<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need urgent help in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/need-urgent-help/m-p/1399633#M327415</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Sateesh,&lt;/P&gt;&lt;P&gt;Please check the below once&lt;/P&gt;&lt;P&gt;1) Tacacs key configured on the Router and ACS server should be same&lt;/P&gt;&lt;P&gt;2) are you able to reach the ACS from the Router&lt;/P&gt;&lt;P&gt;3) Since you are not able to loging via ACS, are you able to connect to the router through the line mode&lt;/P&gt;&lt;P&gt;4) run the debug commands like debugg tacacs events or debugg aaa ?&lt;/P&gt;&lt;P&gt;if possible please paste you entire Routers AAA config&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Dipu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 02 Mar 2010 05:16:48 GMT</pubDate>
    <dc:creator>georgedipu</dc:creator>
    <dc:date>2010-03-02T05:16:48Z</dc:date>
    <item>
      <title>Need urgent help</title>
      <link>https://community.cisco.com/t5/network-access-control/need-urgent-help/m-p/1399632#M327333</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have remote office having router and VPN to my mainoffice.&lt;/P&gt;&lt;P&gt;TACACS server sitting at mainoffice&lt;/P&gt;&lt;P&gt;When I am try integration my remote office router with TACACS(sitting at main office). its not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is can i integrate remore office router(having tunnel to mainoffice) with TACACS?&lt;/P&gt;&lt;P&gt;TACACS encrypted traffic will pass thru the tunnel.? Here is config for the same..Do ineed to add any addtional line for passing TACACS traffic thru tunnel...(offcourse TACACS server IP added in the config)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;BR /&gt;aaa authentication enable default none&lt;BR /&gt;aaa authentication ppp default group tacacs+ local&lt;BR /&gt;aaa authorization exec default group tacacs+ local&lt;BR /&gt;aaa accounting exec default start-stop group tacacs+&lt;BR /&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Sateesh kumar.k&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:59:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-urgent-help/m-p/1399632#M327333</guid>
      <dc:creator>sateeshk10</dc:creator>
      <dc:date>2019-03-10T23:59:00Z</dc:date>
    </item>
    <item>
      <title>Re: Need urgent help</title>
      <link>https://community.cisco.com/t5/network-access-control/need-urgent-help/m-p/1399633#M327415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Sateesh,&lt;/P&gt;&lt;P&gt;Please check the below once&lt;/P&gt;&lt;P&gt;1) Tacacs key configured on the Router and ACS server should be same&lt;/P&gt;&lt;P&gt;2) are you able to reach the ACS from the Router&lt;/P&gt;&lt;P&gt;3) Since you are not able to loging via ACS, are you able to connect to the router through the line mode&lt;/P&gt;&lt;P&gt;4) run the debug commands like debugg tacacs events or debugg aaa ?&lt;/P&gt;&lt;P&gt;if possible please paste you entire Routers AAA config&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Dipu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Mar 2010 05:16:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-urgent-help/m-p/1399633#M327415</guid>
      <dc:creator>georgedipu</dc:creator>
      <dc:date>2010-03-02T05:16:48Z</dc:date>
    </item>
    <item>
      <title>Re: Need urgent help</title>
      <link>https://community.cisco.com/t5/network-access-control/need-urgent-help/m-p/1399634#M327467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes.. TACACS configure will vary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the below link.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/ios/sec_user_services/configuration/guide/sec_per_vrf_aaa.html"&gt;http://www.cisco.com/en/US/docs/ios/sec_user_services/configuration/guide/sec_per_vrf_aaa.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ &lt;STRONG&gt;tacacs_vrf_name&lt;/STRONG&gt;&lt;BR /&gt; server-private &lt;STRONG&gt;IP&lt;/STRONG&gt; key &lt;STRONG&gt;KeyID&lt;/STRONG&gt;&lt;BR /&gt; ip vrf forwarding &lt;STRONG&gt;VRFNAME&lt;/STRONG&gt;&lt;BR /&gt; ip tacacs source-interface &lt;STRONG&gt;Intname&lt;/STRONG&gt;&lt;BR /&gt; &lt;BR /&gt;aaa authentication login default group tacacs_vrf_name group tacacs+ line enable&lt;BR /&gt;aaa authentication login no_tacacs none&lt;BR /&gt;aaa authentication enable default group tacacs_vrf_name group tacacs+ enable none&lt;BR /&gt;aaa authentication ppp default local&lt;BR /&gt;aaa authorization commands 15 default group tacacs_vrf_name group tacacs+ if-authenticated &lt;BR /&gt;aaa accounting exec default start-stop group tacacs_vrf_name group tacacs+&lt;BR /&gt;aaa accounting commands 15 default start-stop group tacacs_vrf_name group tacacs+&lt;BR /&gt;aaa accounting network default start-stop group tacacs_vrf_name group tacacs+&lt;BR /&gt;aaa accounting connection default start-stop group tacacs_vrf_name group tacacs+&lt;BR /&gt;aaa accounting system default start-stop group tacacs_vrf_name group tacacs+&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Mar 2010 05:32:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-urgent-help/m-p/1399634#M327467</guid>
      <dc:creator>Vijayalakshmi.pancheti</dc:creator>
      <dc:date>2010-03-02T05:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: Need urgent help</title>
      <link>https://community.cisco.com/t5/network-access-control/need-urgent-help/m-p/1399635#M327523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have remote office having router and VPN to my mainoffice.&lt;/P&gt;&lt;P&gt;TACACS server sitting at mainoffice&lt;/P&gt;&lt;P&gt;When I am try integration my remote office router with TACACS(sitting at main office). its not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is can i integrate remore office router(having tunnel to mainoffice) with TACACS?&lt;/P&gt;&lt;P&gt;TACACS
encrypted traffic will pass thru the tunnel.? Here is config for the
same..Do ineed to add any addtional line for passing TACACS traffic
thru tunnel...(offcourse TACACS server IP added in the config)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;BR /&gt;aaa authentication enable default none&lt;BR /&gt;aaa authentication ppp default group tacacs+ local&lt;BR /&gt;aaa authorization exec default group tacacs+ local&lt;BR /&gt;aaa accounting exec default start-stop group tacacs+&lt;BR /&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Sateesh kumar.k&lt;/P&gt;&lt;/PRE&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi Sateesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you can integarte the remote office router with you TACAS server for that you should have proper connectivity and reachbilty on ports TCP port 49 between TACAS server and Clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just also mention the source interface through which the packets will be going to tacas server also by the following command &lt;SPAN id="main" style="visibility: visible;"&gt;&lt;SPAN id="search" style="visibility: visible;"&gt;&lt;EM&gt;ip tacacs source&lt;/EM&gt;-&lt;EM&gt;interface&lt;/EM&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope that helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember to rate the useful post&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ganesh.H&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Mar 2010 11:13:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/need-urgent-help/m-p/1399635#M327523</guid>
      <dc:creator>Ganesh Hariharan</dc:creator>
      <dc:date>2010-03-02T11:13:55Z</dc:date>
    </item>
  </channel>
</rss>

