<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: enable Mode authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/enable-mode-authentication/m-p/930014#M396635</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sorry for the late reply, i was busy in other stuff, regarding cisco catalyst switches command authorization is working, but for cisco pix firewall, it is not working,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wanted to apply the same command set for junior admin of firewall, that i m using for switches, but it is not working for me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;firewall only allowing full access to admin, but not allowing junior to do anything, not even show,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have atacched the screen shots for your review and firewall aaa configuration, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TDC-INT-525-01&amp;gt; enable&lt;/P&gt;&lt;P&gt;Command authorization failed&lt;/P&gt;&lt;P&gt;TDC-INT-525-01&amp;gt; show aaa&lt;/P&gt;&lt;P&gt;                     ^&lt;/P&gt;&lt;P&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;&lt;P&gt;TDC-INT-525-01&amp;gt; show xlate&lt;/P&gt;&lt;P&gt;                     ^&lt;/P&gt;&lt;P&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;&lt;P&gt;TDC-INT-525-01&amp;gt; enable&lt;/P&gt;&lt;P&gt;Command authorization failed&lt;/P&gt;&lt;P&gt;TDC-INT-525-01&amp;gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ (edn) host 172.28.31.132&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ (edn) host 172.28.31.133&lt;/P&gt;&lt;P&gt;aaa authentication ssh console TACACS+ LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication serial console LOCAL &lt;/P&gt;&lt;P&gt;aaa authentication enable console TACACS+ LOCAL&lt;/P&gt;&lt;P&gt;aaa authorization command TACACS+ &lt;/P&gt;&lt;P&gt;aaa accounting command privilege 15 TACACS+&lt;/P&gt;&lt;P&gt;aaa accounting enable console TACACS+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 19 May 2008 10:24:12 GMT</pubDate>
    <dc:creator>wasiimcisco</dc:creator>
    <dc:date>2008-05-19T10:24:12Z</dc:date>
    <item>
      <title>enable Mode authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-authentication/m-p/930008#M396629</link>
      <description>&lt;P&gt;I am not able to configure the enable mode authentication, I have set the ACS user password in Tacac+option tab.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and configure the device for enable mode authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacasc+ &lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization config-commands &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs+ &lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+ &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But still after login user only able to enter in enable mode by giving locally configured password, not the password that configured in ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help me out how to configure the device that both login and enable authentication controlled by ACS. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:50:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-authentication/m-p/930008#M396629</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2019-03-10T22:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: enable Mode authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-authentication/m-p/930009#M396630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wasim ,&lt;/P&gt;&lt;P&gt;This is what you need to to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bring users/groups in at level 15&lt;/P&gt;&lt;P&gt;	1.  Go to user or group setup in ACS&lt;/P&gt;&lt;P&gt;	2.  Drop down to "TACACS+ Settings"&lt;/P&gt;&lt;P&gt;	3.  Place a check in "Shell (Exec)"&lt;/P&gt;&lt;P&gt;	4.  Place a check in "Privilege level" and enter "15" in the adjacent field&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 May 2008 23:29:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-authentication/m-p/930009#M396630</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-05-12T23:29:55Z</dc:date>
    </item>
    <item>
      <title>Re: enable Mode authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-authentication/m-p/930010#M396631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did the same thing that u asked me to do, but now user is directly going to the privilage mode, no enable authenication required and no requiring any enable password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though i have set the enable password in ACS user TACACS+ Enable Password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But device is not requiring any password for enable mode. below mention is the command that i configured on the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacasc+ &lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization config-commands &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs+ &lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+ &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 May 2008 10:37:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-authentication/m-p/930010#M396631</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2008-05-13T10:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: enable Mode authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-authentication/m-p/930011#M396632</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please get debug tacacs and debug aaa authentication output.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 May 2008 11:40:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-authentication/m-p/930011#M396632</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-05-13T11:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: enable Mode authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-authentication/m-p/930012#M396633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kindly see attachement for debug of my device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I applied the same configuration that you sent me and turn on the debug &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug aaa authentication &lt;/P&gt;&lt;P&gt;debug tacacs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but still the user is not requiring any enable password, only login username and password required.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PDC-Srv-3750-1#sh debug&lt;/P&gt;&lt;P&gt;General OS:&lt;/P&gt;&lt;P&gt;  TACACS+ authentication debugging is on&lt;/P&gt;&lt;P&gt;  AAA Authentication debugging is on&lt;/P&gt;&lt;P&gt;PDC-Srv-3750-1#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 May 2008 07:59:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-authentication/m-p/930012#M396633</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2008-05-14T07:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: enable Mode authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-authentication/m-p/930013#M396634</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do we have tacacs single connect enabled on acs ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Normally if the command authorization fails due to ACS misconfig - its says&lt;/P&gt;&lt;P&gt;"% Command Authorization Failed".