<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA TACACS NEXUS doesn't work in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700988#M294501</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Karim:&lt;/P&gt;&lt;P&gt;let me know how it goes. On our side the Nexus were reloaded to restore AAA.&lt;/P&gt;&lt;P&gt;We are not using LMS until this is fixed. We are trying to fix some paperwork before able to open a TAC Case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It could be simply the LMS version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate if you keep me in the loop. I will also update you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Jun 2011 15:51:16 GMT</pubDate>
    <dc:creator>Ben Alex</dc:creator>
    <dc:date>2011-06-09T15:51:16Z</dc:date>
    <item>
      <title>AAA TACACS NEXUS doesn't work</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700978#M294491</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin:0cm;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.0pt;
	font-family:"Times New Roman";
	mso-ansi-language:#0400;
	mso-fareast-language:#0400;
	mso-bidi-language:#0400;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;P&gt;I m trying to setup a Tacacs config onto my new NEXUS 5000 series&lt;/P&gt;&lt;P&gt;Nevertheless the authentication doesn't work&lt;/P&gt;&lt;P&gt;Actually I followed the config guide but something is not working or missing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have setup everything through VMWARE with ACS installed on a Windows server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is some of my config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My NEXUS Switch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IP 192.168.254.207&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh run | i aaa&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ bporama&lt;/P&gt;&lt;P&gt;aaa authentication login default group bporama&lt;/P&gt;&lt;P&gt;aaa authentication login console local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh run | i tacacs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;feature tacacs&lt;/P&gt;&lt;P&gt;tacacs-server key 7 "XXXXX"&lt;/P&gt;&lt;P&gt;tacacs-server host 192.168.254.245 key 7 "XXXXX"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ping from Switch to the ACS&lt;/P&gt;&lt;P&gt;64 bytes from 192.168.254.245 icmp_seq=0 ttl=127 time=3.609&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;telnet 192.168.254.245 49&lt;/P&gt;&lt;P&gt;connected to 192.168.254.245.&lt;/P&gt;&lt;P&gt;Escape&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Debug %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the user kar has been created on the ACS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so what't wrong?? something is missing??? can you please and advise&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Karim Brussels&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:06:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700978#M294491</guid>
      <dc:creator>karimbruxelles</dc:creator>
      <dc:date>2019-03-11T01:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: AAA TACACS NEXUS doesn't work</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700979#M294492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please confirm if the tacacs servers are in the tacacs group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;command "&lt;SPAN class="content"&gt;&lt;SPAN style="color: black; font-style: normal; font-weight: normal;"&gt; &lt;/SPAN&gt;&lt;STRONG class="cBold"&gt;show tacacs-server&amp;nbsp; groups &lt;/STRONG&gt;&lt;/SPAN&gt;" will help you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please ensure that the configuration is similar as in the guide and also using the correct Vrf.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/switches/datacenter/nexus5000/sw/configuration/guide/cli/sec_tacacsplus.html#wp1272988"&gt;http://www.cisco.com/en/US/docs/switches/datacenter/nexus5000/sw/configuration/guide/cli/sec_tacacsplus.html#wp1272988&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this mail as answered if you feel your query is resolved. Do rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 May 2011 15:58:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700979#M294492</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-05-27T15:58:30Z</dc:date>
    </item>
    <item>
      <title>Re: AAA TACACS NEXUS doesn't work</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700980#M294493</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Anisha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for this but it still doesn't work, we have a couple of IOS switch and all are working fine with Tacacs through ACS&lt;/P&gt;&lt;P&gt;however with Nexus it is another story....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My interface vlan XXX is the mgt interface so why shall I select "use-vrf management under aaa group server tacacs+ Name_of_Group???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get always the same msg error authenticating to server status 7&lt;/P&gt;&lt;P&gt;also into the ACS the logs are telling me then my&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any idea?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Karim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 May 2011 12:31:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700980#M294493</guid>
      <dc:creator>karimbruxelles</dc:creator>
