<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS 4.1 Command Authorization Failing Intermitently in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-4-1-command-authorization-failing-intermitently/m-p/1550414#M274318</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have setup aaa using tacacs+ on the network switches, however I seems to be getting occassional command authoization error. This is seen when i try to input the command on several ports at once (example interface range giga 1/1-48). If I was to do it on a single port instead, I dont seems to encounter the error. Would this be due to the ACS unable to handle the load? It is only for a single switch executing the command for port ranges.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached a sample of the error for reference:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;switch(config-if-range)#description level 3&lt;BR /&gt;% Authorization failed.&lt;/P&gt;&lt;P&gt;% Command failed on interface range. Aborting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have checked the interface connecting to the ACS and I do not see any error. I am not too sure what may be causing the error. Would it be due to the ACS unable to work nicely with interface range?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 00:37:39 GMT</pubDate>
    <dc:creator>CSCO10675262_2</dc:creator>
    <dc:date>2019-03-11T00:37:39Z</dc:date>
    <item>
      <title>ACS 4.1 Command Authorization Failing Intermitently</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-1-command-authorization-failing-intermitently/m-p/1550414#M274318</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have setup aaa using tacacs+ on the network switches, however I seems to be getting occassional command authoization error. This is seen when i try to input the command on several ports at once (example interface range giga 1/1-48). If I was to do it on a single port instead, I dont seems to encounter the error. Would this be due to the ACS unable to handle the load? It is only for a single switch executing the command for port ranges.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached a sample of the error for reference:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;switch(config-if-range)#description level 3&lt;BR /&gt;% Authorization failed.&lt;/P&gt;&lt;P&gt;% Command failed on interface range. Aborting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have checked the interface connecting to the ACS and I do not see any error. I am not too sure what may be causing the error. Would it be due to the ACS unable to work nicely with interface range?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:37:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-1-command-authorization-failing-intermitently/m-p/1550414#M274318</guid>
      <dc:creator>CSCO10675262_2</dc:creator>
      <dc:date>2019-03-11T00:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 4.1 Command Authorization Failing Intermitently</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-1-command-authorization-failing-intermitently/m-p/1550415#M274322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you trying to perform this command on a stack of 3750's? If so what version of code are you running? If this isnt the case you might want to increase the timeout value for your tacacs-server and then give the same command a shot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how that works!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Dec 2010 05:00:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-1-command-authorization-failing-intermitently/m-p/1550415#M274322</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2010-12-01T05:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 4.1 Command Authorization Failing Intermitently</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-1-command-authorization-failing-intermitently/m-p/1550416#M274329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tarik,&lt;/P&gt;&lt;P&gt;Yes, you are correct that it is a stack of 3750G. The code that is running on the switch is&amp;nbsp; 12.2(53)SE2. Would there be an issue with the code on aaa authorization with acs 4.1?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will also try to increase the tacacs+ timeout to see if it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Dec 2010 06:12:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-1-command-authorization-failing-intermitently/m-p/1550416#M274329</guid>
      <dc:creator>CSCO10675262_2</dc:creator>
      <dc:date>2010-12-01T06:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 4.1 Command Authorization Failing Intermitently</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-1-command-authorization-failing-intermitently/m-p/1550417#M274340</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a bug open for this issue that was found in 12.2(46)SE, and at the moment there is no plans on resolving the issue since it involves some design work in the code to address this issue. The only work around is to remove command authorization, or to see what your limit is on the inteface range command before it starts dropping the requests.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Dec 2010 23:28:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-1-command-authorization-failing-intermitently/m-p/1550417#M274340</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2010-12-01T23:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 4.1 Command Authorization Failing Intermitently</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-1-command-authorization-failing-intermitently/m-p/1550418#M274348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tarik,&lt;/P&gt;&lt;P&gt;Thanks for the information. May I ask&amp;nbsp; what is the bug id for reference?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Dec 2010 09:55:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-1-command-authorization-failing-intermitently/m-p/1550418#M274348</guid>
