<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic authentication failed - in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authentication-failed/m-p/1569546#M254395</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm using tacacs(ACS 4.2) server and trying to login with my tacacs credentials but got a msg:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;authorization failed.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pls advise wht could be the issue and how to resolve it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 00:32:39 GMT</pubDate>
    <dc:creator>gavin han</dc:creator>
    <dc:date>2019-03-11T00:32:39Z</dc:date>
    <item>
      <title>authentication failed -</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-failed/m-p/1569546#M254395</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm using tacacs(ACS 4.2) server and trying to login with my tacacs credentials but got a msg:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;authorization failed.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pls advise wht could be the issue and how to resolve it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:32:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-failed/m-p/1569546#M254395</guid>
      <dc:creator>gavin han</dc:creator>
      <dc:date>2019-03-11T00:32:39Z</dc:date>
    </item>
    <item>
      <title>Re: authentication failed -</title>
      <link>https://community.cisco.com/t5/network-access-control/authentication-failed/m-p/1569547#M254435</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gavin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you are getting authorization failed messgae which means your authentication is passing. It depend which protocol you are using radius/tacacs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please try this sample config and see if authorization works or not. If still same issue, check what is the authorization failure logs your ACS is showing:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a sample configuration:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;router(config)# enable password XXXXXXX &lt;/P&gt;&lt;P&gt;router(config)# username admin privilege 15 password xxxxx &lt;/P&gt;&lt;P&gt;router(config)# aaa new-model (Enables AAA configuration commands on the router)&lt;/P&gt;&lt;P&gt;router(config)# Tacacs-server host XXXXXXX ( IP address of the ACS server) &lt;/P&gt;&lt;P&gt;router(config)# Tacacs-server key XXXXXX ( This is the same shared secret key which we defined on the ACS for this IOS device) &lt;/P&gt;&lt;P&gt;router(config)# aaa authentication login default group Tacacs+ local &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authenticate telnet users on TACACS+ if TACACS+ is down authenticate users with locally configured telnet username password on router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;router(config)# aaa authentication enable default group Tacacs+ enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authenticate the enable password on the TACACS+ if TACACS+ is down authenticate enable password with locally configured enable password on router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router(config)# aaa accounting exec default start-stop group TACACS+ (Account all the user which are telneting based on start and stop session on TACACS+)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router(config)# line vty 04 (Change to line vty line)&lt;/P&gt;&lt;P&gt;Router(config-line)# Login authentication default (Enables tacacs authentication for the vty lines)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Nov 2010 15:08:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authentication-failed/m-p/1569547#M254435</guid>
      <dc:creator>Vinay Sharma</dc:creator>
      <dc:date>2010-11-02T15:08:25Z</dc:date>
    </item>
  </channel>
</rss>

