<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TACACS not working in ASA 8.0(3) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-not-working-in-asa-8-0-3/m-p/1184857#M405606</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok so Local Device was swapped from PIX to ASA. What is the remote Device?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you show us the configs from both Ends of the tunnel?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 Feb 2009 21:09:46 GMT</pubDate>
    <dc:creator>ansalaza</dc:creator>
    <dc:date>2009-02-24T21:09:46Z</dc:date>
    <item>
      <title>TACACS not working in ASA 8.0(3)</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-not-working-in-asa-8-0-3/m-p/1184856#M405605</link>
      <description>&lt;P&gt;We have quite a few ASA s with similar tacacs and crypto configs but yesterday we had issue with pix and we swapped pix with ASA 8.0(3) and tunnel is up and running but we are not able to login using tacacs even after the configs,, and i found a bug in cisco.com which asks us to use command " crypto map set reverse-route" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsk08454" target="_blank"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsk08454&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;even after configuring it right,, am not able to,, login using tacacs,, can some tell me how to use this command or ,, any other way ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thnx in advance&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:21:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-not-working-in-asa-8-0-3/m-p/1184856#M405605</guid>
      <dc:creator>dbellamkonda</dc:creator>
      <dc:date>2019-03-10T23:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS not working in ASA 8.0(3)</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-not-working-in-asa-8-0-3/m-p/1184857#M405606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok so Local Device was swapped from PIX to ASA. What is the remote Device?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you show us the configs from both Ends of the tunnel?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Feb 2009 21:09:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-not-working-in-asa-8-0-3/m-p/1184857#M405606</guid>
      <dc:creator>ansalaza</dc:creator>
      <dc:date>2009-02-24T21:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS not working in ASA 8.0(3)</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-not-working-in-asa-8-0-3/m-p/1184858#M405607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we have a tunnel established with remote ASA and here are the configs related: let me know if ya need any hing,, thnx for replyin thgh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;local device configs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server &lt;NAME&gt; protocol tacacs+&lt;/NAME&gt;&lt;/P&gt;&lt;P&gt;aaa-server &lt;NAME&gt; host &amp;lt; ip&amp;gt;&lt;/NAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication ssh console &lt;NAME&gt;&lt;/NAME&gt;&lt;/P&gt;&lt;P&gt;aaa authentication http console &lt;NAME&gt;&lt;/NAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list &lt;NAME1&gt; extended permit ip &lt;IP add="" subnet=""&gt; any &lt;/IP&gt;&lt;/NAME1&gt;&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-MD5 esp-3des esp-md5-hmac &lt;/P&gt;&lt;P&gt;crypto map &lt;NAME2&gt; 20 match address &lt;NAME1&gt;&lt;/NAME1&gt;&lt;/NAME2&gt;&lt;/P&gt;&lt;P&gt;crypto map &lt;NAME2&gt; 20 set peer x.x.x.x&lt;/NAME2&gt;&lt;/P&gt;&lt;P&gt;crypto map &lt;NAME2&gt; 20 set transform-set ESP-3DES-MD5&lt;/NAME2&gt;&lt;/P&gt;&lt;P&gt;crypto map &lt;NAME2&gt; 20 set reverse-route&lt;/NAME2&gt;&lt;/P&gt;&lt;P&gt;crypto map &lt;NAME2&gt; interface outside&lt;/NAME2&gt;&lt;/P&gt;&lt;P&gt;crypto isakmp enable outside&lt;/P&gt;&lt;P&gt;crypto isakmp policy 20&lt;/P&gt;&lt;P&gt;crypto isakmp policy 65535&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;remote ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list &lt;NAME3&gt; remark MobileAL&lt;/NAME3&gt;&lt;/P&gt;&lt;P&gt;access-list &lt;NAME3&gt; extended permit ip any ip add subnet &lt;/NAME3&gt;&lt;/P&gt;&lt;P&gt;crypto map &lt;NAME2&gt; 1925 match address outside_1925_cryptomap&lt;/NAME2&gt;&lt;/P&gt;&lt;P&gt;crypto map &lt;NAME2&gt; 1925 set peer &lt;IP&gt;&lt;/IP&gt;&lt;/NAME2&gt;&lt;/P&gt;&lt;P&gt;crypto map &lt;NAME2&gt; 1925 set transform-set ESP-3DES-MD5&lt;/NAME2&gt;&lt;/P&gt;&lt;P&gt;crypto map &lt;NAME2&gt; 1925 set security-association lifetime seconds 86400&lt;/NAME2&gt;&lt;/P&gt;&lt;P&gt;crypto map &lt;NAME2&gt; 1925 set nat-t-disable&lt;/NAME2&gt;&lt;/P&gt;&lt;P&gt;crypto map &lt;NAME2&gt; 1925 set reverse-route&lt;/NAME2&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Feb 2009 21:40:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-not-working-in-asa-8-0-3/m-p/1184858#M405607</guid>
      <dc:creator>dbellamkonda</dc:creator>
      <dc:date>2009-02-24T21:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS not working in ASA 8.0(3)</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-not-working-in-asa-8-0-3/m-p/1184859#M405608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, the partial config does not help much...&lt;/P&gt;&lt;P&gt;Please try collecting these debugs from the local ASA:&lt;/P&gt;&lt;P&gt;debug aaa authentication&lt;/P&gt;&lt;P&gt;debug tacacs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have connectivity (ping) from remote End to the Server behind the Local ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you see any failed attempts on ACS?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Feb 2009 22:07:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-not-working-in-asa-8-0-3/m-p/1184859#M405608</guid>
      <dc:creator>ansalaza</dc:creator>
      <dc:date>2009-02-24T22:07:23Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS not working in ASA 8.0(3)</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-not-working-in-asa-8-0-3/m-p/1184860#M405609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It might be easier to check if &lt;/P&gt;&lt;P&gt;TACACS traffic is reaching the local Interface pointing to the ACS Server:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 1:&lt;/P&gt;&lt;P&gt;access-list captured permit tcp any any eq 49&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 2:&lt;/P&gt;&lt;P&gt;capture tacacs access-list captured interface &lt;INTERFACE_NAME&gt;&lt;/INTERFACE_NAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;INTERFACE_NAME&gt; is the Interface pointing to the ACS Server.&lt;/INTERFACE_NAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To see the information:&lt;/P&gt;&lt;P&gt;Option A:&lt;/P&gt;&lt;P&gt;show capture tacacs&lt;/P&gt;&lt;P&gt;Option B:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="https://" target="_blank"&gt;https://&lt;/A&gt;&lt;IP_ADDRESS&gt;/admin/capture/tacacs&lt;/IP_ADDRESS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where &lt;IP_ADDRESS&gt; is the IP address of your Cisco ASA's inside interface.&lt;/IP_ADDRESS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To remove the access-list:&lt;/P&gt;&lt;P&gt;clear configure access-list captured&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To remove the Capture:&lt;/P&gt;&lt;P&gt;No capture tacacs&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Feb 2009 02:04:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-not-working-in-asa-8-0-3/m-p/1184860#M405609</guid>
      <dc:creator>ansalaza</dc:creator>
      <dc:date>2009-02-25T02:04:56Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS not working in ASA 8.0(3)</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-not-working-in-asa-8-0-3/m-p/1184861#M405610</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thnx much sir,&lt;/P&gt;&lt;P&gt;Will do that and let u know if i need any thing,.&lt;/P&gt;&lt;P&gt;Thnx again for ur time and help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Feb 2009 14:28:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-not-working-in-asa-8-0-3/m-p/1184861#M405610</guid>
      <dc:creator>dbellamkonda</dc:creator>
      <dc:date>2009-02-25T14:28:07Z</dc:date>
    </item>
  </channel>
</rss>

