<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Local authentication failure in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/local-authentication-failure/m-p/1350119#M313659</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We use ACS for authenticating equipments but lately when loose conectivity with server, equipments do not allow us to enter "enable" mode (even at console) only at first level, so could somebody give some light on where am I missing something?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the AAA config template:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;enable secret 5 XXXXXX!&lt;BR /&gt;username XXXXprivilege 15 secret 5 XXXXXX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ AuthenticationTacacs&lt;BR /&gt; server xxx.xxx.xxx&lt;BR /&gt; server xxx.xxx.xxx&lt;BR /&gt; server xxx.xxx.xxx&lt;BR /&gt;!&lt;BR /&gt;aaa group server tacacs+ AccountingTacacs&lt;BR /&gt; server xxx.xxx.xxx&lt;BR /&gt; server xxx.xxx.xxx&lt;BR /&gt;!&lt;BR /&gt;aaa authentication password-prompt "Password local: "&lt;BR /&gt;aaa authentication username-prompt "Username local: "&lt;BR /&gt;aaa authentication login default group AuthenticationTacacs local&lt;BR /&gt;aaa authentication login username_tacacs group tacacs+ local&lt;BR /&gt;aaa authentication enable default group AuthenticationTacacs enable&lt;BR /&gt;aaa authorization config-commands&lt;BR /&gt;aaa authorization exec default group AuthenticationTacacs local&lt;BR /&gt;aaa authorization commands 15 default group AuthenticationTacacs local&lt;BR /&gt;aaa accounting commands 15 default stop-only group AccountingTacacs&lt;BR /&gt;aaa accounting system default stop-only group AccountingTacacs&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip tacacs source-interface Vlan2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host xxx.xxx.xxx&lt;BR /&gt;tacacs-server host xxx.xxx.xxx&lt;BR /&gt;tacacs-server host xxx.xxx.xxx&lt;BR /&gt;tacacs-server timeout 3&lt;BR /&gt;tacacs-server directed-request&lt;BR /&gt;tacacs-server key 7 XXXXXXXX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line con 0&lt;BR /&gt; exec-timeout 20 0&lt;BR /&gt; logging synchronous&lt;BR /&gt; full-help&lt;BR /&gt; escape-character 27&lt;BR /&gt;line vty 0 4&lt;BR /&gt; exec-timeout 20 0&lt;BR /&gt; password 7 00071A150754&lt;BR /&gt; logging synchronous&lt;BR /&gt; length 0&lt;BR /&gt; full-help&lt;BR /&gt; escape-character 27&lt;BR /&gt;line vty 5 15&lt;BR /&gt; exec-timeout 20 0&lt;BR /&gt; password 7 1511021F0725&lt;BR /&gt; logging synchronous&lt;BR /&gt; full-help&lt;BR /&gt; escape-character 27&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luiz&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 00:02:30 GMT</pubDate>
    <dc:creator>luiz.alexandre.paiva</dc:creator>
    <dc:date>2019-03-11T00:02:30Z</dc:date>
    <item>
      <title>Local authentication failure</title>
      <link>https://community.cisco.com/t5/network-access-control/local-authentication-failure/m-p/1350119#M313659</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We use ACS for authenticating equipments but lately when loose conectivity with server, equipments do not allow us to enter "enable" mode (even at console) only at first level, so could somebody give some light on where am I missing something?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the AAA config template:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;enable secret 5 XXXXXX!&lt;BR /&gt;username XXXXprivilege 15 secret 5 XXXXXX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ AuthenticationTacacs&lt;BR /&gt; server xxx.xxx.xxx&lt;BR /&gt; server xxx.xxx.xxx&lt;BR /&gt; server xxx.xxx.xxx&lt;BR /&gt;!&lt;BR /&gt;aaa group server tacacs+ AccountingTacacs&lt;BR /&gt; server xxx.xxx.xxx&lt;BR /&gt; server xxx.xxx.xxx&lt;BR /&gt;!&lt;BR /&gt;aaa authentication password-prompt "Password local: "&lt;BR /&gt;aaa authentication username-prompt "Username local: "&lt;BR /&gt;aaa authentication login default group AuthenticationTacacs local&lt;BR /&gt;aaa authentication login username_tacacs group tacacs+ local&lt;BR /&gt;aaa authentication enable default group AuthenticationTacacs enable&lt;BR /&gt;aaa authorization config-commands&lt;BR /&gt;aaa authorization exec default group AuthenticationTacacs local&lt;BR /&gt;aaa authorization commands 15 default group AuthenticationTacacs local&lt;BR /&gt;aaa accounting commands 15 default stop-only group AccountingTacacs&lt;BR /&gt;aaa accounting system default stop-only group AccountingTacacs&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip tacacs source-interface Vlan2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host xxx.xxx.xxx&lt;BR /&gt;tacacs-server host xxx.xxx.xxx&lt;BR /&gt;tacacs-server host xxx.xxx.xxx&lt;BR /&gt;tacacs-server timeout 3&lt;BR /&gt;tacacs-server directed-request&lt;BR /&gt;tacacs-server key 7 XXXXXXXX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line con 0&lt;BR /&gt; exec-timeout 20 0&lt;BR /&gt; logging synchronous&lt;BR /&gt; full-help&lt;BR /&gt; escape-character 27&lt;BR /&gt;line vty 0 4&lt;BR /&gt; exec-timeout 20 0&lt;BR /&gt; password 7 00071A150754&lt;BR /&gt; logging synchronous&lt;BR /&gt; length 0&lt;BR /&gt; full-help&lt;BR /&gt; escape-character 27&lt;BR /&gt;line vty 5 15&lt;BR /&gt; exec-timeout 20 0&lt;BR /&gt; password 7 1511021F0725&lt;BR /&gt; logging synchronous&lt;BR /&gt; full-help&lt;BR /&gt; escape-character 27&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luiz&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:02:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-authentication-failure/m-p/1350119#M313659</guid>
