<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA authentication TACACs failed in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-tacacs-failed/m-p/1414639#M404961</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have configured the default authentication method to use TACACS+ with a fallback of line password.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Since you are being prompted for the line password, it appears that the router can't contact the TACACS+ server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please enable these debugs, recreate the problem and show us the output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug aaa authentication&lt;/P&gt;&lt;P&gt;debug tacacs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will also want to make sure that you can reach the TACACS+ server when sourcing packets from VLAN 4.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Mar 2010 15:02:40 GMT</pubDate>
    <dc:creator>Javier Henderson</dc:creator>
    <dc:date>2010-03-16T15:02:40Z</dc:date>
    <item>
      <title>AAA authentication TACACs failed</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-tacacs-failed/m-p/1414638#M404959</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I've been configured my device 6506-9 with TACACS+ server authentication:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;enable password 7 1414131F5C542638&lt;BR /&gt;aaa new-model&lt;BR /&gt;&lt;STRONG&gt;aaa authentication login default group tacacs+ line&lt;/STRONG&gt;&lt;BR /&gt;aaa authentication login no_tacacs enable&lt;BR /&gt;aaa authentication ppp default group tacacs+&lt;BR /&gt;aaa authorization exec default group tacacs+ if-authenticated none &lt;BR /&gt;aaa authorization network default group tacacs+ &lt;BR /&gt;aaa accounting update newinfo&lt;BR /&gt;aaa accounting exec default start-stop group tacacs+&lt;BR /&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;BR /&gt;aaa accounting network default start-stop group tacacs+&lt;BR /&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip tacacs source-interface Vlan4&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;tacacs-server host 10.4.X.X key 7 1 044A1E030D345F4D080A554745&lt;BR /&gt;tacacs-server directed-request&lt;BR /&gt;tacacs-server key 7 12081012101E1F072B3874786475&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan4&lt;BR /&gt; description Servers&lt;BR /&gt; ip address 10.4.X.X 255.255.0.0&lt;BR /&gt; no ip redirects&lt;BR /&gt; standby 1 ip 10.4.X.X&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but when I tried to access the device only uses authentication local but not uses TACACs (with username/password defined) it can be an error in configuration? in the other devices of network this works properly, only it's wrong in Cat6506-E&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;device#&amp;nbsp; telnet 10.1.1.3&lt;BR /&gt;Trying 10.1.1.3 ... Open&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;User Access Verification&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Password:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:00:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-tacacs-failed/m-p/1414638#M404959</guid>
      <dc:creator>sdurn</dc:creator>
      <dc:date>2019-03-11T00:00:32Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication TACACs failed</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-tacacs-failed/m-p/1414639#M404961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have configured the default authentication method to use TACACS+ with a fallback of line password.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Since you are being prompted for the line password, it appears that the router can't contact the TACACS+ server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please enable these debugs, recreate the problem and show us the output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug aaa authentication&lt;/P&gt;&lt;P&gt;debug tacacs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will also want to make sure that you can reach the TACACS+ server when sourcing packets from VLAN 4.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Mar 2010 15:02:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-tacacs-failed/m-p/1414639#M404961</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2010-03-16T15:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication TACACs failed</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-tacacs-failed/m-p/1414640#M404963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="medium_text" id="result_box"&gt;&lt;SPAN style="background-color: #ffffff;" title="hola,"&gt;Hi,&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;" title="desde los 2 Cat6509&amp;nbsp; que forman el CORE de la red puedo hacer ping al servidor TACACS (desde&amp;nbsp; el resto de equipos de red me