<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA problem in ASA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-problem-in-asa/m-p/1075255#M365021</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;tried doing the same but that also doesnt helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do i need to give:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa accounting command privilege 15 tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to make it privelege 15&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 Oct 2008 19:32:13 GMT</pubDate>
    <dc:creator>piyush_singh</dc:creator>
    <dc:date>2008-10-14T19:32:13Z</dc:date>
    <item>
      <title>AAA problem in ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem-in-asa/m-p/1075253#M365019</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had configured tacacs on ASA but the problem is when i m trying to telnet it it authenticates me with my username &amp;amp; password on ACS but i cant move onto privilege level 15 as configured on ACS. Its asking me for enable password n not taking the password that is on ACS. I have used Shell Authorization for privilege 15. The configuration done on ASA is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;name 172.30.xx.xx ACS-1&lt;/P&gt;&lt;P&gt;name 172.30.yy.yy ACS-2&lt;/P&gt;&lt;P&gt;aaa-server tacacs+ protocol tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server tacacs+  host ACS-1&lt;/P&gt;&lt;P&gt;key cisco&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;aaa-server tacacs+  host ACS-2&lt;/P&gt;&lt;P&gt;key cisco&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication telnet console tacacs+ LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication telnet console tacacs+ tacacs+&lt;/P&gt;&lt;P&gt;aaa authentication ssh console tacacs+ LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication enable console tacacs+ LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;enable password V3VzjwYzTRfTLwOb encrypted&lt;/P&gt;&lt;P&gt;enable password V3VzjwYzTRfTLwOb encrypted&lt;/P&gt;&lt;P&gt;username piyush password vkCzRtKCaNG.HI6s encrypted privilege 15&lt;/P&gt;&lt;P&gt;username ideanoc password S0qrUlXOHFcX7LCw encrypted privilege 15&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even added my username &amp;amp; password in local database on ASA as on ACS. Still no progress....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can any one give his suggestion on the same.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Piyush&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:08:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem-in-asa/m-p/1075253#M365019</guid>
      <dc:creator>piyush_singh</dc:creator>
      <dc:date>2019-03-10T23:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: AAA problem in ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem-in-asa/m-p/1075254#M365020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Piyush,&lt;/P&gt;&lt;P&gt;ASA do not support exec authorization so you will not fall directly in enable mode the way we do on routers/switches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.ciscotaccc.com/security/showcase?case=K25224726" target="_blank"&gt;http://www.ciscotaccc.com/security/showcase?case=K25224726&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it should let you in using enable password. In acs user set up make sure you have enable password defined and you are using that password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;user set up Edit ---&amp;gt;TACACS+ Enable Password and choose option as per your need.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Oct 2008 18:09:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem-in-asa/m-p/1075254#M365020</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-10-14T18:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: AAA problem in ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem-in-asa/m-p/1075255#M365021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;tried doing the same but that also doesnt helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do i need to give:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa accounting command privilege 15 tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to make it privelege 15&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Oct 2008 19:32:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem-in-asa/m-p/1075255#M365021</guid>
      <dc:creator>piyush_singh</dc:creator>
      <dc:date>2008-10-14T19:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: AAA problem in ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem-in-asa/m-p/1075256#M365022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No that command is for accounting. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure you have Max Privilege for any AAA Client is set to 15 in acs group setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do we get any error in failed attempts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Oct 2008 19:55:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem-in-asa/m-p/1075256#M365022</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-10-14T19:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: AAA problem in ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem-in-asa/m-p/1075257#M365023</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ya all that is done level 15 is set in Shell (exec) in group setup &amp;amp; also in Shell Command Authorization Set provided full access...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;N i cant find any logs in failed attempts, but can see authentication passed in passed authentication logs..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The link which you had posted is for IOS ver 7.x but i m using 8.0(3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Piyush&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Oct 2008 20:22:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem-in-asa/m-p/1075257#M365023</guid>
      <dc:creator>piyush_singh</dc:creator>
      <dc:date>2008-10-14T20:22:23Z</dc:date>
    </item>
    <item>
      <title>Re: AAA problem in ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem-in-asa/m-p/1075258#M365024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what i m getting on telnet is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User Access Verification&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Username: piyush&lt;/P&gt;&lt;P&gt;Password: **********&lt;/P&gt;&lt;P&gt;Type help or '?' for a list of available commands.&lt;/P&gt;&lt;P&gt;ICL-PUN-PRIDC1-MPLS-5550ASA1&amp;gt; en&lt;/P&gt;&lt;P&gt;Password: **********&lt;/P&gt;&lt;P&gt;Password: **********&lt;/P&gt;&lt;P&gt;Password: **********&lt;/P&gt;&lt;P&gt;Access denied.&lt;/P&gt;&lt;P&gt;ICL-PUN-PRIDC1-MPLS-5550ASA1&amp;gt;&lt;/P&gt;&lt;P&gt;ICL-PUN-PRIDC1-MPLS-5550ASA1&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this might give you some idea.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Oct 2008 20:25:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem-in-asa/m-p/1075258#M365024</guid>
      <dc:creator>piyush_singh</dc:creator>
      <dc:date>2008-10-14T20:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: AAA problem in ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem-in-asa/m-p/1075259#M365025</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not asking for shell priv level 15 but enable privilege. That should be set to 15 in acs---&amp;gt;user set up ----&amp;gt; enable options---&amp;gt; Max Privilege for any AAA Client--&amp;gt;15&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Oct 2008 20:31:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem-in-asa/m-p/1075259#M365025</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-10-14T20:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: AAA problem in ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-problem-in-asa/m-p/1075260#M365026</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;oh got that.... n that worked man... thanks a lot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Oct 2008 20:46:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-problem-in-asa/m-p/1075260#M365026</guid>
      <dc:creator>piyush_singh</dc:creator>
      <dc:date>2008-10-14T20:46:11Z</dc:date>
    </item>
  </channel>
</rss>

