<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TACACS Authentication Not Working in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776891#M40605</link>
    <description>&lt;P&gt;We currently have a switch - ms-duncan that has been setup for TACACS and works fine.&amp;nbsp; We put the same command on another switch - sw-SPARE and it does not work:&lt;/P&gt;
&lt;P&gt;!&lt;BR /&gt;enable secret 5 $1$lyQB$OUFCNrTeluAVeH9R1Grjm0&lt;BR /&gt;!&lt;BR /&gt;username netadmin privilege 15 secret 5 $1$urJC$LbxLOoBdoG1064QFcjTRe1&lt;BR /&gt;username admin privilege 15 secret 5 $1$LGPp$QbOZQ8Ch2kpEj.tLKsp1m/&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default group tacacs+ local&lt;BR /&gt;aaa authorization console&lt;BR /&gt;aaa authorization config-commands&lt;BR /&gt;aaa authorization exec default group tacacs+ local&lt;BR /&gt;aaa authorization commands 15 default group tacacs+ local&lt;BR /&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;tacacs-server host 10.223.8.29 single-connection key CiscoCisco&lt;BR /&gt;tacacs-server directed-request&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;Here is the debug tacacs from ms-duncan:&lt;/P&gt;
&lt;P&gt;ms-duncan#&lt;BR /&gt;11w5d: TPLUS: Queuing AAA Authentication request 344 for processing&lt;BR /&gt;11w5d: TPLUS: processing authentication start request id 344&lt;BR /&gt;11w5d: TPLUS: Authentication start packet created for 344(reed.vendor)&lt;BR /&gt;11w5d: TPLUS: Using server 10.223.8.29&lt;BR /&gt;11w5d: TPLUS(00000158)/0/IDLE/4383A40: got immediate connect on new 0&lt;BR /&gt;11w5d: TPLUS(00000158)/0/WRITE/4383A40: Started 5 sec timeout&lt;BR /&gt;11w5d: TPLUS(00000158)/0/WRITE: wrote entire 47 bytes request&lt;BR /&gt;11w5d: TPLUS(00000158)/0/READ: read entire 12 header bytes (expect 16 bytes)&lt;BR /&gt;11w5d: TPLUS(00000158)/0/READ: read entire 28 bytes response&lt;BR /&gt;11w5d: TPLUS(00000158)/0/4383A40: Processing the reply packet&lt;BR /&gt;11w5d: TPLUS: Received authen response status GET_PASSWORD (8)&lt;BR /&gt;11w5d: TPLUS: Queuing AAA Authentication request 344 for processing&lt;BR /&gt;11w5d: TPLUS: processing authentication continue request id 344&lt;BR /&gt;11w5d: TPLUS: Authentication continue packet generated for 344&lt;BR /&gt;11w5d: TPLUS(00000158)/0/WRITE/4383CA8: Started 5 sec timeout&lt;BR /&gt;11w5d: TPLUS(00000158)/0/WRITE: wrote entire 25 bytes request&lt;BR /&gt;11w5d: TPLUS(00000158)/0/READ: read entire 12 header bytes (expect 6 bytes)&lt;BR /&gt;11w5d: TPLUS(00000158)/0/READ: read entire 18 bytes response&lt;BR /&gt;11w5d: TPLUS(00000158)/0/4383CA8: Processing the reply packet&lt;BR /&gt;11w5d: TPLUS: Received authen response status PASS (2)&lt;BR /&gt;11w5d: TPLUS: Queuing AAA Authorization request 344 for processing&lt;BR /&gt;11w5d: TPLUS: processing authorization request id 344&lt;BR /&gt;11w5d: TPLUS: Protocol set to None .....Skipping&lt;BR /&gt;11w5d: TPLUS: Sending AV service=shell&lt;BR /&gt;11w5d: TPLUS: Sending AV cmd*&lt;BR /&gt;11w5d: TPLUS: Authorization request created for 344(reed.vendor)&lt;BR /&gt;11w5d: TPLUS: using previously set server 10.223.8.29 from group tacacs+&lt;BR /&gt;11w5d: TPLUS(00000158)/0/IDLE/4384698: got immediate connect on new 0&lt;BR /&gt;11w5d: TPLUS(00000158)/0/WRITE/4384698: Started 5 sec timeout&lt;BR /&gt;11w5d: TPLUS(00000158)/0/WRITE: wrote entire 66 bytes request&lt;BR /&gt;11w5d: TPLUS(00000158)/0/READ: read entire 12 header bytes (expect 18 bytes)&lt;BR /&gt;11w5d: TPLUS(00000158)/0/READ: read entire 30 bytes response&lt;BR /&gt;11w5d: TPLUS(00000158)/0/4384698: Processing the reply packet&lt;BR /&gt;11w5d: TPLUS: Processed AV priv-lvl=15&lt;BR /&gt;11w5d: TPLUS: received authorization response for 344: PASS&lt;BR /&gt;ms-duncan#&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here is the debug tacacs from sw-SPARE:&lt;/P&gt;