      <dc:creator>luiz.alexandre.paiva</dc:creator>
      <dc:date>2019-03-11T00:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: Local authentication failure</title>
      <link>https://community.cisco.com/t5/network-access-control/local-authentication-failure/m-p/1350120#M313667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Luiz,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dentro do seu "line console 0" digite aaa authentication "GROUP" ou "default"&lt;/P&gt;&lt;P&gt;Da mesma forma no seu telnet ou ssh vty&lt;/P&gt;&lt;P&gt;Outra coisa, nao esqueca que se voce botar um espaco no final da sua senha ela tera um espaco, ex: "passWor&lt;SPAN style="text-decoration: underline;"&gt;d&lt;SPAN style="color: #333333;"&gt; &lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside your "line console 0" type aaa authentication "GROUP" or"default"&lt;/P&gt;&lt;P&gt;The same way in your telnet or ssht vty&lt;/P&gt;&lt;P&gt;Don't forget that if you put a space on the end of you password it needs to be typed as the ex: "passWor&lt;SPAN style="text-decoration: underline;"&gt;d&lt;SPAN style="color: #333333;"&gt; &lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW you have redundant line for login, i'd do the following way&lt;/P&gt;&lt;P&gt;Voce tem uma linha redudante para o login, eu faria desta forma abaixo&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication password-prompt "Password local: "&lt;BR /&gt; aaa&amp;nbsp; authentication username-prompt "Username local: "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa authentication login default group AuthenticationTacacs local&lt;BR /&gt;&lt;/STRONG&gt;aaa authentication enable default group AuthenticationTacacs enable&lt;BR /&gt;aaa authorization&amp;nbsp; config-commands&lt;BR /&gt;aaa authorization exec default group AuthenticationTacacs local&lt;BR /&gt;aaa authorization commands 15 default group AuthenticationTacacs local&lt;BR /&gt;aaa accounting commands 15 default stop-only group AccountingTacacs&lt;BR /&gt;aaa accounting system default stop-only group AccountingTacacs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Outra maneira, ela somente ira autenticar no console, pois o grupp nao e maneira "default" de autenticacao do equipamento logo vc precisa aplicar em algum lugar&lt;/P&gt;&lt;P&gt;Here is an other way, its authentication only for the console whitch isnt the default way to authenticate and you need to apply some where&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa authentication login CONSOLE local&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;line console 0&lt;/P&gt;&lt;P&gt;aaa authentication &lt;STRONG&gt;CONSOLE &lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Apr 2010 19:56:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-authentication-failure/m-p/1350120#M313667</guid>
      <dc:creator>Rodrigo Gurriti</dc:creator>
      <dc:date>2010-04-01T19:56:46Z</dc:date>
    </item>
    <item>
      <title>Re: Local authentication failure</title>
      <link>https://community.cisco.com/t5/network-access-control/local-authentication-failure/m-p/1350121#M313688</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;/PRE&gt;&lt;/P&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We use ACS for authenticating equipments but lately when loose conectivity with server, equipments do not allow us to enter "enable" mode (even at console) only at first level, so could somebody give some light on where am I missing something?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the AAA config template:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;enable secret 5 XXXXXX!&lt;BR /&gt;username XXXXprivilege 15 secret 5 XXXXXX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ AuthenticationTacacs&lt;BR /&gt;server xxx.xxx.xxx&lt;BR /&gt;server xxx.xxx.xxx&lt;BR /&gt;server xxx.xxx.xxx&lt;BR /&gt;!&lt;BR /&gt;aaa group server tacacs+ AccountingTacacs&lt;BR /&gt;server xxx.xxx.xxx&lt;BR /&gt;server xxx.xxx.xxx&lt;BR /&gt;!