funciona la configuración del TACACs sin&amp;nbsp; problema)"&gt;from 2 Cat6509 that form the core of the network, I can ping the TACACS&amp;nbsp; server (from other network equipment, TACACS works without&amp;nbsp; problems)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="long_text" id="result_box"&gt;&lt;SPAN style="background-color: #ffffff;" title="hola,"&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;" title="desde los dos 6509&amp;nbsp; llego al servidor TACACs por ping (por la vlan 4):"&gt;:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;" title="CORE1#ping&amp;nbsp; 10.4.2.33"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="long_text" id="result_box"&gt;&lt;SPAN style="background-color: #ffffff;" title="CORE1#ping&amp;nbsp; 10.4.2.33"&gt;Core1 # ping 10.4.2.33&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;" title="Type escape&amp;nbsp; sequence to abort."&gt;Type escape sequence to abort.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;" title="Sending 5, 100-byte&amp;nbsp; ICMP Echos to 10.4.2.33, timeout is 2 seconds:"&gt;Sending 5, 100-byte&amp;nbsp; ICMP Echos to 10.4.2.33, timeout is 2 seconds:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="!!!!!"&gt;!!!!!&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Success rate is 100 percent&amp;nbsp; (5/5), round-trip min/avg/max = 1/1/4 ms"&gt;Success rate is 100 percent (5&amp;nbsp; / 5), round-trip min / avg / max = 1/1/4 ms&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="CORE1#ping"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="long_text" id="result_box"&gt;&lt;SPAN title="CORE1#ping"&gt;Core1 # ping&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Protocol [ip]:"&gt;Protocol&amp;nbsp; [ip]:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Target IP address: 10.4.2.33"&gt;Target IP&amp;nbsp; address: 10.4.2.33&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;" title="Repeat count [5]:"&gt;Repeat count [5]:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Datagram size [100]:"&gt;Datagram size [100]:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Timeout in seconds [2]:"&gt;Timeout in seconds [2]:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Extended commands [n]: y"&gt;Extended commands [n]: y&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Source address or interface: 10.4.1.253"&gt;Source address or&amp;nbsp; interface: 10.4.1.253&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Type of service [0]:"&gt;Type&amp;nbsp; of service [0]:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Set DF bit in IP header?"&gt;September&amp;nbsp; DF bit in IP header? &lt;/SPAN&gt;&lt;SPAN title="[no]:"&gt;[no]:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Validate reply data?"&gt;Validate reply data? &lt;/SPAN&gt;&lt;SPAN title="[no]:"&gt;[no]:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Data pattern [0xABCD]:"&gt;Data&amp;nbsp; pattern [0xABCD]:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Loose, Strict, Record,&amp;nbsp; Timestamp, Verbose[none]:"&gt;Loose, Strict, Record, Timestamp, Verbose&amp;nbsp; [none]:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Sweep range of sizes [n]:"&gt;Sweep range of&amp;nbsp; sizes [n]:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Type escape sequence to abort."&gt;Type&amp;nbsp; escape sequence to abort.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Sending 5, 100-byte&amp;nbsp; ICMP Echos to 10.4.2.33, timeout is 2 seconds:"&gt;Sending 5, 100-byte ICMP&amp;nbsp; Echos to 10.4.2.33, timeout is 2 seconds:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Packet&amp;nbsp; sent with a source address of 10.4.1.253"&gt;Packet sent with a source&amp;nbsp; address of 10.4.1.253&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="!!!!!"&gt;!!!!!&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Success rate is 100 percent (5/5), round-trip min/avg/max =&amp;nbsp; 1/1/4 ms"&gt;Success rate is 100 percent (5 / 5), round-trip min / avg /&amp;nbsp; max = 1/1/4 ms&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;" title="He hecho el debug que me has recomendado (archivo&amp;nbsp; adjunto)."&gt;I completed the debugging that you've recommended (attached file).&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN title="Muchas gracias por tu respuesta."&gt;Thank you very much for your&amp;nbsp; reply.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Mar 2010 17:31:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-tacacs-failed/m-p/1414640#M404963</guid>
      <dc:creator>sdurn</dc:creator>
