<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Secure ACS 4.1 and different routers in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/secure-acs-4-1-and-different-routers/m-p/1021320#M385956</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just a clarification...&lt;/P&gt;&lt;P&gt;We are using 2811 and 2801 at remote locations and have been trying to use the tacacs-server options as well.  Are you saying that we need to configure it as a radius-server even if we are only using the tacacs options?&lt;/P&gt;&lt;P&gt;I just want to make sure prior to delving into radius as we have not used that at all since we are only communicating between routers for multi user authentication.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon Gauntt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 Apr 2008 19:34:28 GMT</pubDate>
    <dc:creator>JonGauntt</dc:creator>
    <dc:date>2008-04-09T19:34:28Z</dc:date>
    <item>
      <title>Secure ACS 4.1 and different routers</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-4-1-and-different-routers/m-p/1021318#M385954</link>
      <description>&lt;P&gt;Are the commands different from router to router?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is what I currently have:&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization exec default if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;tacacs-server host 172.16.6.3&lt;/P&gt;&lt;P&gt;tacacs-server host 172.16.16.3&lt;/P&gt;&lt;P&gt;tacacs-server timeout 60&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;tacacs-server key xxxxxxxxxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It works on my 2621's like a charm but my 2811's it won't allow my to login in as my domain account just the backup local account I have. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am a rookie to this so please be gentle. Thanks in advance for any help you can give me...&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:46:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-4-1-and-different-routers/m-p/1021318#M385954</guid>
      <dc:creator>dgerbergss</dc:creator>
      <dc:date>2019-03-10T22:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ACS 4.1 and different routers</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-4-1-and-different-routers/m-p/1021319#M385955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes they are diffrent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example: &lt;/P&gt;&lt;P&gt;tacacs-server host 1.5.3.2 key cisco_key&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;radius-server source-ports 1645-1646&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regadrs Jan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Apr 2008 06:19:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-4-1-and-different-routers/m-p/1021319#M385955</guid>
      <dc:creator>Jan Rockstedt</dc:creator>
      <dc:date>2008-04-09T06:19:49Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ACS 4.1 and different routers</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-4-1-and-different-routers/m-p/1021320#M385956</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just a clarification...&lt;/P&gt;&lt;P&gt;We are using 2811 and 2801 at remote locations and have been trying to use the tacacs-server options as well.  Are you saying that we need to configure it as a radius-server even if we are only using the tacacs options?&lt;/P&gt;&lt;P&gt;I just want to make sure prior to delving into radius as we have not used that at all since we are only communicating between routers for multi user authentication.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon Gauntt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Apr 2008 19:34:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-4-1-and-different-routers/m-p/1021320#M385956</guid>
      <dc:creator>JonGauntt</dc:creator>
      <dc:date>2008-04-09T19:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ACS 4.1 and different routers</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-4-1-and-different-routers/m-p/1021321#M385957</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In layer 3 devices we also need to define tacacs source interface so that it uses only that interface for sending tacacs request to acs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AAA-Switch(config)#ip tacacs source-interface (vlan or loopback or gigabit interface)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In above command we need to define the interface that is listed in acs---&amp;gt;network configuration---&amp;gt;Router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you have any question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Apr 2008 20:09:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-4-1-and-different-routers/m-p/1021321#M385957</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-04-09T20:09:06Z</dc:date>
    </item>
  </channel>
</rss>