      <dc:date>2011-05-30T12:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: AAA TACACS NEXUS doesn't work</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700981#M294494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nexus works on vrf's and roles. Hence i asked you to define the vrf. by default it is possible that the authentictaion request is exiting via a different vrf and hence not reaching the ACS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you see on the ACS server ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.:please mark this post as answered if you feel your query is resolved. Do rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 May 2011 00:24:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700981#M294494</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-05-31T00:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: AAA TACACS NEXUS doesn't work</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700982#M294495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Karim:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you fix the issue. Please share as I am having the same problem.&lt;/P&gt;&lt;P&gt;Mine is very weird cos it has been working for 4 weeks and suddenly it stopped.&lt;/P&gt;&lt;P&gt;My ACS is pingagle and I am using gthe default vrf.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style=": ; color: #1f497d; font-size: 11pt; sans-serif&amp;quot;: ; font-family: Calibri; , &amp;quot;: ; Calibri&amp;quot;: ; "&gt;2011 Jun&amp;nbsp; 2 11:27:10.592 nx5548-14 %TACACS-3-TACACS_ERROR_MESSAGE: All servers failed to respond&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style=": ; color: #1f497d; font-size: 11pt; sans-serif&amp;quot;: ; font-family: Calibri; , &amp;quot;: ; Calibri&amp;quot;: ; "&gt;2011 Jun&amp;nbsp; 2 11:27:31 nx5548-14 last message repeated 2 times&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style=": ; color: #1f497d; font-size: 11pt; sans-serif&amp;quot;: ; font-family: Calibri; , &amp;quot;: ; Calibri&amp;quot;: ; "&gt;2011 Jun&amp;nbsp; 2 11:27:31 nx5548-14 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user xxx&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style=": ; color: #1f497d; font-size: 11pt; sans-serif&amp;quot;: ; font-family: Calibri; , &amp;quot;: ; Calibri&amp;quot;: ; "&gt;2011 Jun&amp;nbsp; 2 11:28:13.975 nx5548-14 %TACACS-3-TACACS_ERROR_MESSAGE: All servers failed to respond&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style=": ; color: #1f497d; font-size: 11pt; sans-serif&amp;quot;: ; font-family: Calibri; , &amp;quot;: ; Calibri&amp;quot;: ; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jun 2011 15:55:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700982#M294495</guid>
      <dc:creator>Ben Alex</dc:creator>
      <dc:date>2011-06-02T15:55:56Z</dc:date>
    </item>
    <item>
      <title>Re: AAA TACACS NEXUS doesn't work</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700983#M294496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ben,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Two actions did resolve my problem &lt;/P&gt;&lt;P&gt;first of all ip tacacs server was no set on the global config and for unknow reason I had to create a new user id on the ACS it did not work with the previous accounts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I m off but if you wait until Monday I can sent you the all of the config step by step&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;let me know&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Karim&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ps: try the test aaa xxxxx command it is very helpful&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jun 2011 16:07:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700983#M294496</guid>
      <dc:creator>karimbruxelles</dc:creator>
      <dc:date>2011-06-02T16:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: AAA TACACS NEXUS doesn't work</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700984#M294497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I reloaded one of my 4 nexuses without any modifications and it now works. I will not reload the other 3 until I fully understand what is going on.&lt;/P&gt;&lt;P&gt;I don't want this to happen in 4 weeks again since I will go in full production.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sure I can wait till Monay.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jun 2011 18:11:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700984#M294497</guid>
      <dc:creator>Ben Alex</dc:creator>
      <dc:date>2011-06-02T18:11:20Z</dc:date>
    </item>
    <item>
      <title>Re: AAA TACACS NEXUS doesn't work</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700985#M294498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ben, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is my config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;N12-BKP# sh run aaa all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!Command: show running-config aaa all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;version 5.0(3)N1(1c)&lt;/P&gt;&lt;P&gt;aaa authentication login default group bporama&lt;/P&gt;&lt;P&gt;aaa authentication login console local&lt;/P&gt;&lt;P&gt;aaa authorization ssh-publickey default local&lt;/P&gt;&lt;P&gt;aaa authorization ssh-certificate default local&lt;/P&gt;&lt;P&gt;aaa authorization config-commands default local&lt;/P&gt;&lt;P&gt;aaa authorization commands default local&lt;/P&gt;&lt;P&gt;aaa accounting default group bporama&lt;/P&gt;&lt;P&gt;no aaa user default-role&lt;/P&gt;&lt;P&gt;aaa authentication login default fallback error local&lt;/P&gt;&lt;P&gt;aaa authentication login console fallback error local&lt;/P&gt;&lt;P&gt;no aaa authentication login error-enable&lt;/P&gt;&lt;P&gt;no aaa authentication login mschap enable&lt;/P&gt;&lt;P&gt;no aaa authentication login mschapv2 enable&lt;/P&gt;&lt;P&gt;no aaa authentication login chap enable&lt;/P&gt;&lt;P&gt;no aaa authentication login ascii-authentication&lt;/P&gt;&lt;P&gt;no radius-server directed-request&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;N12-BKP# sh run tacacs+ all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!Command: show running-config tacacs+ all&lt;/P&gt;&lt;P&gt;!Time: Mon Jun&amp;nbsp; 6 15:26:32 2011&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;version 5.0(3)N1(1c)&lt;/P&gt;&lt;P&gt;feature tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server key 7 "elsgho"&lt;/P&gt;&lt;P&gt;ip tacacs source-interface Vlan777&lt;/P&gt;&lt;P&gt;tacacs-server test username test password test idle-time 0&lt;/P&gt;&lt;P&gt;tacacs-server timeout 5&lt;/P&gt;&lt;P&gt;tacacs-server deadtime 30&lt;/P&gt;&lt;P&gt;tacacs-server host 192.168.254.245 key 7 "XXXXXX" port 49 timeout 30&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ bporama&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; server 192.168.254.245&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; use-vrf default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; source-interface Vlan777&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jun 2011 13:27:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700985#M294498</guid>
