<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tacacs+ authentication errors in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-errors/m-p/1019553#M396660</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did match all the keys, but just tried deleting the NDG key and retest and got the same results. Switch comes back with % Backup authentication.&lt;/P&gt;&lt;P&gt;Also note that in the failed attempts report, I can change the keys, so they don't match, and get an Authentication Failed key mismatch entry in the report. When the keys match there is no entry in the failed attempts report and no entry in the passed authentications report. Tacacs+ accounting report shows an entry for the username I am using and shows start acct flag and service shell.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 09 May 2008 14:31:12 GMT</pubDate>
    <dc:creator>dguse</dc:creator>
    <dc:date>2008-05-09T14:31:12Z</dc:date>
    <item>
      <title>Tacacs+ authentication errors</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-errors/m-p/1019551#M396658</link>
      <description>&lt;P&gt;I am having problems getting TACACS+ AAA working with my 3560 switches. I have set up users, groups, and NDG on ACS SE as per the CS ACS course material and have triple checked my keys to make sure they match. I have attached debug from switch for authentication, authorization and tacacs+. Can someone please tell me what I am doing wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:50:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-errors/m-p/1019551#M396658</guid>
      <dc:creator>dguse</dc:creator>
      <dc:date>2019-03-10T22:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs+ authentication errors</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-errors/m-p/1019552#M396659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This seems to be a key mismatch. Please note that if you have NDG key also configured that can cause key mismatch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Imp: NDG key overwrites aaa-client key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please use the same key for NDG and client or simply remove the NDG key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 May 2008 13:36:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-errors/m-p/1019552#M396659</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-05-09T13:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs+ authentication errors</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-errors/m-p/1019553#M396660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did match all the keys, but just tried deleting the NDG key and retest and got the same results. Switch comes back with % Backup authentication.&lt;/P&gt;&lt;P&gt;Also note that in the failed attempts report, I can change the keys, so they don't match, and get an Authentication Failed key mismatch entry in the report. When the keys match there is no entry in the failed attempts report and no entry in the passed authentications report. Tacacs+ accounting report shows an entry for the username I am using and shows start acct flag and service shell.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 May 2008 14:31:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-errors/m-p/1019553#M396660</guid>
      <dc:creator>dguse</dc:creator>
      <dc:date>2008-05-09T14:31:12Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs+ authentication errors</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-errors/m-p/1019554#M396662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In layer 3 devices, other then normal aaa commands, we also need to define tacacs source interface so that it uses only that interface for sending tacacs request to acs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AAA-Switch(config)#ip tacacs source-interface (vlan or loopback or gigabit interface)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In above command we need to define the interface that is listed in acs---&amp;gt;network configuration---&amp;gt;Router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 May 2008 14:48:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-errors/m-p/1019554#M396662</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-05-09T14:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs+ authentication errors</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-errors/m-p/1019555#M396663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the config I have on the switch. (sorry should have sent this already).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ none&lt;/P&gt;&lt;P&gt;aaa authentication login no_aaa none&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ none&lt;/P&gt;&lt;P&gt;aaa authorization exec no_aaa none&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs+ none&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ none&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 no_aaa none&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface VLAN1&lt;/P&gt;&lt;P&gt; ip address 10.200.1.16 255.255.255.0&lt;/P&gt;&lt;P&gt; no ip directed-broadcast&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip tacacs source-interface VLAN1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;tacacs-server host 10.200.35.250&lt;/P&gt;&lt;P&gt;tacacs-server key cisco&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt; authorization commands 15 no_aaa&lt;/P&gt;&lt;P&gt; authorization exec no_aaa&lt;/P&gt;&lt;P&gt; login authentication no_aaa&lt;/P&gt;&lt;P&gt; transport input none&lt;/P&gt;&lt;P&gt; stopbits 1&lt;/P&gt;&lt;P&gt;line vty 5 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 May 2008 15:19:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-errors/m-p/1019555#M396663</guid>
      <dc:creator>dguse</dc:creator>
      <dc:date>2008-05-09T15:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs+ authentication errors</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-errors/m-p/1019556#M396665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any other ideas? &lt;/P&gt;&lt;P&gt;As a test, I set up a Windows server and installed ACS 4.1(2) Build 23 on it. Put same config as on SE and it works. I have checked the config on both the Windows and the SE and they are the same from what I can tell.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 May 2008 12:49:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-errors/m-p/1019556#M396665</guid>
      <dc:creator>dguse</dc:creator>
      <dc:date>2008-05-15T12:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs+ authentication errors</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-errors/m-p/1019557#M396667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have dual NIC on acs windows ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 May 2008 14:28:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-errors/m-p/1019557#M396667</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-05-15T14:28:31Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs+ authentication errors</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-errors/m-p/1019558#M396668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, but I am only using one. We have fully tested Radius and Tacacs+ on the Windows ACS and everything is working perfectly. Can't figure out why the SE's will not.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 May 2008 10:33:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-errors/m-p/1019558#M396668</guid>
      <dc:creator>dguse</dc:creator>
      <dc:date>2008-05-16T10:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs+ authentication errors</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-errors/m-p/1019559#M396669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ohh, so its SE that is not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do this, ACS---&amp;gt;Network configuration====&amp;gt;Proxy Dis table---&amp;gt;Click on default====&amp;gt; If you see delivenrance 1 in aaa server----&amp;gt; Drag it to "Forward to" ---&amp;gt;And whatever is there under forward to ---&amp;gt;Drag it to aaa-server--&amp;gt;submit+apply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It should work now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you don't see proxy distribution option then go to acs---&amp;gt;interface configuration-----&amp;gt;advanced option ----&amp;gt;enable distributed table.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 17 May 2008 11:54:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-errors/m-p/1019559#M396669</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2008-05-17T11:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs+ authentication errors</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-errors/m-p/1019560#M396670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That did it!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Darren&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 May 2008 11:05:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-errors/m-p/1019560#M396670</guid>
      <dc:creator>dguse</dc:creator>
      <dc:date>2008-05-19T11:05:06Z</dc:date>
    </item>
  </channel>
</rss>