&lt;P&gt;sw-SPARE#&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:49.477: TPLUS: Queuing AAA Authentication request 42 for processing&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:49.477: TPLUS: processing authentication start request id 42&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:49.477: TPLUS: Authentication start packet created for 42()&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:49.477: TPLUS: Using server 10.223.8.29&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:49.482: TPLUS(0000002A)/0/NB_WAIT/452B47C: Started 5 sec timeout&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:49.482: TPLUS(0000002A)/0/NB_WAIT: wrote entire 36 bytes request&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:49.482: TPLUS: Would block while reading pak header&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:49.487: TPLUS(0000002A)/0/452B47C: Processing the reply packet&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:58.437: TPLUS: Queuing AAA Authentication request 42 for processing&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:58.437: TPLUS: processing authentication start request id 42&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:58.437: TPLUS: Authentication start packet created for 42()&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:58.437: TPLUS: Using server 10.223.8.29&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:58.437: TPLUS(0000002A)/0/NB_WAIT/4165F60: Started 5 sec timeout&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:58.437: TPLUS(0000002A)/0/NB_WAIT: wrote entire 36 bytes request&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:58.437: TPLUS: Would block while reading pak header&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:58.442: TPLUS(0000002A)/0/4165F60: Processing the reply packet&lt;BR /&gt;sw-SPARE#&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It appears that the problem is there is no username in the Authentication start packet for the sw-SPARE:&lt;/P&gt;
&lt;P&gt;Feb&amp;nbsp; 2 17:17:49.477: TPLUS: Authentication start packet created for 42()&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What do we need to do to fix this and get TACACS to work on sw-SPARE?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 06:26:57 GMT</pubDate>
    <dc:creator>dtom</dc:creator>
    <dc:date>2019-03-11T06:26:57Z</dc:date>
    <item>
      <title>TACACS Authentication Not Working</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776891#M40605</link>
      <description>&lt;P&gt;We currently have a switch - ms-duncan that has been setup for TACACS and works fine.&amp;nbsp; We put the same command on another switch - sw-SPARE and it does not work:&lt;/P&gt;
&lt;P&gt;!&lt;BR /&gt;enable secret 5 $1$lyQB$OUFCNrTeluAVeH9R1Grjm0&lt;BR /&gt;!&lt;BR /&gt;username netadmin privilege 15 secret 5 $1$urJC$LbxLOoBdoG1064QFcjTRe1&lt;BR /&gt;username admin privilege 15 secret 5 $1$LGPp$QbOZQ8Ch2kpEj.tLKsp1m/&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default group tacacs+ local&lt;BR /&gt;aaa authorization console&lt;BR /&gt;aaa authorization config-commands&lt;BR /&gt;aaa authorization exec default group tacacs+ local&lt;BR /&gt;aaa authorization commands 15 default group tacacs+ local&lt;BR /&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;tacacs-server host 10.223.8.29 single-connection key CiscoCisco&lt;BR /&gt;tacacs-server directed-request&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;Here is the debug tacacs from ms-duncan:&lt;/P&gt;
&lt;P&gt;ms-duncan#&lt;BR /&gt;11w5d: TPLUS: Queuing AAA Authentication request 344 for processing&lt;BR /&gt;11w5d: TPLUS: processing authentication start request id 344&lt;BR /&gt;11w5d: TPLUS: Authentication start packet created for 344(reed.vendor)&lt;BR /&gt;11w5d: TPLUS: Using server 10.223.8.29&lt;BR /&gt;11w5d: TPLUS(00000158)/0/IDLE/4383A40: got immediate connect on new 0&lt;BR /&gt;11w5d: TPLUS(00000158)/0/WRITE/4383A40: Started 5 sec timeout&lt;BR /&gt;11w5d: TPLUS(00000158)/0/WRITE: wrote entire 47 bytes request&lt;BR /&gt;11w5d: TPLUS(00000158)/0/READ: read entire 12 header bytes (expect 16 bytes)&lt;BR /&gt;11w5d: TPLUS(00000158)/0/READ: read entire 28 bytes response&lt;BR /&gt;11w5d: TPLUS(00000158)/0/4383A40: Processing the reply packet&lt;BR /&gt;11w5d: TPLUS: Received authen response status GET_PASSWORD (8)&lt;BR /&gt;11w5d: TPLUS: Queuing AAA Authentication request 344 for processing&lt;BR /&gt;11w5d: TPLUS: processing authentication continue request id 344&lt;BR /&gt;11w5d: TPLUS: Authentication continue packet generated for 344&lt;BR /&gt;11w5d: TPLUS(00000158)/0/WRITE/4383CA8: Started 5 sec timeout&lt;BR /&gt;11w5d: TPLUS(00000158)/0/WRITE: wrote entire 25 bytes request&lt;BR /&gt;11w5d: TPLUS(00000158)/0/READ: read entire 12 header bytes (expect 6 bytes)&lt;BR /&gt;11w5d: TPLUS(00000158)/0/READ: read entire 18 bytes response&lt;BR /&gt;11w5d: TPLUS(00000158)/0/4383CA8: Processing the reply packet&lt;BR /&gt;11w5d: TPLUS: Received authen response status PASS (2)&lt;BR /&gt;11w5d: TPLUS: Queuing AAA Authorization request 344 for processing&lt;BR /&gt;11w5d: TPLUS: processing authorization request id 344&lt;BR /&gt;11w5d: TPLUS: Protocol set to None .....Skipping&lt;BR /&gt;11w5d: TPLUS: Sending AV service=shell&lt;BR /&gt;11w5d: TPLUS: Sending AV cmd*&lt;BR /&gt;11w5d: TPLUS: Authorization request created for 344(reed.vendor)&lt;BR /&gt;11w5d: TPLUS: using previously set server 10.223.8.29 from group tacacs+&lt;BR /&gt;11w5d: TPLUS(00000158)/0/IDLE/4384698: got immediate connect on new 0&lt;BR /&gt;11w5d: TPLUS(00000158)/0/WRITE/4384698: Started 5 sec timeout&lt;BR /&gt;11w5d: TPLUS(00000158)/0/WRITE: wrote entire 66 bytes request&lt;BR /&gt;11w5d: TPLUS(00000158)/0/READ: read entire 12 header bytes (expect 18 bytes)&lt;BR /&gt;11w5d: TPLUS(00000158)/0/READ: read entire 30 bytes response&lt;BR /&gt;11w5d: TPLUS(00000158)/0/4384698: Processing the reply packet&lt;BR /&gt;11w5d: TPLUS: Processed AV priv-lvl=15&lt;BR /&gt;11w5d: TPLUS: received authorization response for 344: PASS&lt;BR /&gt;ms-duncan#&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here is the debug tacacs from sw-SPARE:&lt;/P&gt;
&lt;P&gt;sw-SPARE#&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:49.477: TPLUS: Queuing AAA Authentication request 42 for processing&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:49.477: TPLUS: processing authentication start request id 42&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:49.477: TPLUS: Authentication start packet created for 42()&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:49.477: TPLUS: Using server 10.223.8.29&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:49.482: TPLUS(0000002A)/0/NB_WAIT/452B47C: Started 5 sec timeout&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:49.482: TPLUS(0000002A)/0/NB_WAIT: wrote entire 36 bytes request&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:49.482: TPLUS: Would block while reading pak header&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:49.487: TPLUS(0000002A)/0/452B47C: Processing the reply packet&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:58.437: TPLUS: Queuing AAA Authentication request 42 for processing&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:58.437: TPLUS: processing authentication start request id 42&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:58.437: TPLUS: Authentication start packet created for 42()&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:58.437: TPLUS: Using server 10.223.8.29&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:58.437: TPLUS(0000002A)/0/NB_WAIT/4165F60: Started 5 sec timeout&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:58.437: TPLUS(0000002A)/0/NB_WAIT: wrote entire 36 bytes request&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:58.437: TPLUS: Would block while reading pak header&lt;BR /&gt;Feb&amp;nbsp; 2 17:17:58.442: TPLUS(0000002A)/0/4165F60: Processing the reply packet&lt;BR /&gt;sw-SPARE#&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It appears that the problem is there is no username in the Authentication start packet for the sw-SPARE:&lt;/P&gt;
&lt;P&gt;Feb&amp;nbsp; 2 17:17:49.477: TPLUS: Authentication start packet created for 42()&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;What do we need to do to fix this and get TACACS to work on sw-SPARE?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:26:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776891#M40605</guid>
      <dc:creator>dtom</dc:creator>
      <dc:date>2019-03-11T06:26:57Z</dc:date>
    </item>
    <item>
      <title>Is sw-SPARE added as a</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776892#M40606</link>
