<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enable mode authorization failed. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/enable-mode-authorization-failed/m-p/841052#M408588</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks,  that fixed it...............&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Oct 2007 15:10:13 GMT</pubDate>
    <dc:creator>rice.randy</dc:creator>
    <dc:date>2007-10-16T15:10:13Z</dc:date>
    <item>
      <title>Enable mode authorization failed.</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-authorization-failed/m-p/841050#M408584</link>
      <description>&lt;P&gt;Have a user that cannot get to en prompt. Here is my trace output:&lt;/P&gt;&lt;P&gt;AAA/AUTHEN: update_user user='lduncan' ruser='(null)' port='telnet146' rem_addr=&lt;/P&gt;&lt;P&gt;'10.128.20.110' authen_type=1 service=ENABLE priv=152007 Oct 16 10:57:07.360 EST&lt;/P&gt;&lt;P&gt; -04:00&lt;/P&gt;&lt;P&gt;AAA/AUTHEN/START (0): port='telnet146' list='(null)' action=LOGIN service=ENABLE&lt;/P&gt;&lt;P&gt;TAC+: send AUTHEN/START packet ver=192 id=626074205&lt;/P&gt;&lt;P&gt;TAC+: Opening TCP/IP connection to 10.129.12.196&lt;/P&gt;&lt;P&gt;TAC+: ver=192 id=626074205 received AUTHEN status = GETPASS2007 Oct 16 10:57:08.&lt;/P&gt;&lt;P&gt;440 EST -04:00&lt;/P&gt;&lt;P&gt;AAA/AUTHEN (626074205): status = GETPASSPassword: 2007 Oct 16 10:57:11.200 EST -&lt;/P&gt;&lt;P&gt;04:00 *62*2007 Oct 16 10:57:11.440 EST -04:00 *69*2007 Oct 16 10:57:11.800 EST -&lt;/P&gt;&lt;P&gt;04:00 *67*2007 Oct 16 10:57:12.050 EST -04:00 *74*2007 Oct 16 10:57:12.300 EST -&lt;/P&gt;&lt;P&gt;04:00 *6f*2007 Oct 16 10:57:12.530 EST -04:00 *65*&lt;/P&gt;&lt;P&gt;2007 Oct 16 10:57:12.950 EST -04:00&lt;/P&gt;&lt;P&gt;AAA/AUTHEN/CONT (626074205): continue_login2007 Oct 16 10:57:12.950 EST -04:00&lt;/P&gt;&lt;P&gt;AAA/AUTHEN (626074205): status = GETPASS&lt;/P&gt;&lt;P&gt;TAC+: send AUTHEN/CONT packet id=626074205&lt;/P&gt;&lt;P&gt;TAC+: ver=192 id=626074205 received AUTHEN status = PASS2007 Oct 16 10:57:13.460&lt;/P&gt;&lt;P&gt; EST -04:00&lt;/P&gt;&lt;P&gt;AAA/AUTHEN (626074205): status = PASS2007 Oct 16 10:57:13.460 EST -04:00 return&lt;/P&gt;&lt;P&gt;PASS&lt;/P&gt;&lt;P&gt;2007 Oct 16 10:57:13.460 EST -04:00&lt;/P&gt;&lt;P&gt;AAA/AUTHOR : ptr2=enable&lt;/P&gt;&lt;P&gt;2007 Oct 16 10:57:13.470 EST -04:00&lt;/P&gt;&lt;P&gt;AAA/AUTHOR : Add AV service=shell&lt;/P&gt;&lt;P&gt;2007 Oct 16 10:57:13.470 EST -04:00&lt;/P&gt;&lt;P&gt;AAA/AUTHOR : Add AV cmd=enable&lt;/P&gt;&lt;P&gt;2007 Oct 16 10:57:13.470 EST -04:00&lt;/P&gt;&lt;P&gt;AAA/AUTHOR/TACACS+ cmd author (413075467): Port='telnet146' list='(null)' servic&lt;/P&gt;&lt;P&gt;e=CMD2007 Oct 16 10:57:13.480 EST -04:00&lt;/P&gt;&lt;P&gt;AAA/AUTHOR/TACACS+ cmd author:  (413075467) user='lduncan'2007 Oct 16 10:57:13.4&lt;/P&gt;&lt;P&gt;80 EST -04:00&lt;/P&gt;&lt;P&gt;AAA/AUTHOR/TACACS+ cmd author: (413075467) send AV service=shell2007 Oct 16 10:5&lt;/P&gt;&lt;P&gt;7:13.480 EST -04:00&lt;/P&gt;&lt;P&gt;AAA/AUTHOR/TACACS+ cmd author: (413075467) send AV cmd=enable&lt;/P&gt;&lt;P&gt;AAA/AUTHOR/TACACS+ cmd author: (413075467) Method=TAC_PLUS2007 Oct 16 10:57:13.4&lt;/P&gt;&lt;P&gt;90 EST -04:00&lt;/P&gt;&lt;P&gt;AAA/AUTHOR/TAC+: (413075467): user=lduncan2007 Oct 16 10:57:13.490 EST -04:00&lt;/P&gt;&lt;P&gt;AAA/AUTHOR/TAC+: (413075467): send AV service=shell2007 Oct 16 10:57:13.490 EST&lt;/P&gt;&lt;P&gt;-04:00&lt;/P&gt;&lt;P&gt;AAA/AUTHOR/TAC+: (413075467): send AV cmd=enable&lt;/P&gt;&lt;P&gt;TAC+: Opening TCP/IP connection to 10.129.12.196&lt;/P&gt;&lt;P&gt;TAC+: (413075467): received author response status = FAIL2007 Oct 16 10:57:14.50&lt;/P&gt;&lt;P&gt;0 EST -04:00&lt;/P&gt;&lt;P&gt;AAA/AUTHOR (413075467): Post authorization status = FAIL2007 Oct 16 10:57:14.500&lt;/P&gt;&lt;P&gt; EST -04:00&lt;/P&gt;&lt;P&gt;AAA/AUTHOR : do_author result=12007 Oct 16 10:57:14.500 EST -04:00 %AAA: author:&lt;/P&gt;&lt;P&gt;tacacs_plus_author ret=1.