<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA issue - No authoritative response from any server. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-issue-no-authoritative-response-from-any-server/m-p/1569683#M254400</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having issue with tacacs server(ACS 4.2), did the following test from the router:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router1#test aaa group tacacs+ cisco cisco legacy&lt;BR /&gt;Attempting authentication test to server-group tacacs+ using tacacs+&lt;BR /&gt;No authoritative response from any server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can ping the ACS server from this router though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pls advise how do what could be the issue and how do i resolve it..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks...&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 00:32:37 GMT</pubDate>
    <dc:creator>gavin han</dc:creator>
    <dc:date>2019-03-11T00:32:37Z</dc:date>
    <item>
      <title>AAA issue - No authoritative response from any server.</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-issue-no-authoritative-response-from-any-server/m-p/1569683#M254400</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having issue with tacacs server(ACS 4.2), did the following test from the router:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router1#test aaa group tacacs+ cisco cisco legacy&lt;BR /&gt;Attempting authentication test to server-group tacacs+ using tacacs+&lt;BR /&gt;No authoritative response from any server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can ping the ACS server from this router though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pls advise how do what could be the issue and how do i resolve it..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks...&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:32:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-issue-no-authoritative-response-from-any-server/m-p/1569683#M254400</guid>
      <dc:creator>gavin han</dc:creator>
      <dc:date>2019-03-11T00:32:37Z</dc:date>
    </item>
    <item>
      <title>Re: AAA issue - No authoritative response from any server.</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-issue-no-authoritative-response-from-any-server/m-p/1569684#M254425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check your router config - AAA part. Most probably you mistype TACACS+ server address or something like that...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers, Iron&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question&amp;nbsp; as "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Nov 2010 14:16:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-issue-no-authoritative-response-from-any-server/m-p/1569684#M254425</guid>
      <dc:creator>iilyinas</dc:creator>
      <dc:date>2010-11-02T14:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: AAA issue - No authoritative response from any server.</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-issue-no-authoritative-response-from-any-server/m-p/1569685#M254503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config. looks good to me, I also verified the config of this router with another router (for which tacacs works fine) their config. are same, no difference &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Nov 2010 14:44:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-issue-no-authoritative-response-from-any-server/m-p/1569685#M254503</guid>
      <dc:creator>gavin han</dc:creator>
      <dc:date>2010-11-02T14:44:21Z</dc:date>
    </item>
    <item>
      <title>Re: AAA issue - No authoritative response from any server.</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-issue-no-authoritative-response-from-any-server/m-p/1569686#M254569</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gavin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you capture the following debugs while you try to authentication:-&lt;/P&gt;&lt;P&gt;1. debug aaa authentication&lt;/P&gt;&lt;P&gt;2. debug tacacs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also do you see any hits on the ACS server when you try to authenticate?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please try this sample config:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a sample configuration:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;router(config)# enable password XXXXXXX &lt;/P&gt;&lt;P&gt;router(config)# username admin privilege 15 password xxxxx &lt;/P&gt;&lt;P&gt;router(config)# aaa new-model (Enables AAA configuration commands on the router)&lt;/P&gt;&lt;P&gt;router(config)# Tacacs-server host XXXXXXX ( IP address of the ACS server) &lt;/P&gt;&lt;P&gt;router(config)# Tacacs-server key XXXXXX ( This is the same shared secret key which we defined on the ACS for this IOS device) &lt;/P&gt;&lt;P&gt;router(config)# aaa authentication login default group Tacacs+ local &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authenticate telnet users on TACACS+ if TACACS+ is down authenticate users with locally configured telnet username password on router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;router(config)# aaa authentication enable default group Tacacs+ enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authenticate the enable password on the TACACS+ if TACACS+ is down authenticate enable password with locally configured enable password on router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router(config)# aaa accounting exec default start-stop group TACACS+ (Account all the user which are telneting based on start and stop session on TACACS+)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router(config)# line vty 04 (Change to line vty line)&lt;/P&gt;&lt;P&gt;Router(config-line)# Login authentication default (Enables tacacs authentication for the vty lines)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Vinay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Nov 2010 14:56:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-issue-no-authoritative-response-from-any-server/m-p/1569686#M254569</guid>
