<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Local Account Authentication - Concern in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122416#M419341</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Its a local user created on Router, no such user exists on ACS Box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 Aug 2008 14:35:53 GMT</pubDate>
    <dc:creator>Amin Shaikh</dc:creator>
    <dc:date>2008-08-22T14:35:53Z</dc:date>
    <item>
      <title>Local Account Authentication - Concern</title>
      <link>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122405#M419330</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want Routers to be authenticated via ACS Box and if ACS Box is unavailable then only local accounts created on Router  should authenticate...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My setup allows Router local account authenticaion even if ACS Box is available...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help to resolve this...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My config :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username alj password 7 0000111188888&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host 192.168.1.100&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;tacacs-server key 7 0000111199999999&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip tacacs source-interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:02:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122405#M419330</guid>
      <dc:creator>Amin Shaikh</dc:creator>
      <dc:date>2019-03-10T23:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: Local Account Authentication - Concern</title>
      <link>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122406#M419331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you cross check that your tacacs-server also having the same tacacs-server key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May be it is creating the problem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Aug 2008 21:32:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122406#M419331</guid>
      <dc:creator>chaitu_kranthi</dc:creator>
      <dc:date>2008-08-20T21:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: Local Account Authentication - Concern</title>
      <link>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122407#M419332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Its using the same Key.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get authenticated via ACS and Local Accounts.. but I want local account should only be authenticated if ACS server is down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Aug 2008 06:46:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122407#M419332</guid>
      <dc:creator>Amin Shaikh</dc:creator>
      <dc:date>2008-08-21T06:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: Local Account Authentication - Concern</title>
      <link>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122408#M419333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you share the config under "line vty"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Aug 2008 15:19:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122408#M419333</guid>
      <dc:creator>dhananjoy chowdhury</dc:creator>
      <dc:date>2008-08-21T15:19:51Z</dc:date>
    </item>
    <item>
      <title>Re: Local Account Authentication - Concern</title>
      <link>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122409#M419334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line vty 5 15&lt;/P&gt;&lt;P&gt;  transport input telnet ssh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Aug 2008 19:08:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122409#M419334</guid>
      <dc:creator>Amin Shaikh</dc:creator>
      <dc:date>2008-08-21T19:08:59Z</dc:date>
    </item>
    <item>
      <title>Re: Local Account Authentication - Concern</title>
      <link>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122410#M419335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;debug aaa authentication&lt;/P&gt;&lt;P&gt;debug tacacs authentication&lt;/P&gt;&lt;P&gt;term mon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would let you know if it is even letting you in using Local account, even if Tacacs server is UP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I doubt that case, and I recommend running these debugs. As you commands are perfect for what you want to achieve, unless there is some bug in the code or unless we are missing something.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Aug 2008 19:23:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122410#M419335</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2008-08-21T19:23:47Z</dc:date>
    </item>
    <item>
      <title>Re: Local Account Authentication - Concern</title>
      <link>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122411#M419336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Amin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to understand better this statement of yours:&lt;/P&gt;&lt;P&gt;I get authenticated via ACS and Local Accounts.&lt;/P&gt;&lt;P&gt;How do you tell that you are authenticated via ACS and Local Accounts. Do you have a user ID that is in ACS but not local and another user ID that is local but not in ACS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or if you have a user ID that is in ACS and also locally configured, but has a different password in the local definition from ACS, then do both passwords work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Understanding this may help us find a solution to your problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[edit] and I agree that the output of the debug aaa authentication and debug tacacs authentication would be quite helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Aug 2008 20:05:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122411#M419336</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2008-08-21T20:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: Local Account Authentication - Concern</title>