      <description>&lt;P&gt;Is sw-SPARE added as a network device on your TACACS+ server?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2016 19:19:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776892#M40606</guid>
      <dc:creator>jj27</dc:creator>
      <dc:date>2016-02-02T19:19:47Z</dc:date>
    </item>
    <item>
      <title>Can you please replace this</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776893#M40607</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Can you please replace this command on sw-SPARE&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;tacacs-server host 10.223.8.29 single-connection key CiscoCisco&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;STRONG&gt;With&lt;/STRONG&gt; tacacs-server host 10.223.8.29&amp;nbsp;key CiscoCisco&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;and test again.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;STRONG&gt;~ Jatin&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2016 19:37:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776893#M40607</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2016-02-02T19:37:46Z</dc:date>
    </item>
    <item>
      <title>yes</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776894#M40608</link>
      <description>&lt;P&gt;yes&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2016 20:24:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776894#M40608</guid>
      <dc:creator>dtom</dc:creator>
      <dc:date>2016-02-02T20:24:37Z</dc:date>
    </item>
    <item>
      <title>I replaced the command with</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776895#M40609</link>
      <description>&lt;P&gt;I replaced the command with the one suggested above.&amp;nbsp; The results were the same:&lt;/P&gt;
&lt;P&gt;sw-SPARE#&lt;BR /&gt;Feb&amp;nbsp; 3 13:33:15.679: TPLUS: Queuing AAA Authentication request 48 for processing&lt;BR /&gt;Feb&amp;nbsp; 3 13:33:15.679: TPLUS: processing authentication start request id 48&lt;BR /&gt;Feb&amp;nbsp; 3 13:33:15.679: TPLUS: Authentication start packet created for 48()&lt;BR /&gt;Feb&amp;nbsp; 3 13:33:15.679: TPLUS: Using server 10.223.8.29&lt;BR /&gt;Feb&amp;nbsp; 3 13:33:15.679: TPLUS(00000030)/0/NB_WAIT/43F43A0: Started 5 sec timeout&lt;BR /&gt;Feb&amp;nbsp; 3 13:33:15.684: TPLUS(00000030)/0/NB_WAIT: socket event 2&lt;BR /&gt;Feb&amp;nbsp; 3 13:33:15.684: TPLUS(00000030)/0/NB_WAIT: wrote entire 36 bytes request&lt;BR /&gt;Feb&amp;nbsp; 3 13:33:15.684: TPLUS(00000030)/0/READ: socket event 1&lt;BR /&gt;Feb&amp;nbsp; 3 13:33:15.684: TPLUS(00000030)/0/READ: Would block while reading&lt;BR /&gt;Feb&amp;nbsp; 3 13:33:15.684: TPLUS(00000030)/0/READ: socket event 1&lt;BR /&gt;Feb&amp;nbsp; 3 13:33:15.684: TPLUS(00000030)/0/READ: errno 254&lt;BR /&gt;Feb&amp;nbsp; 3 13:33:15.684: TPLUS(00000030)/0/43F43A0: Processing the reply packet&lt;BR /&gt;sw-SPARE#&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any other thoughts?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2016 13:35:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776895#M40609</guid>
      <dc:creator>dtom</dc:creator>
      <dc:date>2016-02-03T13:35:37Z</dc:date>
    </item>
    <item>
      <title>I guess errno 254 means that</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776896#M40610</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I guess errno 254 means that tacacs packet is sourced with a different ip address then what you have added on the tacacs server. can you share "show ip int bri" output from the device in question and also what interface / ip address have you configured on Tacacs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 10pt;"&gt;~ Jatin&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2016 14:27:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776896#M40610</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2016-02-03T14:27:28Z</dc:date>
    </item>
    <item>
      <title>sw-SPARE#sh ip int</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776897#M40611</link>
