<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX - AAA authorization with TACACS+ Server in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/pix-aaa-authorization-with-tacacs-server/m-p/925681#M402234</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply. I only tried with general AAA commands, not with source/destination address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just need to know what could be the mistake in my configurations and why it did not authenticate/authorize with my tacacs server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 11 Mar 2008 18:15:23 GMT</pubDate>
    <dc:creator>pemasirid</dc:creator>
    <dc:date>2008-03-11T18:15:23Z</dc:date>
    <item>
      <title>PIX - AAA authorization with TACACS+ Server</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-aaa-authorization-with-tacacs-server/m-p/925679#M402214</link>
      <description>&lt;P&gt;I configured AAA authorization in the my firewall but it works only for local username/password. PIX version 7.2(2) and ACS-SE 4.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following are the steps I did.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Configure AAA on PIX (attached)&lt;/P&gt;&lt;P&gt;2. Add PIX as AAA Client in ACS and selected as TACACS &lt;/P&gt;&lt;P&gt;3. Other setting in ACS as attached&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: Also I have RADIUS as same ACS for my VPN access and I add it as RADIUS client with different key.Moreover I could not see any failed logs on ACS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone tell me why I cant authenticate and authorize with TACACS+ server. Please advise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:42:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-aaa-authorization-with-tacacs-server/m-p/925679#M402214</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2019-03-10T22:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: PIX - AAA authorization with TACACS+ Server</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-aaa-authorization-with-tacacs-server/m-p/925680#M402220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you tried including commands to identify the type of traffic to be authenticated?  Something along the lines of:&lt;/P&gt;&lt;P&gt;aaa authentication include telnet &lt;INTERFACE_NAME&gt; &lt;SOURCE_ADDRESS&gt; &lt;SOURCE_MASK&gt; &lt;DESTINATION_HOST&gt; &lt;DESTINATION_MASK&gt; my-group&lt;/DESTINATION_MASK&gt;&lt;/DESTINATION_HOST&gt;&lt;/SOURCE_MASK&gt;&lt;/SOURCE_ADDRESS&gt;&lt;/INTERFACE_NAME&gt;&lt;/P&gt;&lt;P&gt;aaa authorization include telnet &lt;INTERFACE_NAME&gt; &lt;SOURCE_ADDRESS&gt; &lt;SOURCE_MASK&gt; &lt;DESTINATION_HOST&gt; &lt;DESTINATION_MASK&gt; my-group&lt;/DESTINATION_MASK&gt;&lt;/DESTINATION_HOST&gt;&lt;/SOURCE_MASK&gt;&lt;/SOURCE_ADDRESS&gt;&lt;/INTERFACE_NAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 14:58:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-aaa-authorization-with-tacacs-server/m-p/925680#M402220</guid>
      <dc:creator>artegall1</dc:creator>
      <dc:date>2008-03-11T14:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: PIX - AAA authorization with TACACS+ Server</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-aaa-authorization-with-tacacs-server/m-p/925681#M402234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply. I only tried with general AAA commands, not with source/destination address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just need to know what could be the mistake in my configurations and why it did not authenticate/authorize with my tacacs server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Mar 2008 18:15:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-aaa-authorization-with-tacacs-server/m-p/925681#M402234</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2008-03-11T18:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: PIX - AAA authorization with TACACS+ Server</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-aaa-authorization-with-tacacs-server/m-p/925682#M402245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.aaa authentication telnet console my-group LOCAL&lt;/P&gt;&lt;P&gt;  aaa authentication enable console my-group LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  These commands on pix are for telnet and enable only, if you are accessing the device thro SSH or console,   this wouldnt work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.Also confirm if both the AAA servers hav the keys specified in the PIX config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server my-group host 172.20.20.11&lt;/P&gt;&lt;P&gt; key XXXXXXXX  &amp;lt;------------------------------ key&lt;/P&gt;&lt;P&gt;aaa-server my-group host 172.20.20.12&lt;/P&gt;&lt;P&gt; key cisco123&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3.Also there are lots of timeouts, may be the PIX cant reach the server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Number of timeouts                      153"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4.Do a "debug aaa [ accounting | authentication | authorization ] and check the logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reg,&lt;/P&gt;&lt;P&gt;U&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Mar 2008 02:07:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-aaa-authorization-with-tacacs-server/m-p/925682#M402245</guid>
      <dc:creator>uaravind7</dc:creator>
      <dc:date>2008-03-12T02:07:22Z</dc:date>
    </item>
    <item>
      <title>Re: PIX - AAA authorization with TACACS+ Server</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-aaa-authorization-with-tacacs-server/m-p/925683#M402252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi U,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured telent and enable only. I'm trying to access thro telnet only. server keys are ok. only prob its seems that server is not responding and only authenticate with local username/password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any clue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Mar 2008 05:07:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-aaa-authorization-with-tacacs-server/m-p/925683#M402252</guid>
      <dc:creator>pemasirid</dc:creator>
      <dc:date>2008-03-12T05:07:46Z</dc:date>
    </item>
  </channel>
</rss>