&lt;/P&gt;&lt;P&gt;Enable mode authorization faile&lt;/P&gt;&lt;P&gt;I have checked his user info and group info in tacacs.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:27:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-authorization-failed/m-p/841050#M408584</guid>
      <dc:creator>rice.randy</dc:creator>
      <dc:date>2019-03-10T22:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: Enable mode authorization failed.</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-authorization-failed/m-p/841051#M408586</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems that you have command author configured that is why user in not able to issue it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What kind of user is it ? Admin or normal user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To make him login you need to make changes in the command author set.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make one command autho set in acs ---&amp;gt;shared profile componenets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;add--&amp;gt;give any name "Full access "---&amp;gt; Put radio button to permit and submit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now go to that group--&amp;gt;Under  Shell Command Authorization Set---&amp;gt; Choose---&amp;gt;Assign a Shell Command Authorization Set for any network device and select FULL ACCESS from list and submit apply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now it should let you in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Caution : This is let that uses to issue all commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also provide me more info if you want user to deny some commands. We need to set up command autho set accordingly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helpful posts&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2007 14:51:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-authorization-failed/m-p/841051#M408586</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2007-10-16T14:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: Enable mode authorization failed.</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-authorization-failed/m-p/841052#M408588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks,  that fixed it...............&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2007 15:10:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-authorization-failed/m-p/841052#M408588</guid>
      <dc:creator>rice.randy</dc:creator>
      <dc:date>2007-10-16T15:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: Enable mode authorization failed.</title>
      <link>https://community.cisco.com/t5/network-access-control/enable-mode-authorization-failed/m-p/841053#M408589</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please mark it resolved so other can benefit from it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2007 15:12:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/enable-mode-authorization-failed/m-p/841053#M408589</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2007-10-16T15:12:04Z</dc:date>
    </item>
  </channel>
</rss>