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is a known behavior that the IOS sometimes sends requests with wrong source IP when we are using tacacs single-connect option. And since it is sending the wrong source IP, first of all ACS doesn't recognize this IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And we do not want directed-request either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACTION PLAN:&lt;/P&gt;&lt;P&gt;Please disable the single-connect option and change the config to:&lt;/P&gt;&lt;P&gt;	no tacacs-server host x.x.x.x single-connection&lt;/P&gt;&lt;P&gt;	no tacacs-server directed-request&lt;/P&gt;&lt;P&gt;	no tacacs-server key 7 06260D2A1F575D392653&lt;/P&gt;&lt;P&gt;	tacacs-server host x.x.x.x key 7 06260D2A1F5&lt;/P&gt;&lt;P&gt;	ip tacacs source-interface Loopback0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Define source interface for tacacs authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On router issue command,&lt;/P&gt;&lt;P&gt;ip tacacs source-interface fastethernet x/y , where interface would be the one mentioned in tacacs server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If still issue is there then pls send full running config along with following debug&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug aaa authen&lt;/P&gt;&lt;P&gt;debug aaa author&lt;/P&gt;&lt;P&gt;debug tacacs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 May 2008 12:12:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-authentication/m-p/930013#M396634</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-05-14T12:12:50Z</dc:date>
    </item>
    <item>
      <title>Re: enable Mode authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-authentication/m-p/930014#M396635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sorry for the late reply, i was busy in other stuff, regarding cisco catalyst switches command authorization is working, but for cisco pix firewall, it is not working,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wanted to apply the same command set for junior admin of firewall, that i m using for switches, but it is not working for me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;firewall only allowing full access to admin, but not allowing junior to do anything, not even show,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have atacched the screen shots for your review and firewall aaa configuration, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TDC-INT-525-01&amp;gt; enable&lt;/P&gt;&lt;P&gt;Command authorization failed&lt;/P&gt;&lt;P&gt;TDC-INT-525-01&amp;gt; show aaa&lt;/P&gt;&lt;P&gt;                     ^&lt;/P&gt;&lt;P&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;&lt;P&gt;TDC-INT-525-01&amp;gt; show xlate&lt;/P&gt;&lt;P&gt;                     ^&lt;/P&gt;&lt;P&gt;ERROR: % Invalid input detected at '^' marker.&lt;/P&gt;&lt;P&gt;TDC-INT-525-01&amp;gt; enable&lt;/P&gt;&lt;P&gt;Command authorization failed&lt;/P&gt;&lt;P&gt;TDC-INT-525-01&amp;gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ (edn) host 172.28.31.132&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ (edn) host 172.28.31.133&lt;/P&gt;&lt;P&gt;aaa authentication ssh console TACACS+ LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication serial console LOCAL &lt;/P&gt;&lt;P&gt;aaa authentication enable console TACACS+ LOCAL&lt;/P&gt;&lt;P&gt;aaa authorization command TACACS+ &lt;/P&gt;&lt;P&gt;aaa accounting command privilege 15 TACACS+&lt;/P&gt;&lt;P&gt;aaa accounting enable console TACACS+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 May 2008 10:24:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-authentication/m-p/930014#M396635</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2008-05-19T10:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: enable Mode authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-authentication/m-p/930015#M396636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wasim,&lt;/P&gt;&lt;P&gt;I don't see enable keyword defined in the command authorization set.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please add "enable" along with show and clear in the "command authorization setup".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That should fix it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 May 2008 14:20:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-authentication/m-p/930015#M396636</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-05-19T14:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: enable Mode authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-authentication/m-p/930016#M396637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for the help, it works like a magic, now i am able to restrict the users, &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 May 2008 17:24:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-authentication/m-p/930016#M396637</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2008-05-19T17:24:05Z</dc:date>
    </item>
    <item>
      <title>Re: enable Mode authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-authentication/m-p/930017#M396638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have pix 535, i want to configure it for ACS authentication, but problem is that, users tries to login from inside interface and ACS located on outside interface of pix firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured the following commands but still not able to get the authentication, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ (inside) host 172.28.31.132 waridtel0321&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ (inside) host 172.28.31.133 waridtel0321&lt;/P&gt;&lt;P&gt;aaa authentication ssh console TACACS+ LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication serial console LOCAL &lt;/P&gt;&lt;P&gt;aaa authentication enable console TACACS+ LOCAL&lt;/P&gt;&lt;P&gt;aaa authorization command TACACS+ &lt;/P&gt;&lt;P&gt;aaa accounting command privilege 15 TACACS+&lt;/P&gt;&lt;P&gt;aaa accounting enable console TACACS+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same configuration is working fine for me with rest of the firewalls of my network bcz ACS and users are located on the same interface side, only this firewall is having problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall is not having any thing like source interface like routers have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help me out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 May 2008 12:07:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-authentication/m-p/930017#M396638</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2008-05-20T12:07:01Z</dc:date>
    </item>
  </channel>
</rss>

