<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HTTP - ACS Authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/http-acs-authentication/m-p/754346#M419868</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have just replaced a couple of old switches in my network. 1 2940-8 running 12.1(19)EA1c software with a 2960G-8 running 12.2(35)SE and a 2950-12 running 12.1(22)EA1 with a 2960G-24 running 12.2(25)SEE2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I copied the settings across for aaa that runs on all the other switches but i cannot get http access now and network assistant is having problems accessing the switches. i also have installed 3560g 12.2(25)SEE3. This lets me login, loads the check screen but the asks me for my password again and wont let me go anyfurther. If I keep pressing cancel it eventually loads the web page with errors. These are settings on the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa accounting send stop-record authentication failure&lt;/P&gt;&lt;P&gt;aaa accounting system default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;ip http authentication aaa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host 172.16.61.61&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;tacacs-server key 7 **********&lt;/P&gt;&lt;P&gt;tacacs-server dns-alias-lookup&lt;/P&gt;&lt;P&gt;tacacs-server administration&lt;/P&gt;&lt;P&gt;radius-server source-ports 1645-1646&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The version of HTTP is 1.001.001&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could anybody help with the switch settings and do i need to make any changes on the acs server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 22:17:45 GMT</pubDate>
    <dc:creator>c01642643287</dc:creator>
    <dc:date>2019-03-10T22:17:45Z</dc:date>
    <item>
      <title>HTTP - ACS Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/http-acs-authentication/m-p/754346#M419868</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have just replaced a couple of old switches in my network. 1 2940-8 running 12.1(19)EA1c software with a 2960G-8 running 12.2(35)SE and a 2950-12 running 12.1(22)EA1 with a 2960G-24 running 12.2(25)SEE2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I copied the settings across for aaa that runs on all the other switches but i cannot get http access now and network assistant is having problems accessing the switches. i also have installed 3560g 12.2(25)SEE3. This lets me login, loads the check screen but the asks me for my password again and wont let me go anyfurther. If I keep pressing cancel it eventually loads the web page with errors. These are settings on the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa accounting send stop-record authentication failure&lt;/P&gt;&lt;P&gt;aaa accounting system default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;ip http authentication aaa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host 172.16.61.61&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;tacacs-server key 7 **********&lt;/P&gt;&lt;P&gt;tacacs-server dns-alias-lookup&lt;/P&gt;&lt;P&gt;tacacs-server administration&lt;/P&gt;&lt;P&gt;radius-server source-ports 1645-1646&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The version of HTTP is 1.001.001&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could anybody help with the switch settings and do i need to make any changes on the acs server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:17:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/http-acs-authentication/m-p/754346#M419868</guid>
      <dc:creator>c01642643287</dc:creator>
      <dc:date>2019-03-10T22:17:45Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP - ACS Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/http-acs-authentication/m-p/754347#M419872</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is something you should definitely take a look at,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/tech/tk59/technologies_tech_note09186a008069bdc5.shtml" target="_blank"&gt;http://www.cisco.com/en/US/tech/tk59/technologies_tech_note09186a008069bdc5.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BEGIN snip=""&gt;&lt;/BEGIN&gt;&lt;/P&gt;&lt;P&gt;Cisco IOS Software with the HTTP V1.1 Server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In releases of Cisco IOS Software with the HTTP V1.1 server, the HTTP sessions do not use vtys. They use sockets.&lt;/P&gt;&lt;P&gt;&lt;END snip=""&gt;&lt;/END&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go through above link, might help you out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Jul 2007 22:03:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/http-acs-authentication/m-p/754347#M419872</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2007-07-27T22:03:38Z</dc:date>
    </item>
  </channel>
</rss>