      <dc:creator>karimbruxelles</dc:creator>
      <dc:date>2011-06-06T13:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: AAA TACACS NEXUS doesn't work</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700986#M294499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks.&lt;/P&gt;&lt;P&gt;Guess what.&lt;/P&gt;&lt;P&gt;Ciscoworks LMS is actually the culprit.After reload AAA works back.&lt;/P&gt;&lt;P&gt;And as soon as LMS is trying to discover the nexus, the AAA fails.&lt;/P&gt;&lt;P&gt;LMS is version 3.2&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jun 2011 14:41:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700986#M294499</guid>
      <dc:creator>Ben Alex</dc:creator>
      <dc:date>2011-06-06T14:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: AAA TACACS NEXUS doesn't work</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700987#M294500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Today I had the same issue unable to logon to my nexus through Tacacs and indeed I have got the same LMS version 3.2!!!!&lt;/P&gt;&lt;P&gt;I will reload LMS tonight and check if I can acces my devices&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the info &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Karim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jun 2011 15:15:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700987#M294500</guid>
      <dc:creator>karimbruxelles</dc:creator>
      <dc:date>2011-06-06T15:15:01Z</dc:date>
    </item>
    <item>
      <title>Re: AAA TACACS NEXUS doesn't work</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700988#M294501</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Karim:&lt;/P&gt;&lt;P&gt;let me know how it goes. On our side the Nexus were reloaded to restore AAA.&lt;/P&gt;&lt;P&gt;We are not using LMS until this is fixed. We are trying to fix some paperwork before able to open a TAC Case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It could be simply the LMS version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate if you keep me in the loop. I will also update you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jun 2011 15:51:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700988#M294501</guid>
      <dc:creator>Ben Alex</dc:creator>
      <dc:date>2011-06-09T15:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: AAA TACACS NEXUS doesn't work</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700989#M294502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for the delay, finally I found my problem and a workaround&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On my case sometimes I can't ping or telnet my TACACS (ACS), when I type the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show ip arp vlan XXX (mgmt VLAN) I get some physical address and some other VRRP address.&lt;/P&gt;&lt;P&gt;all the VRRP addresses doesn't work and my TACACS server have got another address on another VLAN and the FW is NATING the TACACS address and therefore I get a VRRP address on my nexus for the tacacs...so I did add an arp mac entry into my mgmt interface VLAN and then it works. However that's not finished one other thing is even strange...I shut my VPC between the two NEXUS and I remove the static arp enty and then it works again even if my mgmt VLAN is not passing through the VPC and bearn in mind then my mgmt vlan is layer 2 excl.!!!!!! Do you follow me or? I will open a case with Cisco&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will keep you informed....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take care&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Karim Brussels&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jun 2011 08:26:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700989#M294502</guid>
      <dc:creator>karimbruxelles</dc:creator>
      <dc:date>2011-06-10T08:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: AAA TACACS NEXUS doesn't work</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700990#M294503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Karim:&lt;/P&gt;&lt;P&gt;Try to enable peer gateway under the vpc domain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Jun 2011 13:58:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700990#M294503</guid>
      <dc:creator>Ben Alex</dc:creator>
      <dc:date>2011-06-10T13:58:02Z</dc:date>
    </item>
    <item>
