<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TACACS+ SSH authentication to ASA Fo problem in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-ssh-authentication-to-asa-fo-problem/m-p/1513248#M297054</link>
    <description>&lt;P&gt;Dear,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I manage an ASA 5540 Active/Failover pair. SSH authentication is done through TACACS+ to ACS 4.2 located in the same VLAN as the inside interface of the firewalls. I have added both firewalls on to the ACS using their inside interface IP addresses (using the active and standby addresses). I can succesfully authenticate and login to the Active ASA without any problem. But on the standby ASA, I get SSH prompt but I could not login. When I see the failed attempts log under the ACS, I see "Unknown NAS" listed for the standby ASA. How can I solve this problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Abebe Amare&lt;/P&gt;&lt;P&gt;Network Engineer, VivaCell&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 00:27:59 GMT</pubDate>
    <dc:creator>cisabucho</dc:creator>
    <dc:date>2019-03-11T00:27:59Z</dc:date>
    <item>
      <title>TACACS+ SSH authentication to ASA Fo problem</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-ssh-authentication-to-asa-fo-problem/m-p/1513248#M297054</link>
      <description>&lt;P&gt;Dear,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I manage an ASA 5540 Active/Failover pair. SSH authentication is done through TACACS+ to ACS 4.2 located in the same VLAN as the inside interface of the firewalls. I have added both firewalls on to the ACS using their inside interface IP addresses (using the active and standby addresses). I can succesfully authenticate and login to the Active ASA without any problem. But on the standby ASA, I get SSH prompt but I could not login. When I see the failed attempts log under the ACS, I see "Unknown NAS" listed for the standby ASA. How can I solve this problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Abebe Amare&lt;/P&gt;&lt;P&gt;Network Engineer, VivaCell&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:27:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-ssh-authentication-to-asa-fo-problem/m-p/1513248#M297054</guid>
      <dc:creator>cisabucho</dc:creator>
      <dc:date>2019-03-11T00:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+ SSH authentication to ASA Fo problem</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-ssh-authentication-to-asa-fo-problem/m-p/1513249#M297079</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Abebe,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the secondary ASA, please check the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh failover&amp;nbsp;&amp;nbsp;&amp;nbsp; ---&amp;gt; and make sure the secondary is in standby ready and not failed.&lt;/P&gt;&lt;P&gt;sh aaa-server&amp;nbsp;&amp;nbsp;&amp;nbsp; ----&amp;gt; check the output and see if the ASA has marked the tacacs server as "UP" and exchange of packets.&lt;/P&gt;&lt;P&gt;Enable follwoing debugs and run a test authentication as mentioned:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug aaa authentication&lt;/P&gt;&lt;P&gt;debug tacacs&lt;/P&gt;&lt;P&gt;debug ssh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="questionBody"&gt;test aaa-server authentication &lt;TACACS&gt; host &lt;SERVER ip=""&gt;&amp;nbsp; username "insert name" password "insert password"&lt;/SERVER&gt;&lt;/TACACS&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Provide me the debugs after taking out your username in it so that i can analyze.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Rudresh V&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Oct 2010 12:05:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-ssh-authentication-to-asa-fo-problem/m-p/1513249#M297079</guid>
      <dc:creator>Rudresh Veerappaji</dc:creator>
      <dc:date>2010-10-05T12:05:02Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+ SSH authentication to ASA Fo problem</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-ssh-authentication-to-asa-fo-problem/m-p/1513250#M297123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Rudresh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I do a sh aaa-server I got the following:&lt;/P&gt;&lt;P&gt;ASA-01# sh aaa-server&lt;BR /&gt;Server Group:&amp;nbsp;&amp;nbsp;&amp;nbsp; ACS&lt;BR /&gt;Server Protocol: tacacs+&lt;BR /&gt;Server Address:&amp;nbsp; 192.168.x.xx&lt;BR /&gt;Server port:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 49&lt;BR /&gt;Server status:&amp;nbsp;&amp;nbsp; ACTIVE, Last transaction at unknown&lt;BR /&gt;Number of pending requests&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;Average round trip time&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0ms&lt;BR /&gt;Number of authentication requests&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;Number of authorization requests&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;Number of accounting requests&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;Number of retransmissions&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;Number of accepts&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;Number of rejects&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;Number of challenges&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;Number of malformed responses&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;Number of bad authenticators&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;Number of timeouts&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;Number of unrecognized responses&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This made me to double check the configuration. I define the same ACS server twice with different name and protocol (once for RADIUS to authenticate VPN sessions and the other for TACACS+ to authenticate device access). So it turned out I put the wrong server name under ssh authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for pointing me in the right direction and I give you full marks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Abebe Amare&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Oct 2010 13:39:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-ssh-authentication-to-asa-fo-problem/m-p/1513250#M297123</guid>
      <dc:creator>cisabucho</dc:creator>
      <dc:date>2010-10-05T13:39:39Z</dc:date>
    </item>
  </channel>
</rss>