      <description>&lt;P&gt;sw-SPARE#sh ip int bri&lt;BR /&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP-Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OK? Method Status&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Protocol&lt;BR /&gt;Vlan1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.19.4.9&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES NVRAM&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;BR /&gt;Vlan160&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.249.160.11&amp;nbsp;&amp;nbsp; YES DHCP&amp;nbsp;&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;BR /&gt;Vlan240&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.249.240.11&amp;nbsp;&amp;nbsp; YES DHCP&amp;nbsp;&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;BR /&gt;FastEthernet0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES NVRAM&amp;nbsp; administratively down down&lt;BR /&gt;GigabitEthernet1/0/1&amp;nbsp;&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/2&amp;nbsp;&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/3&amp;nbsp;&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/4&amp;nbsp;&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/5&amp;nbsp;&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/6&amp;nbsp;&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/7&amp;nbsp;&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/8&amp;nbsp;&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/9&amp;nbsp;&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/10&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/11&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;BR /&gt;GigabitEthernet1/0/12&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/13&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/14&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/15&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/16&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/17&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/18&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/19&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/20&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/21&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; administratively down down&lt;BR /&gt;GigabitEthernet1/0/22&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/23&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/24&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; up&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;BR /&gt;GigabitEthernet1/0/25&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/26&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/27&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;GigabitEthernet1/0/28&amp;nbsp; unassigned&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; YES unset&amp;nbsp; down&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; down&lt;BR /&gt;sw-SPARE#&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;TACACS&lt;/P&gt;
&lt;P&gt;Network Configuration --&amp;gt; Network Device Group --&amp;gt; Spare Test --&amp;gt;&lt;/P&gt;
&lt;P&gt;AAA Client Hostname --&amp;gt; Spare Switch --&amp;gt; AAA Client IP Address --&amp;gt; 172.19.4.9&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2016 15:39:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776897#M40611</guid>
      <dc:creator>dtom</dc:creator>
      <dc:date>2016-02-03T15:39:35Z</dc:date>
    </item>
    <item>
      <title>yes</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776898#M40612</link>
      <description>&lt;P&gt;yes&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2016 18:31:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776898#M40612</guid>
      <dc:creator>dtom</dc:creator>
      <dc:date>2016-02-03T18:31:46Z</dc:date>
    </item>
    <item>
      <title>Can you add another statement</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776899#M40613</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Can you add another statement to the configuration:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;ip tacacs source-interface vlan1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;The command is to specify an interface / IP address for all outgoing TACACS+ packets.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-size: 10pt;"&gt;~ Jatin&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2016 21:25:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776899#M40613</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2016-02-03T21:25:58Z</dc:date>