      <title>Re: AAA TACACS NEXUS doesn't work</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700991#M294504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello we faced similar problem with onf Nexuses 5548P we have. In this environment we are using ACS appliance with 5.2. and it has been working for months now. Now this one 5548P does not send out TCP/49 Tacacs query to the ACS, althought it has not changed nor other chages done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We took TCPdump, as well as from the 5548P debug aaa, and ffrom the dump we obtained, that the 5548 do not send out any packet (syn) to the tacacs+ server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When there is no packets going out, the tacacs+ authentication fails, and only the locally configured admininstravite users can logon (the aaa is able to pick a next method: local correctly).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the Log I got two messages: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2011 Dec&amp;nbsp; 1 11:47:08.630 sw01 %TACACS-5-TACACS_SERVER_STATUS: TACACS+ server 10.11.22.33 with auth-port 49 and acct-port 49 status has changed from UNMONITORED STATE to DEAD STATE. Server was in previous-state for N/A, and total dead time of the server is N/A&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2011 Dec&amp;nbsp; 1 11:47:08.630 sw01 %TACACS-5-TACACS_MONITOR_STATUS: Tacacs+ server 10.11.22.33 with auth-port 49 and acct-port 49 is now being monitored for interval 60 minutes. The server is currently marked DEAD&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;these Nexuses are running version 5.0(3)N2(2a) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the any option to get this TACACS server to UP-AND-RUNNING state, without reload?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds, Pekka&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Dec 2011 11:10:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700991#M294504</guid>
      <dc:creator>Pekka Majuri</dc:creator>
      <dc:date>2011-12-08T11:10:36Z</dc:date>
    </item>
    <item>
      <title>Re: AAA TACACS NEXUS doesn't work</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700992#M294505</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;first of all sorry for the delay, my mgmt VLAN doesn't exist into the nexus switches nevertheless it is configured on the VRF mgmt for security issue and if your switches goes down you still have a access onto the devices&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Connect your mgmt link/cable onto the physical interface mgmt 0 in the NEXUS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) show running-config | i vrf&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vrf context management&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) configure the inteface on the vrf mgmt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show running-config interface mgmt0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;version 5.0(3)N1(1c)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface mgmt0&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 192.168.254.207/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) ping an ip on the same MGMT vlan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ping 192.168.254.208 vrf management&lt;/P&gt;&lt;P&gt;PING 192.168.254.208 (192.168.254.208): 56 data bytes&lt;/P&gt;&lt;P&gt;64 bytes from 192.168.254.208: icmp_seq=0 ttl=254 time=0.711 ms&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Dec 2011 13:04:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700992#M294505</guid>
      <dc:creator>karimbruxelles</dc:creator>
      <dc:date>2011-12-08T13:04:46Z</dc:date>
    </item>
    <item>
      <title>AAA TACACS NEXUS doesn't work</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700993#M294506</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; No worry about the delay, these Nexus 5548P switches are in such a physical environment, that we could not do some of your task you suggested, unfortunately. Anyway they do not solve the question, is there any other methor to get it work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I even removed the existing tacacs+ configuration from the box, then I re configured it (by using the configuration statemens used for these working ones), no help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As earlier said in my post, that the Nexus 5548P stopped to send out any outbound tcp/49 tacacs+ session requests. (this were obtained from the tcpdump taken from firewall, which is def.gateway for Nexus management). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when trying to logon (with tacacs userid/pw) the following error message is resulted to gatekeeper (SSH) session establishment when entring the UID + strong password....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Remote AAA servers unreachable_local authentication failed.png&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A 2-4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;A&gt;&lt;/A&gt;&lt;A&gt;&lt;/A&gt;&lt;A&gt;&lt;/A&gt;&lt;A&gt;&lt;/A&gt;we do use mgmt vrf for VPC peer, not for the box management. the management interface is SVI, which has a firewall (not changed) as a Gateway, and all the other sessions, logging to the external security log servers, NTP, ssh, and&amp;nbsp; things like incoming/outgoing ssh sessions are working well, but no any tacacs request is leaving the box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The version we are running:&amp;nbsp; &lt;STRONG&gt;version 5.0(3)N2(2a)&lt;/STRONG&gt;&amp;nbsp; (bootflash:/n5000-uk9.5.0.3.N2.2a.bin) since beging of November. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Satisfactions from the N 5548 boxes are somewhat &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_macro_emoticon" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt; &lt;SPAN __jive_emoticon_name="minus" __jive_macro_name="emoticon" class="jive_macro jive_macro_emoticon" height="1" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif" width="1"&gt;&lt;/SPAN&gt; the only good thing is the price of the 10G interface port, which is not a cheap, but more a less expensive the Catalyst 6500s have. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Dec 2011 09:54:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700993#M294506</guid>
      <dc:creator>Pekka Majuri</dc:creator>
      <dc:date>2011-12-09T09:54:50Z</dc:date>
    </item>
    <item>
