<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS - Console access request for password reset ?? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-console-access-request-for-password-reset/m-p/917418#M408652</link>
    <description>&lt;P&gt;G'day All &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope someone can answer this question for me.&lt;/P&gt;&lt;P&gt;I am auth'ing a number of 6500's + 4500's switches to a pair of acs appliances, if I telnet or ssh to the switches, all is good and I never get requested for a password request, but if I log in via console it almost always wants me to reset my account password ?&lt;/P&gt;&lt;P&gt;As I have 2 accounts I can use, if I alternate between both of them it will eventually let me in with out reseting any passwords.&lt;/P&gt;&lt;P&gt;Why is this ? and why does it only affect console access ? &lt;/P&gt;&lt;P&gt;Below is my config : &lt;/P&gt;&lt;P&gt;aaa group server tacacs+ AAA-TAC&lt;/P&gt;&lt;P&gt; server 10.5.x.x&lt;/P&gt;&lt;P&gt; server 10.5.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default group AAA-TAC local-case&lt;/P&gt;&lt;P&gt;aaa authentication enable default group AAA-TAC enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group AAA-TAC if-authenticated &lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group AAA-TAC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions would be great, as it is really bugging me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 22:26:28 GMT</pubDate>
    <dc:creator>mgrollo1972</dc:creator>
    <dc:date>2019-03-10T22:26:28Z</dc:date>
    <item>
      <title>ACS - Console access request for password reset ??</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-console-access-request-for-password-reset/m-p/917418#M408652</link>
      <description>&lt;P&gt;G'day All &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope someone can answer this question for me.&lt;/P&gt;&lt;P&gt;I am auth'ing a number of 6500's + 4500's switches to a pair of acs appliances, if I telnet or ssh to the switches, all is good and I never get requested for a password request, but if I log in via console it almost always wants me to reset my account password ?&lt;/P&gt;&lt;P&gt;As I have 2 accounts I can use, if I alternate between both of them it will eventually let me in with out reseting any passwords.&lt;/P&gt;&lt;P&gt;Why is this ? and why does it only affect console access ? &lt;/P&gt;&lt;P&gt;Below is my config : &lt;/P&gt;&lt;P&gt;aaa group server tacacs+ AAA-TAC&lt;/P&gt;&lt;P&gt; server 10.5.x.x&lt;/P&gt;&lt;P&gt; server 10.5.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default group AAA-TAC local-case&lt;/P&gt;&lt;P&gt;aaa authentication enable default group AAA-TAC enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group AAA-TAC if-authenticated &lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group AAA-TAC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions would be great, as it is really bugging me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:26:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-console-access-request-for-password-reset/m-p/917418#M408652</guid>
      <dc:creator>mgrollo1972</dc:creator>
      <dc:date>2019-03-10T22:26:28Z</dc:date>
    </item>
    <item>
      <title>Re: ACS - Console access request for password reset ??</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-console-access-request-for-password-reset/m-p/917419#M408653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think its just a coincidence that you are only getting password change prompt when you are accessing device from console.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the ACS server, check the group/user settings, whether you have any password aging policy applied or not? that should give you some direction. Other then that, there is no such thing as password change when connection is initiated from Console.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 13 Oct 2007 17:06:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-console-access-request-for-password-reset/m-p/917419#M408653</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2007-10-13T17:06:12Z</dc:date>
    </item>
  </channel>
</rss>

