<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS + Device Authorization Failure in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-device-authorization-failure/m-p/975832#M390223</link>
    <description>&lt;P&gt;Good Afternoon:&lt;/P&gt;&lt;P&gt;I hoping someone can help me out... I have an ACS configured with a group that is setup for admins.  This group is mapped to an AD group.  This is setup correctly.  On each network device are the commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can create a local user and place them into the aformentioned group and the TACACs authentication and authorization work fine.  However, I cannot use that same local group mapped to a AD group and a user in that group.  It passes authentication but I get an authorization failure in my logs (ACS) and a authorization failed message on the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 22:56:58 GMT</pubDate>
    <dc:creator>svanhandel</dc:creator>
    <dc:date>2019-03-10T22:56:58Z</dc:date>
    <item>
      <title>ACS + Device Authorization Failure</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-device-authorization-failure/m-p/975832#M390223</link>
      <description>&lt;P&gt;Good Afternoon:&lt;/P&gt;&lt;P&gt;I hoping someone can help me out... I have an ACS configured with a group that is setup for admins.  This group is mapped to an AD group.  This is setup correctly.  On each network device are the commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can create a local user and place them into the aformentioned group and the TACACs authentication and authorization work fine.  However, I cannot use that same local group mapped to a AD group and a user in that group.  It passes authentication but I get an authorization failure in my logs (ACS) and a authorization failed message on the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:56:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-device-authorization-failure/m-p/975832#M390223</guid>
      <dc:creator>svanhandel</dc:creator>
      <dc:date>2019-03-10T22:56:58Z</dc:date>
    </item>
    <item>
      <title>Re: ACS + Device Authorization Failure</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-device-authorization-failure/m-p/975833#M390225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ACS has extensive logging capabilities that allow an administrator to troubleshoot any issue pertaining to the ACS server itself (for example, replication) or an AAA request problem (for example, an authentication problem) from NAS. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refer the following url for more info on troubleshooting ACS:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1/user/A_Trble.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1/user/A_Trble.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Jul 2008 16:42:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-device-authorization-failure/m-p/975833#M390225</guid>
      <dc:creator>hadbou</dc:creator>
      <dc:date>2008-07-07T16:42:06Z</dc:date>
    </item>
  </channel>
</rss>

