<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TACACS not working - Need help in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-not-working-need-help/m-p/1164218#M419058</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I  believe there is a known issue with this setup and you might need to enter into server mode and then define the vrf forwarding interface something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ TEST&lt;/P&gt;&lt;P&gt; server X.X.X.X&lt;/P&gt;&lt;P&gt; ip vrf forwarding LAN &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 09 Feb 2009 18:12:56 GMT</pubDate>
    <dc:creator>Ivan Martinon</dc:creator>
    <dc:date>2009-02-09T18:12:56Z</dc:date>
    <item>
      <title>TACACS not working - Need help</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-not-working-need-help/m-p/1164217#M419056</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have implemented the TACACS in VPN VRF environment but the same is not working,  I am not able to route the ACS servers IP's through the VRF-VPN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuration pasted below&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ line &lt;/P&gt;&lt;P&gt;aaa authentication login no_tacacs line &lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization commands 0 default group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+ &lt;/P&gt;&lt;P&gt;aaa accounting commands 0 default start-stop group tacacs+ &lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs+ &lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+ &lt;/P&gt;&lt;P&gt;aaa accounting network default start-stop group tacacs+ &lt;/P&gt;&lt;P&gt;ip tacacs source-interface VLAN1 &lt;/P&gt;&lt;P&gt;tacacs-server host X.X.X.X &lt;/P&gt;&lt;P&gt;tacacs-server host 10.10.10.4 &lt;/P&gt;&lt;P&gt;tacacs-server key 7 ####################333 &lt;/P&gt;&lt;P&gt;tacacs-server administration &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ tacacs1 &lt;/P&gt;&lt;P&gt;server-private 10.10.10.4 key ############ &lt;/P&gt;&lt;P&gt;ip vrf forwarding LAN &lt;/P&gt;&lt;P&gt;ip tacacs source-interface VLAN1 &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:19:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-not-working-need-help/m-p/1164217#M419056</guid>
      <dc:creator>dipumj</dc:creator>
      <dc:date>2019-03-10T23:19:49Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS not working - Need help</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-not-working-need-help/m-p/1164218#M419058</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I  believe there is a known issue with this setup and you might need to enter into server mode and then define the vrf forwarding interface something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ TEST&lt;/P&gt;&lt;P&gt; server X.X.X.X&lt;/P&gt;&lt;P&gt; ip vrf forwarding LAN &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Feb 2009 18:12:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-not-working-need-help/m-p/1164218#M419058</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2009-02-09T18:12:56Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS not working - Need help</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-not-working-need-help/m-p/1164219#M419060</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks you so much for your mail,&lt;/P&gt;&lt;P&gt;I have tried with this but still I am not able make it success&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ tacacs1&lt;/P&gt;&lt;P&gt; server 10.10.10.14&lt;/P&gt;&lt;P&gt; server 10.10.10.45&lt;/P&gt;&lt;P&gt; ip vrf forwarding LAN&lt;/P&gt;&lt;P&gt; ip tacacs source-interface Vlan1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It showing authorisation failed when I try a new VTY session. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Feb 2009 12:13:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-not-working-need-help/m-p/1164219#M419060</guid>