      <link>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122412#M419337</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes,&lt;/P&gt;&lt;P&gt;I have a user ID that is in ACS but not local and another user ID that is local but not in ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And both of them work when ACS BOX is reachable by the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;===========================================&lt;/P&gt;&lt;P&gt;&amp;lt;&amp;lt; Let me rephrase my question &amp;gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As an Admin Local Account created on Router should only be authenticated when ACS BOx is unreachable.&lt;/P&gt;&lt;P&gt;=============================================&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2008 11:20:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122412#M419337</guid>
      <dc:creator>Amin Shaikh</dc:creator>
      <dc:date>2008-08-22T11:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: Local Account Authentication - Concern</title>
      <link>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122413#M419338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;debugs please &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the account that is local on device and ACS box should be reachable at that moment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2008 11:26:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122413#M419338</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2008-08-22T11:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: Local Account Authentication - Concern</title>
      <link>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122414#M419339</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;329399: *Jun 23 09:28:05.375 PAK: %FAN-3-FAN_FAILED: Fan 1 had a rotation error reported.&lt;/P&gt;&lt;P&gt;329400: *Jun 23 09:28:16.767 PAK: AAA/BIND(00000082): Bind i/f  &lt;/P&gt;&lt;P&gt;329401: *Jun 23 09:28:16.767 PAK: AAA/AUTHEN/LOGIN (00000082): Pick method list 'default' &lt;/P&gt;&lt;P&gt;329402: *Jun 23 09:28:16.767 PAK: TPLUS: Queuing AAA Authentication request 130 for processing&lt;/P&gt;&lt;P&gt;329403: *Jun 23 09:28:16.767 PAK: TPLUS: processing authentication start request id 130&lt;/P&gt;&lt;P&gt;329404: *Jun 23 09:28:16.767 PAK: TPLUS: Authentication start packet created for 130(paknt)&lt;/P&gt;&lt;P&gt;329405: *Jun 23 09:28:16.767 PAK: TPLUS: Using server 192.168.1.100&lt;/P&gt;&lt;P&gt;329406: *Jun 23 09:28:16.767 PAK: TPLUS(00000082)/1/NB_WAIT/641C1728: Started 5 sec timeout&lt;/P&gt;&lt;P&gt;329407: *Jun 23 09:28:16.767 PAK: TPLUS(00000082)/1/NB_WAIT: socket event 2&lt;/P&gt;&lt;P&gt;329408: *Jun 23 09:28:16.767 PAK: TPLUS(00000082)/1/NB_WAIT: wrote entire 43 bytes request&lt;/P&gt;&lt;P&gt;329409: *Jun 23 09:28:16.767 PAK: TPLUS(00000082)/1/READ: socket event 1&lt;/P&gt;&lt;P&gt;329410: *Jun 23 09:28:16.767 PAK: TPLUS(00000082)/1/READ: Would block while reading&lt;/P&gt;&lt;P&gt;329411: *Jun 23 09:28:16.767 PAK: TPLUS(00000082)/1/READ: socket event 1&lt;/P&gt;&lt;P&gt;329412: *Jun 23 09:28:16.767 PAK: TPLUS(00000082)/1/READ: read entire 12 header bytes (expect 16 bytes data)&lt;/P&gt;&lt;P&gt;329413: *Jun 23 09:28:16.767 PAK: TPLUS(00000082)/1/READ: socket event 1&lt;/P&gt;&lt;P&gt;329414: *Jun 23 09:28:16.767 PAK: TPLUS(00000082)/1/READ: read entire 28 bytes response&lt;/P&gt;&lt;P&gt;329415: *Jun 23 09:28:16.771 PAK: TPLUS(00000082)/1/641C1728: Processing the reply packet&lt;/P&gt;&lt;P&gt;329416: *Jun 23 09:28:16.771 PAK: TPLUS: Received authen response status GET_PASSWORD (8)&lt;/P&gt;&lt;P&gt;329417: *Jun 23 09:28:26.179 PAK: TPLUS: Queuing AAA Authentication request 130 for processing&lt;/P&gt;&lt;P&gt;329418: *Jun 23 09:28:26.179 PAK: TPLUS: processing authentication continue request id 130&lt;/P&gt;&lt;P&gt;329419: *Jun 23 09:28:26.179 PAK: TPLUS: Authentication continue packet generated for 130&lt;/P&gt;&lt;P&gt;329420: *Jun 23 09:28:26.179 PAK: TPLUS(00000082)/1/WRITE/641C166C: Started 5 sec timeout&lt;/P&gt;&lt;P&gt;329421: *Jun 23 09:28:26.179 PAK: TPLUS(00000082)/1/WRITE: wrote entire 27 bytes request&lt;/P&gt;&lt;P&gt;329422: *Jun 23 09:28:31.179 PAK: TPLUS(00000082)/1/READ/641C166C: timed out&lt;/P&gt;&lt;P&gt;329423: *Jun 23 09:28:31.179 PAK: TPLUS(00000082)/1/READ/641C166C: timed out, clean up&lt;/P&gt;&lt;P&gt;329424: *Jun 23 09:28:31.179 PAK: TPLUS(00000082)/1/641C166C: Processing the reply packet&lt;/P&gt;&lt;P&gt;329425: *Jun 23 09:28:32.467 PAK: AAA: parse name=tty163 idb type=-1 tty=-1&lt;/P&gt;&lt;P&gt;329426: *Jun 23 09:28:32.467 PAK: AAA: name=tty163 flags=0x11 type=5 shelf=0 slot=0 adapter=0 port=163 channel=0&lt;/P&gt;&lt;P&gt;329427: *Jun 23 09:28:32.467 PAK: AAA/MEMORY: create_user (0x6461EB48) user='paknt' ruser='NULL' ds0=0 port='tty163' rem_addr='192.168.1.199' authen_type=ASCII service=ENABLE priv=15 initial_task_id='0', vrf= (id=0)&lt;/P&gt;&lt;P&gt;329428: *Jun 23 09:28:32.467 PAK: AAA/AUTHEN/START (238219777): port='tty163' list='' action=LOGIN service=ENABLE&lt;/P&gt;&lt;P&gt;329429: *Jun 23 09:28:32.467 PAK: AAA/AUTHEN/START (238219777): non-console enable - default to enable password&lt;/P&gt;&lt;P&gt;329430: *Jun 23 09:28:32.467 PAK: AAA/AUTHEN/START (238219777): Method=ENABLE&lt;/P&gt;&lt;P&gt;329431: *Jun 23 09:28:32.467 PAK: AAA/AUTHEN(238219777): Status=GETPASS&lt;/P&gt;&lt;P&gt;329432: *Jun 23 09:28:35.375 PAK: %FAN-3-FAN_FAILED: Fan 1 had a rotation error reported.&lt;/P&gt;&lt;P&gt;329433: *Jun 23 09:28:40.395 PAK: AAA/AUTHEN/CONT (238219777): continue_login (user='(undef)')&lt;/P&gt;&lt;P&gt;329434: *Jun 23 09:28:40.395 PAK: AAA/AUTHEN(238219777): Status=GETPASS&lt;/P&gt;&lt;P&gt;329435: *Jun 23 09:28:40.395 PAK: AAA/AUTHEN/CONT (238219777): Method=ENABLE&lt;/P&gt;&lt;P&gt;329436: *Jun 23 09:28:40.399 PAK: AAA/AUTHEN(238219777): Status=PASS&lt;/P&gt;&lt;P&gt;329437: *Jun 23 09:28:40.399 PAK: AAA/MEMORY: free_user (0x6461EB48) user='NULL' ruser='NULL' port='tty163' rem_addr='192.168.1.199' authen_type=ASCII service=ENABLE priv=15 vrf= (id=0)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2008 12:00:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122414#M419339</guid>
