<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic There is no special config on in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-fallback-issue-to-local-database/m-p/2891873#M36535</link>
    <description>&lt;P&gt;There is no special config on line con 0.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The tacacs server timeout is set to 5 seconds as below:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;tacacs-server host 192.168.1.1 timeout 5&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;tacacs-server host 192.168.1.2 timeout 5&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I was not able&amp;nbsp;to&amp;nbsp;login therefore was not able to turn on debugging.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 25 Apr 2016 07:50:56 GMT</pubDate>
    <dc:creator>m.reay</dc:creator>
    <dc:date>2016-04-25T07:50:56Z</dc:date>
    <item>
      <title>aaa fallback issue to local database</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-fallback-issue-to-local-database/m-p/2891870#M36530</link>
      <description>&lt;P&gt;!&lt;BR /&gt;!&lt;BR /&gt;username Fred privilege 15 password xxxxxxxxxxx&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa group server tacacs+ TacacsSvrGP1&lt;BR /&gt; server-private 192.168.1.1&lt;BR /&gt; server-private 192.168.1.2&lt;/P&gt;
&lt;P&gt;!&lt;BR /&gt;aaa authentication login default group TacacsSvrGP1 local&lt;BR /&gt;aaa authentication enable default group TacacsSvrGP1 enable&lt;BR /&gt;aaa accounting exec default start-stop group tacacs+&lt;BR /&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;BR /&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;BR /&gt;aaa accounting system default start-stop group tacacs+&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;tacacs-server host 192.168.1.1 timeout 5&lt;BR /&gt;tacacs-server host 192.168.1.2 timeout 5&lt;BR /&gt;tacacs-server directed-request&lt;BR /&gt;tacacs-server key 7 xxxxxxxxxx&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;I applied the above configuration to a Cisco 3850 switch not connected to the network.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Because the switch could not contact the tacacs server I was expecting a prompt to allow me to login &amp;nbsp;as Fred to using authentication via the local database, however I experienced the following:&lt;/P&gt;
&lt;P&gt;When accessing via con 0 using a terminal emulator - the screen looped&amp;nbsp;between the message of the day banner and the&amp;nbsp;"Press Enter to proceed" message.&lt;BR /&gt;The Username/Password prompts failed to appear and I was unable to log into the device.&lt;/P&gt;
&lt;P&gt;At the same time I received a "Network error: Connection refused" message - again no Username/Password prompts when attempting SSH access.&lt;/P&gt;
&lt;P&gt;Reducing the tacacs timeout to 3 seconds did present the Username/Password prompts however access was extremely erratic - with a 60 &lt;BR /&gt;second delay between prompts being displayed.&lt;/P&gt;
&lt;P&gt;This behaviour was the same using both Putty and Hyperterminal.&lt;/P&gt;
&lt;P&gt;Also the issue was intermittent ie after a certain period of time I was able to login, however after a further period of time the &lt;BR /&gt;problem reappeared.&lt;/P&gt;
&lt;P&gt;I initially thought the problem was peculiar to the 3850, however I also saw it on a Cisco 2960.&lt;/P&gt;
&lt;P&gt;It appears that there is an issue with failing back to the local database when there is no tacacs server available.&lt;/P&gt;
&lt;P&gt;It is conceivable that once the devices are connected to the network, they will be able to connect to tacacs and access to the switches will occur, however&amp;nbsp;I am concerned that if the tacacs servers are unreachable, no one will be able to access the devices with a local account in order to carry out configuration or&amp;nbsp;troubleshooting.&lt;/P&gt;
&lt;P&gt;Has anyone come across this issue?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:42:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-fallback-issue-to-local-database/m-p/2891870#M36530</guid>
      <dc:creator>m.reay</dc:creator>
      <dc:date>2019-03-11T06:42:00Z</dc:date>
    </item>
    <item>
      <title>Have you set a deadtime for</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-fallback-issue-to-local-database/m-p/2891871#M36531</link>
      <description>&lt;P&gt;Have you set a deadtime for the tacacs server ? Otherwise the switch will just try to use it again, straight after it has determined that the tacacs server is down.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2016 17:28:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-fallback-issue-to-local-database/m-p/2891871#M36531</guid>
      <dc:creator>jan.nielsen</dc:creator>
      <dc:date>2016-04-22T17:28:47Z</dc:date>
    </item>
    <item>
      <title>With 3 seconds timeout and 3</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-fallback-issue-to-local-database/m-p/2891872#M36532</link>
      <description>&lt;P&gt;With 3 seconds timeout and 3 retries, the max delay you should see is 18 seconds - 9 seconds delay per server. Did you try to run 'debug tacacs' and 'debug aaa authentication' to understand why it's taking 60 seconds to prompt you a username / password. Do we have any special config on line con 0 ?&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Regards,&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Jatin&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Do rate helpful posts !&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Apr 2016 07:45:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-fallback-issue-to-local-database/m-p/2891872#M36532</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2016-04-23T07:45:35Z</dc:date>
    </item>
    <item>
      <title>There is no special config on</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-fallback-issue-to-local-database/m-p/2891873#M36535</link>
      <description>&lt;P&gt;There is no special config on line con 0.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The tacacs server timeout is set to 5 seconds as below:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;tacacs-server host 192.168.1.1 timeout 5&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;tacacs-server host 192.168.1.2 timeout 5&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I was not able&amp;nbsp;to&amp;nbsp;login therefore was not able to turn on debugging.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2016 07:50:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-fallback-issue-to-local-database/m-p/2891873#M36535</guid>
      <dc:creator>m.reay</dc:creator>
      <dc:date>2016-04-25T07:50:56Z</dc:date>
    </item>
    <item>
      <title>Tacacs timeout is as below:</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-fallback-issue-to-local-database/m-p/2891874#M36537</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Tacacs timeout is as below:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;tacacs-server host 192.168.1.1 timeout 5&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;tacacs-server host 192.168.1.2 timeout 5&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2016 07:51:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-fallback-issue-to-local-database/m-p/2891874#M36537</guid>
      <dc:creator>m.reay</dc:creator>
      <dc:date>2016-04-25T07:51:42Z</dc:date>
    </item>
    <item>
      <title>Hello,I don't know if that</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-fallback-issue-to-local-database/m-p/2891875#M36541</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I don't know if that helps, but try adding&lt;BR /&gt;&lt;BR /&gt;aaa authorization config-commands&lt;BR /&gt;aaa authorization exec default group &lt;SPAN&gt;TacacsSvrGP1&lt;/SPAN&gt; local&lt;BR /&gt;aaa authorization commands 0 default local group &lt;SPAN&gt;TacacsSvrGP1&lt;/SPAN&gt;&lt;BR /&gt;aaa authorization commands 1 default local group &lt;SPAN&gt;TacacsSvrGP1&lt;/SPAN&gt;&lt;BR /&gt;aaa authorization commands 15 default local group &lt;SPAN&gt;TacacsSvrGP1&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;or a variation of this to your config.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;I think you are missing authorization options in your config, so the system doesn't know what the user you try to login is allowed to do.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2016 12:32:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-fallback-issue-to-local-database/m-p/2891875#M36541</guid>
      <dc:creator>Maximilian Usinger</dc:creator>
      <dc:date>2016-04-25T12:32:59Z</dc:date>
    </item>
  </channel>
</rss>

