p/1881609#M245838</guid>
      <dc:creator>ejeangilles</dc:creator>
      <dc:date>2019-03-13T00:40:43Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS can't find/authenticate internal user on 3550 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-can-t-find-authenticate-internal-user-on-3550-switch/m-p/1881610#M245856</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In ACS try sending following attributes as part of authorization for uses who can telnet/ssh to the router/switch.&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: Arial;"&gt;cisco-avpair = "shell:priv-lvl=15"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 May 2012 10:36:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-can-t-find-authenticate-internal-user-on-3550-switch/m-p/1881610#M245856</guid>
      <dc:creator>shoaibkhan</dc:creator>
      <dc:date>2012-05-01T10:36:04Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS can't find/authenticate internal user on 3550 switch</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-can-t-find-authenticate-internal-user-on-3550-switch/m-p/1881611#M245888</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is that a command that I have to run. I'm using the ACS that runs on my Windows 2003 server. Not sure where that is in the GUI&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 May 2012 12:44:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-can-t-find-authenticate-internal-user-on-3550-switch/m-p/1881611#M245888</guid>
      <dc:creator>ejeangilles</dc:creator>
      <dc:date>2012-05-01T12:44:52Z</dc:date>
    </item>
  </channel>
</rss>

