<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 5.1 - tacacs+ issue witch &amp;quot;network access&amp;quot; access servic in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-1-tacacs-issue-witch-quot-network-access-quot-access/m-p/1457576#M312444</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I meant that in ASA I needed to define 2 aaa servers (one for tacacs and one for radius).&lt;/P&gt;&lt;P&gt;When integrating ASA with ACS4.2 I could use only tacacs server (for command authorization and vpn policy as well).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx and regards&lt;/P&gt;&lt;P&gt;P&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Aug 2010 07:51:41 GMT</pubDate>
    <dc:creator>Przemyslaw Konitz</dc:creator>
    <dc:date>2010-08-12T07:51:41Z</dc:date>
    <item>
      <title>ACS 5.1 - tacacs+ issue witch "network access" access services</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-tacacs-issue-witch-quot-network-access-quot-access/m-p/1457570#M312438</link>
      <description>&lt;P&gt;hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can anyone explain why tacacs+ can't be used with network access services?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/4/8/3/6384-ScreenShot147.jpg" alt="ScreenShot147.jpg" class="jive-image-thumbnail jive-image" height="142" onclick="" width="463" /&gt;&lt;/P&gt;&lt;P&gt;I know that main purpose of tacacs is command authorization but as I remember with ACS 4.2 it was possible. For example for PPP purpose.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx and regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Przemek&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:19:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-tacacs-issue-witch-quot-network-access-quot-access/m-p/1457570#M312438</guid>
      <dc:creator>Przemyslaw Konitz</dc:creator>
      <dc:date>2019-03-11T00:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.1 - tacacs+ issue witch "network access" access servic</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-tacacs-issue-witch-quot-network-access-quot-access/m-p/1457571#M312439</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On ACS 5.x &lt;/P&gt;&lt;P&gt;Default Device Admin = Tacacs+&lt;/P&gt;&lt;P&gt;Default Network Access = Radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is determined by the service selection rules.&amp;nbsp; Without other information it appears that you tried to process a Tacacs request with the Default Network Access somehow.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Aug 2010 20:45:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-tacacs-issue-witch-quot-network-access-quot-access/m-p/1457571#M312439</guid>
      <dc:creator>michagar</dc:creator>
      <dc:date>2010-08-11T20:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.1 - tacacs+ issue witch "network access" access servic</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-tacacs-issue-witch-quot-network-access-quot-access/m-p/1457572#M312440</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thx for reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think this is not the case that Default Network Access is selected in response to TACACS request cause I have other "Access Services" created and default one is even deactivated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;even in log there is my vpn-access-rule selected&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/0/7/3/6370-ScreenShot152.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your opinion this should work? I mean using Tacacs+ with Network Access service.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone confirm it?&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Aug 2010 06:48:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-tacacs-issue-witch-quot-network-access-quot-access/m-p/1457572#M312440</guid>
      <dc:creator>Przemyslaw Konitz</dc:creator>
      <dc:date>2010-08-12T06:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.1 - tacacs+ issue witch "network access" access servic</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-tacacs-issue-witch-quot-network-access-quot-access/m-p/1457573#M312441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;TACACS+ requests can only be handled by access services with the Service Type set to "Device Administration".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;If type is NetworkAccess it will fail. Please check the Service Type defined for the Access Service "VPM-access"&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Aug 2010 06:54:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-tacacs-issue-witch-quot-network-access-quot-access/m-p/1457573#M312441</guid>
      <dc:creator>jrabinow</dc:creator>
      <dc:date>2010-08-12T06:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.1 - tacacs+ issue witch "network access" access servic</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-tacacs-issue-witch-quot-network-access-quot-access/m-p/1457574#M312442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thx for explaination&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was afraid that this was the case. So if ASA need to control command authorization and verify user credentials in vpn policy (with attributes for that vpn policy) I need to define 2 seperate AAA servers? First as tacacs and 2nd as RADIUS?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Aug 2010 07:07:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-tacacs-issue-witch-quot-network-access-quot-access/m-p/1457574#M312442</guid>
      <dc:creator>Przemyslaw Konitz</dc:creator>
      <dc:date>2010-08-12T07:07:49Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.1 - tacacs+ issue witch "network access" access servic</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-tacacs-issue-witch-quot-network-access-quot-access/m-p/1457575#M312443</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure if I follow the question. However, a single ACS server can be used to process both RADIUS and TACACS+ requests&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is in fact the sample services and selection rules that are provide upon product installation. Performs service selection according to the protocol and then selects either: "Default Device Admin" and "Default Network Access" accordingly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Aug 2010 07:29:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-tacacs-issue-witch-quot-network-access-quot-access/m-p/1457575#M312443</guid>
      <dc:creator>jrabinow</dc:creator>
      <dc:date>2010-08-12T07:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.1 - tacacs+ issue witch "network access" access servic</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-1-tacacs-issue-witch-quot-network-access-quot-access/m-p/1457576#M312444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I meant that in ASA I needed to define 2 aaa servers (one for tacacs and one for radius).&lt;/P&gt;&lt;P&gt;When integrating ASA with ACS4.2 I could use only tacacs server (for command authorization and vpn policy as well).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx and regards&lt;/P&gt;&lt;P&gt;P&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Aug 2010 07:51:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-1-tacacs-issue-witch-quot-network-access-quot-access/m-p/1457576#M312444</guid>
      <dc:creator>Przemyslaw Konitz</dc:creator>
      <dc:date>2010-08-12T07:51:41Z</dc:date>
    </item>
  </channel>
</rss>