      <dc:creator>dipumj</dc:creator>
      <dc:date>2009-02-10T12:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS not working - Need help</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-not-working-need-help/m-p/1164220#M419062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You might need to get some debugs on this box as well as the failed logs from your TACACS server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Feb 2009 15:11:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-not-working-need-help/m-p/1164220#M419062</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2009-02-10T15:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS not working - Need help</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-not-working-need-help/m-p/1164221#M419064</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi sorry for late reply.&lt;/P&gt;&lt;P&gt;Please find below the logs from the router&lt;/P&gt;&lt;P&gt;Feb 12 14:10:28.748: AAA/ACCT/CMD(000000B9): free_rec, count 2&lt;/P&gt;&lt;P&gt;Feb 12 14:10:28.748: AAA/ACCT/CMD(000000B9): Setting session id 283 : db=846968EC&lt;/P&gt;&lt;P&gt;Feb 12 14:10:28.748: AAA/ACCT(000000B9): Accouting method=tacacs+ (TACACS+)&lt;/P&gt;&lt;P&gt;Feb 12 14:10:35.450: AAA/BIND(000000BA): Bind i/f  &lt;/P&gt;&lt;P&gt;Feb 12 14:10:35.450: AAA/ACCT/EVENT/(000000BA): CALL START&lt;/P&gt;&lt;P&gt;Feb 12 14:10:35.450: Getting session id for NET(000000BA) : db=83E3E3B0&lt;/P&gt;&lt;P&gt;Feb 12 14:10:35.450: AAA/ACCT(00000000): add node, session 284&lt;/P&gt;&lt;P&gt;Feb 12 14:10:35.450: AAA/ACCT/NET(000000BA): add, count 1&lt;/P&gt;&lt;P&gt;Feb 12 14:10:35.450: Getting session id for NONE(000000BA) : db=83E3E3B0&lt;/P&gt;&lt;P&gt;Feb 12 14:10:36.014: AAA/AUTHEN/LOGIN (000000BA): Pick method list 'default' &lt;/P&gt;&lt;P&gt;Feb 12 14:10:38.749: AAA/ACCT/CMD(000000B9): STOP protocol reply FAIL&lt;/P&gt;&lt;P&gt;Feb 12 14:10:38.749: AAA/ACCT(000000B9): Accouting method=NOT_SET&lt;/P&gt;&lt;P&gt;Feb 12 14:10:38.749: AAA/ACCT(000000B9): Send STOP accounting notification to EM successfully&lt;/P&gt;&lt;P&gt;Feb 12 14:10:38.749: AAA/ACCT/CMD(000000B9): Tried all the methods, osr 0&lt;/P&gt;&lt;P&gt;Feb 12 14:10:38.749: AAA/ACCT/CMD(000000B9) Record not present&lt;/P&gt;&lt;P&gt;Feb 12 14:10:38.749: AAA/ACCT/CMD(000000B9) reccnt 2, csr FALSE, osr 0&lt;/P&gt;&lt;P&gt;Feb 12 14:10:46.011: AAA/AUTHEN/LINE(000000BA): GET_PASSWORD &lt;/P&gt;&lt;P&gt;Feb 12 14:11:14.326: AAA/AUTHOR: config command authorization not enabled&lt;/P&gt;&lt;P&gt;Feb 12 14:11:14.326: AAA/ACCT/CMD(000000B9): Pick method list 'default'&lt;/P&gt;&lt;P&gt;Feb 12 14:11:14.326: AAA/ACCT/SETMLIST(000000B9): Handle 0, mlist 83E2FF8C, Name default&lt;/P&gt;&lt;P&gt;Feb 12 14:11:14.330: Getting session id for CMD(000000B9) : db=846968EC&lt;/P&gt;&lt;P&gt;Feb 12 14:11:14.330: AAA/ACCT/CMD(000000B9): add, count 3&lt;/P&gt;&lt;P&gt;Feb 12 14:11:14.330: AAA/ACCT/EVENT/(000000B9): COMMAND&lt;/P&gt;&lt;P&gt;Feb 12 14:11:14.330: AAA/ACCT/CMD(000000B9): Queueing record is COMMAND osr 1&lt;/P&gt;&lt;P&gt;Feb 12 14:11:14.330: AAA/ACCT/CMD(000000B9): free_rec, count 2&lt;/P&gt;&lt;P&gt;Feb 12 14:11:14.330: AAA/ACCT/CMD(000000B9): Setting session id 285 : db=846968EC&lt;/P&gt;&lt;P&gt;Feb 12 14:11:14.330: AAA/ACCT(000000B9): Accouting method=tacacs+ (TACACS+)&lt;/P&gt;&lt;P&gt;Feb 12 14:11:16.642: AAA/ACCT/EXEC(000000BA): Pick method list 'default'&lt;/P&gt;&lt;P&gt;Feb 12 14:11:16.642: AAA/ACCT/SETMLIST(000000BA): Handle 0, mlist 83E2FEEC, Name default&lt;/P&gt;&lt;P&gt;Feb 12 14:11:16.642: Getting session id for EXEC(000000BA) : db=83E3E3B0&lt;/P&gt;&lt;P&gt;Feb 12 14:11:16.642: AAA/ACCT(000000BA): add common node to avl failed&lt;/P&gt;&lt;P&gt;Feb 12 14:11:16.642: AAA/ACCT/EXEC(000000BA): add, count 2&lt;/P&gt;&lt;P&gt;Feb 12 14:11:16.642: AAA/ACCT/EVENT/(000000BA): EXEC DOWN&lt;/P&gt;&lt;P&gt;Feb 12 14:11:16.642: