<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA Authorization not working - in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-not-working/m-p/1392613#M317484</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nusrat,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you found a solution for this problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are having the same issue with the Nexus 5000 concerning Authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jasper&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 Jun 2010 10:05:43 GMT</pubDate>
    <dc:creator>Jasper van Nederpelt</dc:creator>
    <dc:date>2010-06-25T10:05:43Z</dc:date>
    <item>
      <title>AAA Authorization not working -</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-not-working/m-p/1392611#M317472</link>
      <description>&lt;P&gt;I have a very strange problem. I set up tacacs on two Nexus 5000 switches with exactly the same tacacs, aaa config (see below). N01 is working fine but N02 has problems in Authorization. I am able to authenticate into N02 but can use only a few commands, whereas N01 has the full set of commands available.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I see error messages in the log (see bottom).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ked1.dcacc.n02(config)# ?&lt;/P&gt;&lt;P&gt;end Go to exec mode&lt;/P&gt;&lt;P&gt;exit Exit from command interpreter&lt;/P&gt;&lt;P&gt;no Negate a command or set its defaults&lt;/P&gt;&lt;P&gt;username Configure user information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ked1.dcacc.n02# sho run aaa&lt;/P&gt;&lt;P&gt;version 4.1(3)N2(1)&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs local&lt;/P&gt;&lt;P&gt;aaa authorization config-commands default group tacacs local&lt;/P&gt;&lt;P&gt;aaa authorization commands default group tacacs local&lt;/P&gt;&lt;P&gt;aaa accounting default group tacacs local&lt;/P&gt;&lt;P&gt;aaa authentication login error-enable&lt;/P&gt;&lt;P&gt;ked1.dcacc.n02# sho run tacacs&lt;/P&gt;&lt;P&gt;version 4.1(3)N2(1)&lt;/P&gt;&lt;P&gt;feature tacacs+&lt;/P&gt;&lt;P&gt;tacacs-server host 167.54.254.113 key 7 .....&lt;/P&gt;&lt;P&gt;ip tacacs source-interface Vlan2&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ tacacs&lt;/P&gt;&lt;P&gt;server 167.54.254.113&lt;/P&gt;&lt;P&gt;source-interface Vlan2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Comparing CONFIG with ked1.dcacc.n01:&lt;/P&gt;&lt;P&gt;ked1.dcacc.n01# sho run tacacs&lt;/P&gt;&lt;P&gt;version 4.1(3)N2(1)&lt;/P&gt;&lt;P&gt;feature tacacs+&lt;/P&gt;&lt;P&gt;tacacs-server host 167.54.254.113 key 7 .....&lt;/P&gt;&lt;P&gt;ip tacacs source-interface Vlan2&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ tacacs&lt;/P&gt;&lt;P&gt;server 167.54.254.113&lt;/P&gt;&lt;P&gt;source-interface Vlan2&lt;/P&gt;&lt;P&gt;ked1.dcacc.n01# sho run aaa&lt;/P&gt;&lt;P&gt;version 4.1(3)N2(1)&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs local&lt;/P&gt;&lt;P&gt;aaa authorization config-commands default group tacacs local&lt;/P&gt;&lt;P&gt;aaa authorization commands default group tacacs local&lt;/P&gt;&lt;P&gt;aaa accounting default group tacacs local&lt;/P&gt;&lt;P&gt;aaa authentication login error-enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ked1.dcacc.n02# sho log last 10&lt;/P&gt;&lt;P&gt;2010 Feb 12 13:55:13.697 ked1.dcacc.n02 %TACACS-3-TACACS_ERROR_MESSAGE: All servers failed to respond&lt;/P&gt;&lt;P&gt;2010 Feb 12 13:56:14.975 ked1.dcacc.n02 %TACACS-3-TACACS_ERROR_MESSAGE: All servers failed to respond&lt;/P&gt;&lt;P&gt;2010 Feb 12 13:56:14.975 ked1.dcacc.n02 %VSHD-5-VSHD_SYSLOG_CONFIG_I: Configured from vty by khwajan on 167.54.254.2@pt&lt;/P&gt;&lt;P&gt;s/0&lt;/P&gt;&lt;P&gt;2010 Feb 12 13:56:14.987 ked1.dcacc.n02 9836]: CLIC-6-EXIT_CONFIG: Configured from 0 by systest&lt;/P&gt;&lt;P&gt;2010 Feb 12 13:56:15.087 ked1.dcacc.n02 snmpd: snmpd: send_trap: Failure in sendto (No route to host)&lt;/P&gt;&lt;P&gt;2010 Feb 12 13:56:15.088 ked1.dcacc.n02 snmpd: snmpd: send_trap: Failure in sendto (No route to host)&lt;/P&gt;&lt;P&gt;2010 Feb 12 13:56:15.088 ked1.dcacc.n02 snmpd: NETWORK- UNREACHABLE&lt;/P&gt;&lt;P&gt;2010 Feb 12 14:01:22.771 ked1.dcacc.n02 %TACACS-3-TACACS_ERROR_MESSAGE: All servers failed to respond&lt;/P&gt;&lt;P&gt;2010 Feb 12 14:01:34 ked1.dcacc.n02 %AUTHPRIV-3-SYSTEM_MSG: pam_aaa:Authentication failed for user admin from 172.19.1.&lt;/P&gt;&lt;P&gt;3 - login[9969]&lt;/P&gt;&lt;P&gt;2010 Feb 12 14:01:50.349 ked1.dcacc.n02 %TACACS-3-TACACS_ERROR_MESSAGE: All servers failed to respond&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Both N01 and N02 have the following message logged frequently,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%TACACS-3-TACACS_ERROR_MESSAGE: All servers failed to respond&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Our tacacs server is V3.0&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:57:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization-not-working/m-p/1392611#M317472</guid>
      <dc:creator>khwajanusrat</dc:creator>
      <dc:date>2019-03-10T23:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Authorization not working -</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-not-working/m-p/1392612#M317476</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per the logs if request is going to TACAS server and TACAS server is failed to respond mean check the services of tacas services in tacas server are flaaping or check the connectivity of tacas server from switches they are reachable or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope to help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ganesh.H&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Feb 2010 08:20:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization-not-working/m-p/1392612#M317476</guid>
      <dc:creator>Ganesh Hariharan</dc:creator>
      <dc:date>2010-02-16T08:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Authorization not working -</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-not-working/m-p/1392613#M317484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nusrat,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you found a solution for this problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are having the same issue with the Nexus 5000 concerning Authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jasper&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jun 2010 10:05:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization-not-working/m-p/1392613#M317484</guid>
      <dc:creator>Jasper van Nederpelt</dc:creator>
      <dc:date>2010-06-25T10:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Authorization not working -</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-not-working/m-p/1392614#M317504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;no response so far.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jun 2010 13:29:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization-not-working/m-p/1392614#M317504</guid>
      <dc:creator>khwajanusrat</dc:creator>
      <dc:date>2010-06-25T13:29:41Z</dc:date>
    </item>
  </channel>
</rss>