      <dc:creator>CSCO10675262_2</dc:creator>
      <dc:date>2010-12-10T09:55:28Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 4.1 Command Authorization Failing Intermitently</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-1-command-authorization-failing-intermitently/m-p/1550419#M274355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure here is the link:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=cscti02944"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=cscti02944&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the detail of the bug:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="3" cellspacing="0" width="95%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD class="smallfont"&gt;&lt;SPAN style="font-weight: bold;"&gt;CSCti02944 &lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="smallfont"&gt;&lt;SPAN style="font-weight: bold;"&gt; command authorization using a range of interfaces can cause issues with &lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD class="smallfont"&gt;&lt;STRONG&gt;Symptom&lt;/STRONG&gt;: when you issue a command for a range of ports as per example router(config) interface g1 g14 then issue a group of commands router(config-if) set ip router(config-if) set speed 100 router(config-if) set duplex full router(config-if) set dhcp snoop limit rate router(config-if) no shut router(config-if) bandwidth 1000 router(config-if) default flowcontrol receive&amp;nbsp; then you will see some of the commands as failed authorization the ACS does not show that the command hits it or is refused by it&amp;nbsp; &lt;STRONG&gt;&lt;STRONG&gt;Condition&lt;/STRONG&gt;s&lt;/STRONG&gt;: have the following enabled on a stack and do commands for a range of interfaces.&amp;nbsp; aaa authentication login default group tacacs+ local enable aaa authentication login tacacs+ local enable aaa authentication login console line aaa authentication enable default group tacacs+ enable aaa authorization config-commands aaa authorization exec default group tacacs+ if-authenticated local&amp;nbsp; aaa authorization exec console none&amp;nbsp; aaa authorization commands 0 default group tacacs+ local&amp;nbsp; aaa authorization commands 1 default group tacacs+ local&amp;nbsp; aaa authorization commands 15 default group tacacs+ local&amp;nbsp; aaa authorization commands 15 console none&amp;nbsp; aaa authorization network default group tacacs+&amp;nbsp; aaa accounting update periodic 5 aaa accounting exec default start-stop group tacacs+ aaa accounting commands 0 default start-stop group tacacs+ aaa accounting commands 1 default start-stop group tacacs+ aaa accounting commands 15 default start-stop group tacacs+ aaa accounting network default start-stop group tacacs+ aaa accounting connection default start-stop group tacacs+ aaa accounting system default start-stop group tacacs+&amp;nbsp;&amp;nbsp; Workaround: disable accounting and authorization config-commands&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Dec 2010 03:14:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-1-command-authorization-failing-intermitently/m-p/1550419#M274355</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2010-12-11T03:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 4.1 Command Authorization Failing Intermitently</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-1-command-authorization-failing-intermitently/m-p/1550420#M274359</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the bug id.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Dec 2010 02:34:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-1-command-authorization-failing-intermitently/m-p/1550420#M274359</guid>
      <dc:creator>CSCO10675262_2</dc:creator>
      <dc:date>2010-12-13T02:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 4.1 Command Authorization Failing Intermitently</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-1-command-authorization-failing-intermitently/m-p/1550421#M274362</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is this fixed in a later version of ACS?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Dec 2010 12:10:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-1-command-authorization-failing-intermitently/m-p/1550421#M274362</guid>
      <dc:creator>stevehorsleyNXG</dc:creator>
      <dc:date>2010-12-14T12:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 4.1 Command Authorization Failing Intermitently</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-4-1-command-authorization-failing-intermitently/m-p/1550422#M274368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No this is not an ACS issue, its a limitation on the software that divides up the AAA requests.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Dec 2010 17:19:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-4-1-command-authorization-failing-intermitently/m-p/1550422#M274368</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2010-12-14T17:19:44Z</dc:date>
    </item>
  </channel>
</rss>