AAA/ACCT/EXEC(000000BA): Accounting record not sent&lt;/P&gt;&lt;P&gt;Feb 12 14:11:16.642: AAA/ACCT/EXEC(000000BA): free_rec, count 1&lt;/P&gt;&lt;P&gt;Feb 12 14:11:16.642: AAA/ACCT/EXEC(000000BA) reccnt 1, csr FALSE, osr 0&lt;/P&gt;&lt;P&gt;Feb 12 14:11:18.425: AAA/AUTHOR: config command authorization not enabled&lt;/P&gt;&lt;P&gt;Feb 12 14:11:18.425: AAA/ACCT/243(000000B9): Pick method list 'default'&lt;/P&gt;&lt;P&gt;Feb 12 14:11:18.425: AAA/ACCT/SETMLIST(000000B9): Handle 0, mlist 83144FF8, Name default&lt;/P&gt;&lt;P&gt;Feb 12 14:11:18.425: Getting session id for CMD(000000B9) : db=846968EC&lt;/P&gt;&lt;P&gt;Feb 12 14:11:18.425: AAA/ACCT/CMD(000000B9): add, count 3&lt;/P&gt;&lt;P&gt;Feb 12 14:11:18.425: AAA/ACCT/EVENT/(000000B9): COMMAND&lt;/P&gt;&lt;P&gt;Feb 12 14:11:18.425: AAA/ACCT/CMD(000000B9): Queueing record is COMMAND osr 2&lt;/P&gt;&lt;P&gt;Feb 12 14:11:18.425: AAA/ACCT/CMD(000000B9): free_rec, count 2&lt;/P&gt;&lt;P&gt;Feb 12 14:11:18.425: AAA/ACCT/CMD(000000B9): Setting session id 286 : db=846968EC&lt;/P&gt;&lt;P&gt;Feb 12 14:11:18.429: AAA/ACCT(000000B9): Accouting method=tacacs+ (TACACS+)&lt;/P&gt;&lt;P&gt;Feb 12 14:11:18.649: AAA/ACCT/EVENT/(000000BA): CALL STOP&lt;/P&gt;&lt;P&gt;Feb 12 14:11:18.649: AAA/ACCT/CALL STOP(000000BA): Sending stop requests&lt;/P&gt;&lt;P&gt;Feb 12 14:11:18.649: AAA/ACCT(000000BA): Send all stops&lt;/P&gt;&lt;P&gt;Feb 12 14:11:18.649: AAA/ACCT/NET(000000BA): STOP&lt;/P&gt;&lt;P&gt;Feb 12 14:11:18.649: AAA/ACCT/NET(000000BA): Method list not found&lt;/P&gt;&lt;P&gt;Feb 12 14:11:18.649: AAA/ACCT(000000BA): del node, session 284&lt;/P&gt;&lt;P&gt;Feb 12 14:11:18.649: AAA/ACCT/NET(000000BA): free_rec, count 0&lt;/P&gt;&lt;P&gt;Feb 12 14:11:18.649: AAA/ACCT/NET(000000BA) reccnt 0, csr TRUE, osr 0&lt;/P&gt;&lt;P&gt;Feb 12 14:11:18.649: AAA/ACCT/NET(000000BA): Last rec in db, intf not enqueued&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Feb 2009 14:38:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-not-working-need-help/m-p/1164221#M419064</guid>
      <dc:creator>dipumj</dc:creator>
      <dc:date>2009-02-12T14:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS not working - Need help</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-not-working-need-help/m-p/1164222#M419066</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;aaa authentication login default group tacacs1 line &lt;/P&gt;&lt;P&gt;aaa authentication login no_tacacs line &lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs1 if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization commands 0 default group tacacs1 if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs1 if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs1 if-authenticated &lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs1 &lt;/P&gt;&lt;P&gt;aaa accounting commands 0 default start-stop group tacacs1 &lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs1 &lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs1 &lt;/P&gt;&lt;P&gt;aaa accounting network default start-stop group tacacs1 &lt;/P&gt;&lt;P&gt;ip tacacs source-interface VLAN1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ tacacs1 &lt;/P&gt;&lt;P&gt;server-private 10.10.10.4 key ############ &lt;/P&gt;&lt;P&gt;ip vrf forwarding LAN &lt;/P&gt;&lt;P&gt;ip tacacs source-interface VLAN1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remove the config below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host X.X.X.X &lt;/P&gt;&lt;P&gt;tacacs-server host 10.10.10.4 &lt;/P&gt;&lt;P&gt;tacacs-server key 7 ####################333 &lt;/P&gt;&lt;P&gt;tacacs-server administration &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 May 2009 18:14:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-not-working-need-help/m-p/1164222#M419066</guid>
      <dc:creator>smak74</dc:creator>
      <dc:date>2009-05-07T18:14:18Z</dc:date>
    </item>
  </channel>
</rss>