&lt;BR /&gt;aaa authentication password-prompt "Password local: "&lt;BR /&gt;aaa authentication username-prompt "Username local: "&lt;BR /&gt;aaa authentication login default group AuthenticationTacacs local&lt;BR /&gt;aaa authentication login username_tacacs group tacacs+ local&lt;BR /&gt;aaa authentication enable default group AuthenticationTacacs enable&lt;BR /&gt;aaa authorization config-commands&lt;BR /&gt;aaa authorization exec default group AuthenticationTacacs local&lt;BR /&gt;aaa authorization commands 15 default group AuthenticationTacacs local&lt;BR /&gt;aaa accounting commands 15 default stop-only group AccountingTacacs&lt;BR /&gt;aaa accounting system default stop-only group AccountingTacacs&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip tacacs source-interface Vlan2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host xxx.xxx.xxx&lt;BR /&gt;tacacs-server host xxx.xxx.xxx&lt;BR /&gt;tacacs-server host xxx.xxx.xxx&lt;BR /&gt;tacacs-server timeout 3&lt;BR /&gt;tacacs-server directed-request&lt;BR /&gt;tacacs-server key 7 XXXXXXXX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line con 0&lt;BR /&gt;exec-timeout 20 0&lt;BR /&gt;logging synchronous&lt;BR /&gt;full-help&lt;BR /&gt;escape-character 27&lt;BR /&gt;line vty 0 4&lt;BR /&gt;exec-timeout 20 0&lt;BR /&gt;password 7 00071A150754&lt;BR /&gt;logging synchronous&lt;BR /&gt;length 0&lt;BR /&gt;full-help&lt;BR /&gt;escape-character 27&lt;BR /&gt;line vty 5 15&lt;BR /&gt;exec-timeout 20 0&lt;BR /&gt;password 7 1511021F0725&lt;BR /&gt;logging synchronous&lt;BR /&gt;full-help&lt;BR /&gt;escape-character 27&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luiz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi Luiz,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuration for authentication need to&amp;nbsp; be done under line con as suggested and check out the below link for configuratio on AAA server configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www9.cisco.com/en/US/tech/tk59/technologies_tech_note09186a0080093c81.shtml"&gt;http://www9.cisco.com/en/US/tech/tk59/technologies_tech_note09186a0080093c81.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope to help !!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ganesh.H&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Cisco are currently donating money to the Haiti earthquake appeal for every rating so please consider rating all helpful posts.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Apr 2010 16:13:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-authentication-failure/m-p/1350121#M313688</guid>
      <dc:creator>Ganesh Hariharan</dc:creator>
      <dc:date>2010-04-02T16:13:58Z</dc:date>
    </item>
    <item>
      <title>Re: Local authentication failure</title>
      <link>https://community.cisco.com/t5/network-access-control/local-authentication-failure/m-p/1350122#M313752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The suggestions about configuring authentication on the console might make more sense if the problem were not getting into user mode. But if I understand the original post from Luiz he says that they can get into user mode but can not get into enable mode. If my understanding is not correct then I hope that Luiz will correct me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wonder if the problem might be that you are not using the right enable secret when you attempt to get into enable mode. I would suggest that you configure the router with a new, and very simple enable secret. Then the next time that you can not communicate with the server try using the simple enable secret and see if that works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Apr 2010 21:33:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-authentication-failure/m-p/1350122#M313752</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2010-04-07T21:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: Local authentication failure</title>
      <link>https://community.cisco.com/t5/network-access-control/local-authentication-failure/m-p/1350123#M313790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, first of all thanks for the answers and wehave two situations&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;When loose connectivity to AAA servers at console we can't access, shows user and password screen but doesn't authenticate, and when telnet to the equipment reach the user level, but not at enable level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We tryed enable secret as "cisco", enable password as the same but still doesn't work.&lt;/P&gt;&lt;P&gt;Tryed to use "username user privilege 15 secret {XXXXXXX}" and goes only at user level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as I understood this is a matter of better configuring console and line vty ports, but my problem now is that regarding IOS versions because at some equipments it doesn't support the exact commands as I need.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Apr 2010 18:42:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-authentication-failure/m-p/1350123#M313790</guid>
      <dc:creator>luiz.alexandre.paiva</dc:creator>
      <dc:date>2010-04-08T18:42:33Z</dc:date>
    </item>
  </channel>
</rss>

