<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Understanding this TACACS Debug in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/understanding-this-tacacs-debug/m-p/716857#M420382</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The "check keys" message would seem to indicate the shared secret doesnt match the one on the AAA server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 15 Jun 2007 14:51:52 GMT</pubDate>
    <dc:creator>darpotter</dc:creator>
    <dc:date>2007-06-15T14:51:52Z</dc:date>
    <item>
      <title>Understanding this TACACS Debug</title>
      <link>https://community.cisco.com/t5/network-access-control/understanding-this-tacacs-debug/m-p/716855#M420380</link>
      <description>&lt;P&gt;01:19:44: TAC+: Invalid AUTHEN/START/LOGIN/ASCII packet (check keys).&lt;/P&gt;&lt;P&gt;01:19:44: TAC+: Closing TCP/IP 0xAC5F14 connection to 10.52.166.119/49&lt;/P&gt;&lt;P&gt;01:19:44: TAC+: Using default tacacs server-group "tacacs+" list.&lt;/P&gt;&lt;P&gt;01:19:46: TAC+: Using default tacacs server-group "tacacs+" list.&lt;/P&gt;&lt;P&gt;01:19:46: TAC+: Opening TCP/IP to 10.52.166.119/49 timeout=5&lt;/P&gt;&lt;P&gt;01:19:46: TAC+: Opened TCP/IP handle 0xABDD68 to 10.52.166.119/49&lt;/P&gt;&lt;P&gt;01:19:46: TAC+: 10.52.166.119 (2254716401) ACCT/REQUEST/STOP queued&lt;/P&gt;&lt;P&gt;01:19:46: TAC+: (2254716401) ACCT/REQUEST/STOP processed&lt;/P&gt;&lt;P&gt;01:19:46: TAC+: received bad ACCT packet: type = 0, expected 3&lt;/P&gt;&lt;P&gt;01:19:46: TAC+: Invalid ACCT/REQUEST/STOP packet (check keys).&lt;/P&gt;&lt;P&gt;01:19:46: TAC+: Closing TCP/IP 0xABDD68 connection to 10.52.166.119/49&lt;/P&gt;&lt;P&gt;01:19:46: TAC+: Using default tacacs server-group "tacacs+" list.&lt;/P&gt;&lt;P&gt;01:20:19: TAC+: Using default tacacs server-group "tacacs+" list.&lt;/P&gt;&lt;P&gt;01:20:19: TAC+: Opening TCP/IP to 10.52.166.119/49 timeout=5&lt;/P&gt;&lt;P&gt;01:20:19: TAC+: Opened TCP/IP handle 0xAC5F14 to 10.52.166.119/49&lt;/P&gt;&lt;P&gt;01:20:19: TAC+: 10.52.166.119 (726398633) ACCT/REQUEST/STOP queued&lt;/P&gt;&lt;P&gt;01:20:19: TAC+: (726398633) ACCT/REQUEST/STOP processed&lt;/P&gt;&lt;P&gt;01:20:19: TAC+: received bad ACCT packet: type = 0, expected 3&lt;/P&gt;&lt;P&gt;01:20:19: TAC+: Invalid ACCT/REQUEST/STOP packet (check keys).&lt;/P&gt;&lt;P&gt;01:20:19: TAC+: Closing TCP/IP 0xAC5F14 connection to 10.52.166.119/49&lt;/P&gt;&lt;P&gt;01:20:19: TAC+: Using default tacacs server-group "tacacs+" list.&lt;/P&gt;&lt;P&gt;01:20:19: TAC+: Using default tacacs server-group "tacacs+" list.&lt;/P&gt;&lt;P&gt;01:20:19: TAC+: Opening TCP/IP to 10.52.166.119/49 timeout=5&lt;/P&gt;&lt;P&gt;01:20:19: TAC+: Opened TCP/IP handle 0xABDD68 to 10.52.166.119/49&lt;/P&gt;&lt;P&gt;01:20:19: TAC+: 10.52.166.119 (1195930714) ACCT/REQUEST/STOP queued&lt;/P&gt;&lt;P&gt;01:20:20: TAC+: (1195930714) ACCT/REQUEST/STOP processed&lt;/P&gt;&lt;P&gt;01:20:20: TAC+: received bad ACCT packet: type = 0, expected 3&lt;/P&gt;&lt;P&gt;01:20:20: TAC+: Invalid ACCT/REQUEST/STOP packet (check keys).&lt;/P&gt;&lt;P&gt;01:20:20: TAC+: Closing TCP/IP 0xABDD68 connection to 10.52.166.119/49&lt;/P&gt;&lt;P&gt;01:20:20: TAC+: Using default tacacs server-group "tacacs+" list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anybody help me understand this TACACS debug that I get when I try and authenticate on this device using TACACS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:13:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/understanding-this-tacacs-debug/m-p/716855#M420380</guid>
      <dc:creator>daniel.bowen</dc:creator>
      <dc:date>2019-03-10T22:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding this TACACS Debug</title>
      <link>https://community.cisco.com/t5/network-access-control/understanding-this-tacacs-debug/m-p/716856#M420381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is some info :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;01:19:44: TAC+: Using default tacacs server-group "tacacs+" list.&lt;/P&gt;&lt;P&gt;01:19:46: TAC+: Using default tacacs server-group "tacacs+" list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is using default configured tacacs list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;01:19:46: TAC+: Opening TCP/IP to 10.52.166.119/49 timeout=5&lt;/P&gt;&lt;P&gt;01:19:46: TAC+: Opened TCP/IP handle 0xABDD68 to 10.52.166.119/49&lt;/P&gt;&lt;P&gt;01:19:46: TAC+: 10.52.166.119 (2254716401) ACCT/REQUEST/STOP queued &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here it is trying to make a connection with tacacs server on port 49 ( default tacacs port), request is queued.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;01:19:46: TAC+: (2254716401) ACCT/REQUEST/STOP processed&lt;/P&gt;&lt;P&gt;01:19:46: TAC+: received bad ACCT packet: type = 0, expected 3&lt;/P&gt;&lt;P&gt;01:19:46: TAC+: Invalid ACCT/REQUEST/STOP packet (check keys).&lt;/P&gt;&lt;P&gt;01:19:46: TAC+: Closing TCP/IP 0xABDD68 connection to 10.52.166.119/49 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here it is not getting any response from tacacs due to secret key mismatch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And loop goes on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please reenter aaa key on this device and acs , pls do not copy/paste&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also be aware that in ACS aaa client key take precedence over NDG key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how that goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jagdeep&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jun 2007 11:43:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/understanding-this-tacacs-debug/m-p/716856#M420381</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2007-06-15T11:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: Understanding this TACACS Debug</title>
      <link>https://community.cisco.com/t5/network-access-control/understanding-this-tacacs-debug/m-p/716857#M420382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The "check keys" message would seem to indicate the shared secret doesnt match the one on the AAA server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jun 2007 14:51:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/understanding-this-tacacs-debug/m-p/716857#M420382</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2007-06-15T14:51:52Z</dc:date>
    </item>
  </channel>
</rss>