      <dc:creator>Vinay Sharma</dc:creator>
      <dc:date>2010-11-02T14:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: AAA issue - No authoritative response from any server.</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-issue-no-authoritative-response-from-any-server/m-p/1569687#M254610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;nbsp; You named your server group&amp;nbsp; tacacs+ ? just do a show run | in aaa&amp;nbsp; and verify.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ce message a été modifié par: cadetalain&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Nov 2010 09:52:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-issue-no-authoritative-response-from-any-server/m-p/1569687#M254610</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2010-11-03T09:52:47Z</dc:date>
    </item>
    <item>
      <title>AAA issue - No authoritative response from any server.</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-issue-no-authoritative-response-from-any-server/m-p/1569688#M254670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey man i was having this same problem firstly for my RADIUS server then for TACACS+ server.&lt;/P&gt;&lt;P&gt;i solved it, please go and check in network configuration of your ACS admin page in your AAA Client that what ip have you give for you required client router.&lt;/P&gt;&lt;P&gt;IMAGIN you have a Router R1 and R2 connected via fastetherne/ serial connectivity or via an ISP technology and your ACS server is on your R1.&lt;/P&gt;&lt;P&gt;in your ACS admin page you make an entry for client R1 with the ip address which is given on your R1 interface which connects your ACS server machine to your R1 ((eg:- ACS ip address 10.10.10.10 and gateway 10.10.10.1 and this machine is connected with you f1/0 this shows you have entered ip add 10.10.10.1 on your f1/0 so this port connects your ACS sv to R1.)). this will solve this NO AUTHORITIVE RESPONSE problem on just your R1 now R2 will have the same problem. &lt;/P&gt;&lt;P&gt;R1 is connected via fast/serial port to R2 (R1 11.0.0.1&amp;nbsp;&amp;nbsp; R2 11.0.0.2). Then in your ACS add entry for R2 with ip address of 11.0.0.2 because this port connects your R2 with R1, or if you are using a GRE tunnel between this R1 and R2 (R1 11.0.0.1&amp;nbsp;&amp;nbsp; R2 11.0.0.2 and&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Tunnel R1 to R2 ip as Tunnel R1 port 12.0.0.1&amp;nbsp;&amp;nbsp; tunnel R2 port 12.0.0.2)&amp;nbsp; then do not enter ip given on your physical port, enter ip address given on you tunnel interface which connects your R1 to R2 &lt;/P&gt;&lt;P&gt;means12.0.0.2. I did this little bit on only my ACS server page it solved my problem. hope you are having the same . if yes then tell us if no then also tell us may be some another can help you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Saqib.&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/9/8/9/106989-Topology.png" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 07 Oct 2012 23:06:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-issue-no-authoritative-response-from-any-server/m-p/1569688#M254670</guid>
      <dc:creator>saqib zafar</dc:creator>
      <dc:date>2012-10-07T23:06:42Z</dc:date>
    </item>
    <item>
      <title>AAA issue - No authoritative response from any server.</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-issue-no-authoritative-response-from-any-server/m-p/1569689#M254708</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;well i also had same issue and the issue points out that&lt;/P&gt;&lt;P&gt;1.your tacacs+ server is not reachable so check the connectivity issues.&lt;/P&gt;&lt;P&gt;2.if you could ping tacacs+ server then one thing to check is the command&lt;/P&gt;&lt;P&gt;"tacacs-server host 10.0.0.1 key cisco" which is to be given on router (client of tacacs+ server)&lt;/P&gt;&lt;P&gt;3.check the key configured on acs for tacacs and that configured in the above command in this case the key is "cisco"&lt;/P&gt;&lt;P&gt;4.this could be silly but i did that mistake to add tacacs+ server in ACS which will actually be doing authentication.authorization and accounting so this is really crucial step to look for because i did not configured this i got that error.&lt;/P&gt;&lt;P&gt;5.finally dont forget to add the client i.e the router to the acs server.and one more thing spell tacacs+ properly because even if you type tacas+ the router accepts it but while doing authentication this error appears,&lt;/P&gt;&lt;P&gt;%AAA-3-BADSERVERTYPEERROR: Cannot process authentication server type *invalid_group_handle*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 Nov 2012 18:59:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-issue-no-authoritative-response-from-any-server/m-p/1569689#M254708</guid>
      <dc:creator>manoj k jadhav</dc:creator>
      <dc:date>2012-11-17T18:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: AAA issue - No authoritative response from any server.</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-issue-no-authoritative-response-from-any-server/m-p/4899325#M583298</link>
      <description>&lt;P&gt;The first thing you have to validate is that you have a ping to the ACS, then validate that the requests reach the ACS, if the requests do not reach the ACS, you should put the following line (ip tacacs source-interface XXX/XXX) and you can test it using the command (test aaa group tacacs+ user password legacy). You should get the following (Attempting authentication test to server-group tacacs+ using tacacs+&lt;BR /&gt;User was successfully authenticated.)&lt;/P&gt;</description>
      <pubDate>Sat, 05 Aug 2023 14:55:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-issue-no-authoritative-response-from-any-server/m-p/4899325#M583298</guid>
      <dc:creator>oscarcastillo2004</dc:creator>
      <dc:date>2023-08-05T14:55:37Z</dc:date>
    </item>
  </channel>
</rss>

