<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TACACS Authentication issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-issue/m-p/2962230#M38774</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi Cisco,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Good day!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Need your help on my problem,&amp;nbsp;&lt;SPAN&gt;the problem is that a switch that we are trying to integrate to ACS can't&amp;nbsp;authenticate via TACACS.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;based on our testing and troubleshooting, the ACS before config is Single connect device and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;TACACS+ Draft Compliant Single Connect Support is chosen. but when trying to change the configuration to Legacy TACACS + Single Connect support it works fine.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Question: what is the standard&amp;nbsp;procedure for enrollment 1 or 2 (See below) ? what is the different?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. Single connect Device and TACACAS + Draft Compliant Single Connect Support&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;or&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. Just Legacy TACACS + Single Connect Support&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Mar 2019 00:35:02 GMT</pubDate>
    <dc:creator>Erland Medrano</dc:creator>
    <dc:date>2019-03-26T00:35:02Z</dc:date>
    <item>
      <title>TACACS Authentication issue</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-issue/m-p/2962230#M38774</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi Cisco,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Good day!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Need your help on my problem,&amp;nbsp;&lt;SPAN&gt;the problem is that a switch that we are trying to integrate to ACS can't&amp;nbsp;authenticate via TACACS.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;based on our testing and troubleshooting, the ACS before config is Single connect device and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;TACACS+ Draft Compliant Single Connect Support is chosen. but when trying to change the configuration to Legacy TACACS + Single Connect support it works fine.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Question: what is the standard&amp;nbsp;procedure for enrollment 1 or 2 (See below) ? what is the different?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. Single connect Device and TACACAS + Draft Compliant Single Connect Support&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;or&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. Just Legacy TACACS + Single Connect Support&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:35:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-issue/m-p/2962230#M38774</guid>
      <dc:creator>Erland Medrano</dc:creator>
      <dc:date>2019-03-26T00:35:02Z</dc:date>
    </item>
    <item>
      <title>Hi Erland,</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-issue/m-p/2962231#M38775</link>
      <description>&lt;P&gt;Hi Erland,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The difference between&amp;nbsp;&lt;SPAN&gt;Single connect Device and TACACAS + Draft Compliant Single Connect Support OR&amp;nbsp;Legacy TACACS + Single Connect Support is former will send single connect flag to the NAS and latter will not send the single connect flag to NAS device.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You can also refer this draft for better understanding,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;http://tools.ietf.org/html/draft-grant-tacacs-02&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2016 14:09:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-issue/m-p/2962231#M38775</guid>
      <dc:creator>karans</dc:creator>
      <dc:date>2016-08-11T14:09:30Z</dc:date>
    </item>
    <item>
      <title>thanks for verification </title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-issue/m-p/2962232#M38776</link>
      <description>&lt;P&gt;thanks for verification&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 09:23:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-issue/m-p/2962232#M38776</guid>
      <dc:creator>Erland Medrano</dc:creator>
      <dc:date>2016-08-24T09:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: Hi Erland,</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-issue/m-p/3385763#M38777</link>
      <description>&lt;P&gt;Any recommended best practices for this setting?&lt;/P&gt;</description>
      <pubDate>Fri, 18 May 2018 20:34:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-issue/m-p/3385763#M38777</guid>
      <dc:creator>kevink707</dc:creator>
      <dc:date>2018-05-18T20:34:37Z</dc:date>
    </item>
  </channel>
</rss>

