<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Router Attempting Authentication to TACACS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/router-attempting-authentication-to-tacacs/m-p/1131702#M364612</link>
    <description>&lt;P&gt;I have a new router which about every 2-3 mintues tries to authenticate to the TACACS server.  With variuos usernames like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rb: &amp;lt;&lt;/P&gt;&lt;P&gt;rb: &amp;lt;&lt;/P&gt;&lt;P&gt;Local_1&amp;gt; User Access Verification&lt;/P&gt;&lt;P&gt;own command verb: &amp;lt;USERNAME:&amp;gt;. &lt;/P&gt;&lt;P&gt;ccess Verification&lt;/P&gt;&lt;P&gt;ess Verification&lt;/P&gt;&lt;P&gt;cal_1&amp;gt; Username: &lt;/P&gt;&lt;P&gt;ame: &lt;/P&gt;&lt;P&gt;al_1&amp;gt; User Access Verification&lt;/P&gt;&lt;P&gt;Local_1&amp;gt; Username: &lt;/P&gt;&lt;P&gt;Local_1&amp;gt; Username: &lt;/P&gt;&lt;P&gt;fied.&lt;/P&gt;&lt;P&gt;rb: &amp;lt;&lt;/P&gt;&lt;P&gt;n command verb: &amp;lt;&lt;/P&gt;&lt;P&gt;rb: &amp;lt;&lt;/P&gt;&lt;P&gt;ame: &lt;/P&gt;&lt;P&gt;e&amp;gt; Username: &lt;/P&gt;&lt;P&gt;Local_1&amp;gt; Username: &lt;/P&gt;&lt;P&gt;Local_1&amp;gt; Username: &lt;/P&gt;&lt;P&gt;Local_1&amp;gt; Username: &lt;/P&gt;&lt;P&gt;n command verb: &amp;lt;&lt;/P&gt;&lt;P&gt;nd verb: &amp;lt;USER&amp;gt;. &lt;/P&gt;&lt;P&gt;r: Unknown command verb: &amp;lt;USER&amp;gt;. &lt;/P&gt;&lt;P&gt;nd verb: &amp;lt;USER&amp;gt;. &lt;/P&gt;&lt;P&gt;ER&amp;gt;. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's the basic config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local line&lt;/P&gt;&lt;P&gt;aaa authentication login ACS group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;tacacs-server host A.B.C.D&lt;/P&gt;&lt;P&gt;tacacs-server host A.B.C.D&lt;/P&gt;&lt;P&gt;tacacs-server key 7 XXXXXXXXXXXXXXXXXXXXXXX&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help will be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 23:12:20 GMT</pubDate>
    <dc:creator>ssarte123</dc:creator>
    <dc:date>2019-03-10T23:12:20Z</dc:date>
    <item>
      <title>Router Attempting Authentication to TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/router-attempting-authentication-to-tacacs/m-p/1131702#M364612</link>
      <description>&lt;P&gt;I have a new router which about every 2-3 mintues tries to authenticate to the TACACS server.  With variuos usernames like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rb: &amp;lt;&lt;/P&gt;&lt;P&gt;rb: &amp;lt;&lt;/P&gt;&lt;P&gt;Local_1&amp;gt; User Access Verification&lt;/P&gt;&lt;P&gt;own command verb: &amp;lt;USERNAME:&amp;gt;. &lt;/P&gt;&lt;P&gt;ccess Verification&lt;/P&gt;&lt;P&gt;ess Verification&lt;/P&gt;&lt;P&gt;cal_1&amp;gt; Username: &lt;/P&gt;&lt;P&gt;ame: &lt;/P&gt;&lt;P&gt;al_1&amp;gt; User Access Verification&lt;/P&gt;&lt;P&gt;Local_1&amp;gt; Username: &lt;/P&gt;&lt;P&gt;Local_1&amp;gt; Username: &lt;/P&gt;&lt;P&gt;fied.&lt;/P&gt;&lt;P&gt;rb: &amp;lt;&lt;/P&gt;&lt;P&gt;n command verb: &amp;lt;&lt;/P&gt;&lt;P&gt;rb: &amp;lt;&lt;/P&gt;&lt;P&gt;ame: &lt;/P&gt;&lt;P&gt;e&amp;gt; Username: &lt;/P&gt;&lt;P&gt;Local_1&amp;gt; Username: &lt;/P&gt;&lt;P&gt;Local_1&amp;gt; Username: &lt;/P&gt;&lt;P&gt;Local_1&amp;gt; Username: &lt;/P&gt;&lt;P&gt;n command verb: &amp;lt;&lt;/P&gt;&lt;P&gt;nd verb: &amp;lt;USER&amp;gt;. &lt;/P&gt;&lt;P&gt;r: Unknown command verb: &amp;lt;USER&amp;gt;. &lt;/P&gt;&lt;P&gt;nd verb: &amp;lt;USER&amp;gt;. &lt;/P&gt;&lt;P&gt;ER&amp;gt;. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's the basic config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local line&lt;/P&gt;&lt;P&gt;aaa authentication login ACS group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;tacacs-server host A.B.C.D&lt;/P&gt;&lt;P&gt;tacacs-server host A.B.C.D&lt;/P&gt;&lt;P&gt;tacacs-server key 7 XXXXXXXXXXXXXXXXXXXXXXX&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help will be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:12:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/router-attempting-authentication-to-tacacs/m-p/1131702#M364612</guid>
      <dc:creator>ssarte123</dc:creator>
      <dc:date>2019-03-10T23:12:20Z</dc:date>
    </item>
    <item>
      <title>Re: Router Attempting Authentication to TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/router-attempting-authentication-to-tacacs/m-p/1131703#M364632</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Authentication, authorization, and accounting (AAA) network security services provide the primary framework through which you set up access control on your router or access server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See the following url for an example to configure Authentication, Authorization, and Accounting (AAA) on a Cisco router using Radius or TACACS+ protocols:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/tech/tk59/technologies_tech_note09186a0080093c81.shtml" target="_blank"&gt;http://www.cisco.com/en/US/tech/tk59/technologies_tech_note09186a0080093c81.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Also refer the url below for detailed information on AAA:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/ios/12_2/security/configuration/guide/scfathen.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/ios/12_2/security/configuration/guide/scfathen.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Dec 2008 15:45:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/router-attempting-authentication-to-tacacs/m-p/1131703#M364632</guid>
      <dc:creator>sadbulali</dc:creator>
      <dc:date>2008-12-01T15:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: Router Attempting Authentication to TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/router-attempting-authentication-to-tacacs/m-p/1131704#M364638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the link but I have AAA configured on many cisco routers and switches, but this one router seems to attempt logins which fail repeatedly according to my logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Dec 2008 15:58:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/router-attempting-authentication-to-tacacs/m-p/1131704#M364638</guid>
      <dc:creator>ssarte123</dc:creator>
      <dc:date>2008-12-01T15:58:41Z</dc:date>
    </item>
    <item>
      <title>Re: Router Attempting Authentication to TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/router-attempting-authentication-to-tacacs/m-p/1131705#M364645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per the configuration in router it clearly say's that for login it should prompt for tacas ser first,then local database and lastly lin vty.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Username should be configured in ACS and AAA client is also added in ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ganesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Dec 2008 05:45:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/router-attempting-authentication-to-tacacs/m-p/1131705#M364645</guid>
      <dc:creator>ganeshhiyer</dc:creator>
      <dc:date>2008-12-02T05:45:36Z</dc:date>
    </item>
  </channel>
</rss>

