<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TACACS login problem on ACS 4.0 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-login-problem-on-acs-4-0/m-p/786992#M409027</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please check,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS---&amp;gt;Network configuration----&amp;gt; NDG (where you have this switch) ----&amp;gt; Edit Properties----&amp;gt; Remove key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NDG key overwrites aaa client key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 03 Sep 2007 12:59:30 GMT</pubDate>
    <dc:creator>Jagdeep Gambhir</dc:creator>
    <dc:date>2007-09-03T12:59:30Z</dc:date>
    <item>
      <title>TACACS login problem on ACS 4.0</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-login-problem-on-acs-4-0/m-p/786991#M409026</link>
      <description>&lt;P&gt;I configured the ACS box with a LAN infrastructure client including the correct client ip addresses of the devices, a key and set to authenticate using TACACS+. I configured a test user in the local ACS Internal database.  I then configured a switch with the ACS IP address and the correct key.  When I then try to login to the switch it fails and the following is logged in in the ACS failed attempts log:&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;08/29/2007 11:39:22 Authen failed .. Default Group .. (Default) Key Mismatch .. .. .. x.x.x.x.. .. .. .. .. LAN-Switches LAN-Infrastructure &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;I have triple checked that the keys are correct and yet the reason listed for failure is a key mismatch.  I don't know if I've got something wrong in the config or if there is a bug.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Cisco switch config:&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication attempts login 5&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication login console local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 no_tacacs none&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;tacacs-server host x.x.x.x&lt;/P&gt;&lt;P&gt;no tacacs-server directed-request&lt;/P&gt;&lt;P&gt;tacacs-server key xxx&lt;/P&gt;&lt;P&gt;radius-server source-ports 1645-1646&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;ACS version:&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;CiscoSecure ACS&lt;/P&gt;&lt;P&gt;Release 4.0(1) Build 44&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;what could be worng&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:22:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-login-problem-on-acs-4-0/m-p/786991#M409026</guid>
      <dc:creator>okanlawon.ayodeji</dc:creator>
      <dc:date>2019-03-10T22:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS login problem on ACS 4.0</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-login-problem-on-acs-4-0/m-p/786992#M409027</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please check,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS---&amp;gt;Network configuration----&amp;gt; NDG (where you have this switch) ----&amp;gt; Edit Properties----&amp;gt; Remove key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NDG key overwrites aaa client key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Sep 2007 12:59:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-login-problem-on-acs-4-0/m-p/786992#M409027</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2007-09-03T12:59:30Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS login problem on ACS 4.0</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-login-problem-on-acs-4-0/m-p/786993#M409028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;JG, Many thanks. The issue has been resolved now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2007 13:22:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-login-problem-on-acs-4-0/m-p/786993#M409028</guid>
      <dc:creator>okanlawon.ayodeji</dc:creator>
      <dc:date>2007-09-04T13:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS login problem on ACS 4.0</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-login-problem-on-acs-4-0/m-p/786994#M409029</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks jgambhir,&lt;/P&gt;&lt;P&gt;This solved a problem that I was having authenticating Management Access on a WLC4402 controller to an ACS 4.1, my NDG contained the same password that I used for my router devices, and this was my first non router device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Charlie&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 06 Jan 2008 22:58:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-login-problem-on-acs-4-0/m-p/786994#M409029</guid>
      <dc:creator>charlie-hall</dc:creator>
      <dc:date>2008-01-06T22:58:37Z</dc:date>
    </item>
  </channel>
</rss>

