<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ACS authentication problems in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-acs-authentication-problems/m-p/1306491#M348516</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just setup my ACS server for Windows. It running software version 4.1. I having problems authenticating. I have my AAA Clients setup in the ACS gui use tacacs to authenticate. I the switch key and ACS server keys matching. I have users setup.   Here is my AAA config on the switch..&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the debug info on tacacs&lt;/P&gt;&lt;P&gt;183757: Sep  2 10:14:22.131 edt: TAC+: send AUTHEN/START packet ver=192 id=2789804961&lt;/P&gt;&lt;P&gt;183758: Sep  2 10:14:22.131 edt: TAC+: Using default tacacs server-group "tacacs+" list.&lt;/P&gt;&lt;P&gt;183759: Sep  2 10:14:22.131 edt: TAC+: Opening TCP/IP to 10.11.8.200/49 timeout=5&lt;/P&gt;&lt;P&gt;183760: Sep  2 10:14:22.135 edt: TAC+: Opened TCP/IP handle 0x80E767B8 to 10.11.8.200/49&lt;/P&gt;&lt;P&gt;183761: Sep  2 10:14:22.135 edt: TAC+: 10.11.8.200 (2789804961) AUTHEN/START/LOGIN/ASCII queued&lt;/P&gt;&lt;P&gt;183762: Sep  2 10:14:22.335 edt: TAC+: (2789804961) AUTHEN/START/LOGIN/ASCII processed&lt;/P&gt;&lt;P&gt;183763: Sep  2 10:14:22.335 edt: TAC+: received bad AUTHEN packet: length = 6, expected 128683&lt;/P&gt;&lt;P&gt;WC2950-12#&lt;/P&gt;&lt;P&gt;183764: Sep  2 10:14:22.335 edt: TAC+: Invalid AUTHEN/START/LOGIN/ASCII packet (check keys).&lt;/P&gt;&lt;P&gt;183765: Sep  2 10:14:22.335 edt: TAC+: Closing TCP/IP 0x80E767B8 connection to 10.11.8.200/49&lt;/P&gt;&lt;P&gt;183766: Sep  2 10:14:22.339 edt: TAC+: Using default tacacs server-group "tacacs+" list.&lt;/P&gt;&lt;P&gt;183767: Sep  2 10:14:22.339 edt: SSH1: password authentication failed for wcromwell&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have same keys on the AAA server as I do on my switch.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 23:40:14 GMT</pubDate>
    <dc:creator>Wayne Cromwell</dc:creator>
    <dc:date>2019-03-10T23:40:14Z</dc:date>
    <item>
      <title>Cisco ACS authentication problems</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-authentication-problems/m-p/1306491#M348516</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just setup my ACS server for Windows. It running software version 4.1. I having problems authenticating. I have my AAA Clients setup in the ACS gui use tacacs to authenticate. I the switch key and ACS server keys matching. I have users setup.   Here is my AAA config on the switch..&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the debug info on tacacs&lt;/P&gt;&lt;P&gt;183757: Sep  2 10:14:22.131 edt: TAC+: send AUTHEN/START packet ver=192 id=2789804961&lt;/P&gt;&lt;P&gt;183758: Sep  2 10:14:22.131 edt: TAC+: Using default tacacs server-group "tacacs+" list.&lt;/P&gt;&lt;P&gt;183759: Sep  2 10:14:22.131 edt: TAC+: Opening TCP/IP to 10.11.8.200/49 timeout=5&lt;/P&gt;&lt;P&gt;183760: Sep  2 10:14:22.135 edt: TAC+: Opened TCP/IP handle 0x80E767B8 to 10.11.8.200/49&lt;/P&gt;&lt;P&gt;183761: Sep  2 10:14:22.135 edt: TAC+: 10.11.8.200 (2789804961) AUTHEN/START/LOGIN/ASCII queued&lt;/P&gt;&lt;P&gt;183762: Sep  2 10:14:22.335 edt: TAC+: (2789804961) AUTHEN/START/LOGIN/ASCII processed&lt;/P&gt;&lt;P&gt;183763: Sep  2 10:14:22.335 edt: TAC+: received bad AUTHEN packet: length = 6, expected 128683&lt;/P&gt;&lt;P&gt;WC2950-12#&lt;/P&gt;&lt;P&gt;183764: Sep  2 10:14:22.335 edt: TAC+: Invalid AUTHEN/START/LOGIN/ASCII packet (check keys).&lt;/P&gt;&lt;P&gt;183765: Sep  2 10:14:22.335 edt: TAC+: Closing TCP/IP 0x80E767B8 connection to 10.11.8.200/49&lt;/P&gt;&lt;P&gt;183766: Sep  2 10:14:22.339 edt: TAC+: Using default tacacs server-group "tacacs+" list.&lt;/P&gt;&lt;P&gt;183767: Sep  2 10:14:22.339 edt: SSH1: password authentication failed for wcromwell&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have same keys on the AAA server as I do on my switch.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:40:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-authentication-problems/m-p/1306491#M348516</guid>
      <dc:creator>Wayne Cromwell</dc:creator>
      <dc:date>2019-03-10T23:40:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS authentication problems</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-authentication-problems/m-p/1306492#M348517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please check the NDG secret key and aaa client key. NDG override aaa client key. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure you have correct key in NDG&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Sep 2009 13:59:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-authentication-problems/m-p/1306492#M348517</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2009-09-02T13:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS authentication problems</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-authentication-problems/m-p/1306493#M348518</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That all set! thanks... I have accounting questioned. I set accounting for commands in the switch . Were do I view the report in ACS? In the Report and Activity I don't see the report for commands. I click on Tacacs+ Accounting but that report doesn't have any of the commands that I have used. If I debug AAA i do see AAA recording the commands.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Sep 2009 15:11:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-authentication-problems/m-p/1306493#M348518</guid>
      <dc:creator>Wayne Cromwell</dc:creator>
      <dc:date>2009-09-02T15:11:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS authentication problems</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-authentication-problems/m-p/1306494#M348519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here are the command you need on IOS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 aaa-list start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 aaa-list start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These logs are stored in tacacs administration report, so make sure you are checking the correct head.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still it is not working then check acs code. Incase it is 4.1.1 then you need to apply patch 5 to fix it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To download patch for appliance,&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/cgi-bin/tablebuild.pl/acs-soleng-3des" target="_blank"&gt;http://www.cisco.com/cgi-bin/tablebuild.pl/acs-soleng-3des&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For windows&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/cgi-bin/tablebuild.pl/acs-win-3des" target="_blank"&gt;http://www.cisco.com/cgi-bin/tablebuild.pl/acs-win-3des&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Sep 2009 15:18:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-authentication-problems/m-p/1306494#M348519</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2009-09-02T15:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS authentication problems</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-authentication-problems/m-p/1306495#M348520</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, Thanks worked!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Sep 2009 16:30:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-authentication-problems/m-p/1306495#M348520</guid>
      <dc:creator>Wayne Cromwell</dc:creator>
      <dc:date>2009-09-02T16:30:54Z</dc:date>
    </item>
  </channel>
</rss>

