<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TACACS queries in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-queries/m-p/773341#M409254</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good answer! There are 20 some odd bugs fixed.  You might even consider going up to 4.1.3 p2&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 Aug 2007 13:59:03 GMT</pubDate>
    <dc:creator>akemp</dc:creator>
    <dc:date>2007-08-16T13:59:03Z</dc:date>
    <item>
      <title>TACACS queries</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-queries/m-p/773339#M409252</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My ACS accounting doesn't show the Logs for commands executed . As per me, it should be under "TACACS Administration" Tab. But its blank.. Please let me know what is the problem causing no accounting for Authorized commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the configuration on AAA client:&lt;/P&gt;&lt;P&gt;=~=~=~=~=~=~=~=~=~=~=~=&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch&amp;gt;&lt;/P&gt;&lt;P&gt;Switch&amp;gt;&lt;/P&gt;&lt;P&gt;Switch&amp;gt;&lt;/P&gt;&lt;P&gt;Switch#&lt;/P&gt;&lt;P&gt;Switch#&lt;/P&gt;&lt;P&gt;Switch#&lt;/P&gt;&lt;P&gt;Switch#sh run&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current configuration : 4068 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;version 12.1&lt;/P&gt;&lt;P&gt;no service pad&lt;/P&gt;&lt;P&gt;service timestamps debug uptime&lt;/P&gt;&lt;P&gt;service timestamps log uptime&lt;/P&gt;&lt;P&gt;service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname Switch&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa accounting update newinfo&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username bhaven privilege 15 password 7 ****************&lt;/P&gt;&lt;P&gt;ip subnet-zero&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no ip igmp snooping&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;spanning-tree mode rapid-pvst&lt;/P&gt;&lt;P&gt;no spanning-tree optimize bpdu transmission&lt;/P&gt;&lt;P&gt;spanning-tree extend system-id&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/1&lt;/P&gt;&lt;P&gt; switchport access vlan 203&lt;/P&gt;&lt;P&gt; switchport trunk allowed vlan 10,20&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/2&lt;/P&gt;&lt;P&gt; switchport access vlan 203&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/3&lt;/P&gt;&lt;P&gt; switchport access vlan 203&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/4&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/5&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/6&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/7&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/8&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/9&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/10&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; ip address 172.20.7.26 255.255.255.0&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan3&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan10&lt;/P&gt;&lt;P&gt; ip address 172.20.65.246 255.255.255.0&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan11&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan77&lt;/P&gt;&lt;P&gt; ip address 172.16.4.5 255.255.255.0&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip default-gateway 172.20.65.3&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;tacacs-server host 172.20.65.247 key ******&lt;/P&gt;&lt;P&gt;tacacs-server host 172.20.65.248 key ******&lt;/P&gt;&lt;P&gt;radius-server host 172.20.65.247 auth-port 1812 acct-port 1813 key ******&lt;/P&gt;&lt;P&gt;radius-server retransmit 3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; password 7 ***********&lt;/P&gt;&lt;P&gt;line vty 5 15&lt;/P&gt;&lt;P&gt; password 7 **************&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ntp authentication-key 24 md5 ********** 7&lt;/P&gt;&lt;P&gt;ntp authenticate&lt;/P&gt;&lt;P&gt;ntp trusted-key 24&lt;/P&gt;&lt;P&gt;ntp clock-period 17179742&lt;/P&gt;&lt;P&gt;ntp server 172.20.25.221 key 24&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;monitor session 1 source interface Gi0/1&lt;/P&gt;&lt;P&gt;monitor session 1 destination interface Fa0/10 ingress vlan 77&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch#         exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would apprciate if somebody can help me on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also my second query is when i configure two ACS servers in HA mode, primary is configure to send &amp;amp; secendory is configured to receive.&lt;/P&gt;&lt;P&gt;But in case of any failure any my primry goes down , will my configuration changes done on Secendory ACS server will sync with primary ACS when primary comes back online.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:19:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-queries/m-p/773339#M409252</guid>
      <dc:creator>img</dc:creator>
      <dc:date>2019-03-10T22:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS queries</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-queries/m-p/773340#M409253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;If you have acs ver 4.1.1 23 then this is a known issue, you need to apply patch ACS 4.1.1.23.5 to fix the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patch for appliance is available on,&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/cgi-bin/tablebuild.pl/acs-soleng-3des" target="_blank"&gt;http://www.cisco.com/cgi-bin/tablebuild.pl/acs-soleng-3des&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patch name : ACS SE 4.1.1.23.5 accumulative patch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patch for acs windows is available on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/cgi-bin/tablebuild.pl/acs-win-3des" target="_blank"&gt;http://www.cisco.com/cgi-bin/tablebuild.pl/acs-win-3des&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patch Name:ACS 4.1.1.23.5 accumulative patch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That should fix the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Second Issue,&lt;/P&gt;&lt;P&gt;ACS replication is always one way, from primary to secondary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: If that answers your question, then please mark this thread as resolved, so that others can benefit from it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2007 12:07:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-queries/m-p/773340#M409253</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2007-08-14T12:07:30Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS queries</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-queries/m-p/773341#M409254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good answer! There are 20 some odd bugs fixed.  You might even consider going up to 4.1.3 p2&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Aug 2007 13:59:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-queries/m-p/773341#M409254</guid>
      <dc:creator>akemp</dc:creator>
      <dc:date>2007-08-16T13:59:03Z</dc:date>
    </item>
  </channel>
</rss>