      <dc:date>2010-03-22T17:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication TACACs failed</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-tacacs-failed/m-p/1414641#M404968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; color: #0000ff;"&gt;Make sure ACS have IP address of VLAN 4 listed under aaa-clients.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; color: #0000ff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; color: #0000ff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; color: #0000ff;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: verdana,geneva; color: #0000ff;"&gt;~JG&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Mar 2010 18:09:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-tacacs-failed/m-p/1414641#M404968</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2010-03-22T18:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication TACACs failed</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-tacacs-failed/m-p/1414642#M404971</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;SPAN class="long_text" id="result_box"&gt;&lt;SPAN style="background-color: #ffffff;" title="La IP de gestión de todos los equipos de red&amp;nbsp; está en la vlan1 con rango de IPs: 10.1.XX/16"&gt;The IP management of all&amp;nbsp; network equipment is in vlan1 with IP range: 10.1.XX/16&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;" title="La IP del servidor&amp;nbsp; TACACs está en la vlan 4 con direccionamiento 10.4.XX/16."&gt;The TACACS&amp;nbsp; server IP is on VLAN 4 with addressing 10.4.XX/16.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff;" title="En el servidor&amp;nbsp; TACACs está definido todo el rando de la Vlan1 para que se autentique,&amp;nbsp; todos los equipos de red lo hacen excepto los equipos de CORE (cat6509)"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="long_text" id="result_box"&gt;&lt;SPAN style="background-color: #ffffff;" title="En el servidor TACACs está permitido todo el&amp;nbsp; rango de la Vlan1 para que se autentique, todos los equipos de red lo&amp;nbsp; hacen excepto los equipos de CORE (cat6509)"&gt;In the TACACS server is&amp;nbsp; allowed the full range of VLAN1 to authenticate, &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="long_text" id="result_box"&gt;&lt;SPAN title="En el servidor&amp;nbsp; TACACs está permitido todo el rango de la Vlan1 para que se autentique,&amp;nbsp; todos los equipos de red lo hacen correctamente excepto los equipos de&amp;nbsp; CORE (cat6509)"&gt;and all network equipment properly do, except the CORE devices...(Cat6509)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Mar 2010 10:06:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-tacacs-failed/m-p/1414642#M404971</guid>
      <dc:creator>sdurn</dc:creator>
      <dc:date>2010-03-23T10:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication TACACs failed</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-tacacs-failed/m-p/1414643#M404977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the debug output we see:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mar 22 17:14:58: TPLUS(00000061)/0/NB_WAIT/524FDA08: Started 5 sec timeout&lt;BR /&gt;Mar 22 17:14:58: TPLUS(00000061)/0/NB_WAIT: socket event 2&lt;BR /&gt;Mar 22 17:14:58: TPLUS(00000061)/0/NB_WAIT: wrote entire 51 bytes request&lt;BR /&gt;Mar 22 17:14:58: TPLUS(00000061)/0/READ: socket event 1&lt;BR /&gt;Mar 22 17:14:58: TPLUS(00000061)/0/READ: Would block while reading&lt;BR /&gt;Mar 22 17:14:58: TPLUS(00000061)/0/READ: socket event 1&lt;BR /&gt;Mar 22 17:14:58: TPLUS(00000061)/0/READ: errno 254&lt;BR /&gt;Mar 22 17:14:58: TPLUS(00000061)/0/524FDA08: Processing the reply packet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That suggests a mismatched TACACS+ shared secret, please check into this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Mar 2010 14:16:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-tacacs-failed/m-p/1414643#M404977</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2010-03-23T14:16:00Z</dc:date>
    </item>
    <item>
      <title>AAA authentication TACACs failed</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-tacacs-failed/m-p/1414644#M404981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I, too, am having issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Solutions attempted, but still failed:&lt;/P&gt;&lt;P&gt;1. entered tacacs key again&lt;/P&gt;&lt;P&gt;2. restarted Cisco ACS 5.2 server&lt;/P&gt;&lt;P&gt;3. added "ip tacacs source-interface" command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's the original post I created.&amp;nbsp; I didnt know what to search originally, so created a separate topic/thread.&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/thread/2203407"&gt;https://supportforums.cisco.com/thread/2203407&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Adam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Apr 2013 21:15:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-tacacs-failed/m-p/1414644#M404981</guid>
      <dc:creator>dynamitec1</dc:creator>
      <dc:date>2013-04-17T21:15:12Z</dc:date>
    </item>
  </channel>
</rss>