      <dc:creator>Amin Shaikh</dc:creator>
      <dc:date>2008-08-22T12:00:10Z</dc:date>
    </item>
    <item>
      <title>Re: Local Account Authentication - Concern</title>
      <link>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122415#M419340</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is 'paknt' a local user or a user on Tacacs server ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2008 12:13:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122415#M419340</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2008-08-22T12:13:50Z</dc:date>
    </item>
    <item>
      <title>Re: Local Account Authentication - Concern</title>
      <link>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122416#M419341</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Its a local user created on Router, no such user exists on ACS Box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2008 14:35:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122416#M419341</guid>
      <dc:creator>Amin Shaikh</dc:creator>
      <dc:date>2008-08-22T14:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: Local Account Authentication - Concern</title>
      <link>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122417#M419342</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Either something is not right the way your Tacacs is responding or something not right on the code, check this,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;329420: *Jun 23 09:28:26.179 PAK: TPLUS(00000082)/1/WRITE/641C166C: Started 5 sec timeout&lt;/P&gt;&lt;P&gt;329421: *Jun 23 09:28:26.179 PAK: TPLUS(00000082)/1/WRITE: wrote entire 27 bytes request&lt;/P&gt;&lt;P&gt;329422: *Jun 23 09:28:31.179 PAK: TPLUS(00000082)/1/READ/641C166C: timed out&lt;/P&gt;&lt;P&gt;329423: *Jun 23 09:28:31.179 PAK: TPLUS(00000082)/1/READ/641C166C: timed out, clean up&lt;/P&gt;&lt;P&gt;329424: *Jun 23 09:28:31.179 PAK: TPLUS(00000082)/1/641C166C: Processing the reply packet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After device sent the credentials to the TACACS server @ 09:28:26.179, The device started the 5sec timeout. And could not get a reply back from the authentication server in 5 sec i.e. (09:28:26.179 + 5 = 09:28:31.179), so device timed out on the Tacacs reply @ 09:28:31.179.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This triggered the fallback method, though IOS has not ozzed the fallback related debugs as I expected. But one thing is for sure, the device is timing out on the Tacacs reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are my suggestions.&lt;/P&gt;&lt;P&gt;- Increase the tacacs server timeout,&lt;/P&gt;&lt;P&gt;  tacacs-server timeout &lt;N&gt; (default is 5sec)&lt;/N&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Or try some other code.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To take a look at good debugs with your/similar configuration check the attachment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate if it helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2008 15:56:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122417#M419342</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2008-08-22T15:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: Local Account Authentication - Concern</title>
      <link>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122418#M419343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It looks to me like there is some issue on the TACACS server. The server is there and is at least somewhat active in the beginning of the transaction. The router sends the beginning of the transaction to the server and the router gets some resonse from the server as shown in:&lt;/P&gt;&lt;P&gt;329415: *Jun 23 09:28:16.771 PAK: TPLUS(00000082)/1/641C1728: Processing the reply packet &lt;/P&gt;&lt;P&gt;329416: *Jun 23 09:28:16.771 PAK: TPLUS: Received authen response status GET_PASSWORD (8) &lt;/P&gt;&lt;P&gt;but then the router sends the password, waits for a response, and gets no response. So it times out and falls back to local authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2008 16:20:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122418#M419343</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2008-08-22T16:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: Local Account Authentication - Concern</title>
      <link>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122419#M419344</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As you have already told "paknt" is a local user account and no such user exists on Tacacs. So what I feel, if no such user is available on TAcacs, it will look for same user credentials on local database. You try to make one more user with same user name i.e. "paknt" and set different password for it....then try again. Then it should login with Tacacs username/password pair not with local user/password pair.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Sep 2008 14:47:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-account-authentication-concern/m-p/1122419#M419344</guid>
      <dc:creator>pranuv.pandit</dc:creator>
      <dc:date>2008-09-05T14:47:22Z</dc:date>
    </item>
  </channel>
</rss>