      <title>AAA TACACS NEXUS doesn't work</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700994#M294507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/people/pekka.majuri" id="jive-59640912024026529409267" onmouseout="" onmouseover=""&gt;Pekka Majuri&lt;/A&gt; ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am experiencing the exact problem you describe on the Nexus 5548 with TACACS.&amp;nbsp; Did you ever get this resolved? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Mar 2012 20:43:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700994#M294507</guid>
      <dc:creator>awatson20</dc:creator>
      <dc:date>2012-03-14T20:43:07Z</dc:date>
    </item>
    <item>
      <title>AAA TACACS NEXUS doesn't work</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700995#M294508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1) Connect your mgmt link/cable onto the &lt;STRONG&gt;physical interface mgmt 0 &lt;/STRONG&gt;in the NEXUS(&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) show running-config | i vrf&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vrf context management&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) configure the inteface on the vrf mgmt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show running-config interface mgmt0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;version 5.0(3)N1(1c)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface mgmt0&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 192.X.X.X/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) ping an ip on the same MGMT vlan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ping &lt;/STRONG&gt;192.X.X.X&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; vrf managemen&lt;/STRONG&gt;t&lt;/P&gt;&lt;P&gt;PING 192.X.X.X&lt;/P&gt;&lt;P&gt; (192.X.X.X): 56 data bytes&lt;/P&gt;&lt;P&gt;64 bytes from 192.X.X.X: icmp_seq=0 ttl=254 time=0.711 ms&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Command: show running-config aaa&lt;/P&gt;&lt;P&gt;!Time: Thu Mar 15 09:58:05 2012&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;version 5.1(3)N1(1)&lt;/P&gt;&lt;P&gt;logging level aaa 5&lt;/P&gt;&lt;P&gt;aaa authentication login default group bporama&lt;/P&gt;&lt;P&gt;aaa authentication login console local&lt;/P&gt;&lt;P&gt;aaa accounting default group bporama&lt;/P&gt;&lt;P&gt;no aaa user default-role&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;N11-BKP# sh running-config tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!Command: show running-config tacacs+&lt;/P&gt;&lt;P&gt;!Time: Thu Mar 15 09:58:11 2012&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;version 5.1(3)N1(1)&lt;/P&gt;&lt;P&gt;feature tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging level tacacs 5&lt;/P&gt;&lt;P&gt;tacacs-server key 7 "XXXX"&lt;/P&gt;&lt;P&gt;tacacs-server deadtime 30&lt;/P&gt;&lt;P&gt;tacacs-server host 192.X.X.X&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ bporama&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; server 192.X.X.X&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; use-vrf management&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; source-interface mgmt0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;N11-BKP#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2012 09:01:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700995#M294508</guid>
      <dc:creator>karimbruxelles</dc:creator>
      <dc:date>2012-03-15T09:01:16Z</dc:date>
    </item>
    <item>
      <title>AAA TACACS NEXUS doesn't work</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700996#M294509</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; No, the problem with the tacacs query (which didn't leave a nexus switch) were not solved, however my circumvention were reload the switch (luckyly we have fully redundant environment, where this problem exists). Personally my opinion is that the aaa subsystem state machine looked to have a problem to call tcp socket functios, but I could not prove any details to point it out to be there. And it looks like that this problem occurs quite a seldom, probably the process tread is going to be locked somehow by the kernel process causing aaa to hang with tacacs queries.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since we reloaded the switch in problems, this has not yet happened again (still same aaa configuration in it), so we have not obtained what ever material needed for TAC. But if the problem faced again, we will open a TAC case to address the problem...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you also running the&amp;nbsp; 5.0(3)N2(2a) in your Nexus switch or do you already run newer one? I hope you could reload the switch you have problem, to circumvent pb. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2012 09:22:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700996#M294509</guid>
      <dc:creator>Pekka Majuri</dc:creator>
      <dc:date>2012-03-15T09:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: AAA TACACS NEXUS doesn't work</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700997#M294510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thought I'd add to this thread given that we also experienced the problem of the tacacs query not leaving the switch on a Nexus 7K (C7010, NXOS version 5.2(5)) and resolved it without requiring a reload.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fortunately the 'admin' login does not require ACS authentication, so I could login remotely using this.&lt;/P&gt;&lt;P&gt;Remove all the aaa and tacacs config and disable the tacacs+ feature (no feature tacacs+).&lt;/P&gt;&lt;P&gt;Re-install tacacs+ and readd the tacacs and aaa config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Problem solved and no outage required.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 May 2013 23:11:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-tacacs-nexus-doesn-t-work/m-p/1700997#M294510</guid>
      <dc:creator>Tim Lane</dc:creator>
      <dc:date>2013-05-13T23:11:42Z</dc:date>
    </item>
  </channel>
</rss>