    </item>
    <item>
      <title>That worked!  So, why do you</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776900#M40614</link>
      <description>&lt;P&gt;That worked!&amp;nbsp; So, why do you have to specify an interface for the outgoing TACACS packets here?&amp;nbsp; Never had to do that before.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2016 17:59:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776900#M40614</guid>
      <dc:creator>dtom</dc:creator>
      <dc:date>2016-02-12T17:59:52Z</dc:date>
    </item>
    <item>
      <title>This command is especially</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776901#M40615</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;This command is especially useful in cases where the NAD has many interfaces and you want to ensure that all TACACS+ packets from a particular NAD have the same IP address.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;~ Jatin&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2016 18:38:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/2776901#M40615</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2016-02-12T18:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: This command is especially</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/3367883#M40616</link>
      <description>&lt;P&gt;I had some problem too. I received in log and ISE next messages:&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2"&gt;Apr 18 06:36:29.639: TPLUS(000001A2)/0/READ: Would block while reading&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Apr 18 06:36:29.639: TPLUS(000001A2)/0/READ: socket event 1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Apr 18 06:36:29.639: TPLUS(000001A2)/0/READ: read 0 bytes&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Apr 18 06:36:29.639: TPLUS(000001A2)/0/READ: socket event 1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Apr 18 06:36:29.639: TPLUS(000001A2)/0/READ: errno 254&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Apr 18 06:36:29.639: TPLUS(000001A2)/0/131A1114: Processing the reply packet&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE class="content_table" border="0"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="31%"&gt;Message Text&lt;/TD&gt;
&lt;TD width="69%"&gt;Failed-Attempt: TACACS+ Request dropped&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="31%"&gt;Failure Reason&lt;/TD&gt;
&lt;TD width="69%"&gt;13017 Received TACACS+ packet from unknown Network Device or AAA Client&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I solved this problem by removing this device on the ISE and created it again.&lt;/P&gt;
&lt;P&gt;But usually that occurs when on device config do not have command&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;ip tacacs source-interface&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 07:24:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/3367883#M40616</guid>
      <dc:creator>MaxAvsetsin</dc:creator>
      <dc:date>2018-04-18T07:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: Can you add another statement</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/3746475#M40617</link>
      <description>&lt;P&gt;Thank you. This worked for me.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 12:17:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/3746475#M40617</guid>
      <dc:creator>DavidW</dc:creator>
      <dc:date>2018-11-14T12:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Authentication Not Working</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/4775591#M579832</link>
      <description>&lt;P&gt;This worked for me as well.&amp;nbsp; Our would work sometimes and sometimes not.&amp;nbsp; &amp;nbsp; Cant believe I didn't think of this, but it makes perfect sense.&amp;nbsp; &amp;nbsp;ISE is configured with just a single IP from this device, so gotta make sure it all comes from the same IP.&amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Feb 2023 22:34:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-not-working/m-p/4775591#M579832</guid>
      <dc:creator>leoingle</dc:creator>
      <dc:date>2023-02-14T22:34:50Z</dc:date>
    </item>
  </channel>
</rss>

