<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with ACS authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/problem-with-acs-authentication/m-p/746919#M421033</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And the output of "debug tacacs"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My output looks like this: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apr 17 11:30:27: TAC+: send AUTHEN/START packet ver=192 id=3801177964&lt;/P&gt;&lt;P&gt;Apr 17 11:30:27: TAC+: Using default tacacs server-group "tacacs+" list.&lt;/P&gt;&lt;P&gt;Apr 17 11:30:27: TAC+: Opening TCP/IP to 10.10.10.24/49 timeout=5&lt;/P&gt;&lt;P&gt;Apr 17 11:30:27: TAC+: Opened TCP/IP handle 0x80EC2700 to 10.10.10.24/49&lt;/P&gt;&lt;P&gt;Apr 17 11:30:27: TAC+: 10.10.10.24 (3801177964) AUTHEN/START/LOGIN/ASCII queued&lt;/P&gt;&lt;P&gt;Apr 17 11:30:28: TAC+: (3801177964) AUTHEN/START/LOGIN/ASCII processed&lt;/P&gt;&lt;P&gt;Apr 17 11:30:28: TAC+: ver=192 id=3801177964 received AUTHEN status = GETPASS&lt;/P&gt;&lt;P&gt;Apr 17 11:30:31: TAC+: send AUTHEN/CONT packet id=3801177964&lt;/P&gt;&lt;P&gt;Apr 17 11:30:31: TAC+: 10.10.10.24 (3801177964) AUTHEN/CONT queued&lt;/P&gt;&lt;P&gt;Apr 17 11:30:31: TAC+: (3801177964) AUTHEN/CONT processed&lt;/P&gt;&lt;P&gt;Apr 17 11:30:31: TAC+: ver=192 id=3801177964 received AUTHEN status = PASS&lt;/P&gt;&lt;P&gt;Apr 17 11:30:31: TAC+: Closing TCP/IP 0x80EC2700 connection to 10.10.10.24/49&lt;/P&gt;&lt;P&gt;Apr 17 11:30:31: TAC+: using previously set server 10.10.10.24 from group tacacs+&lt;/P&gt;&lt;P&gt;Apr 17 11:30:31: TAC+: Opening TCP/IP to 10.10.10.24/49 timeout=5&lt;/P&gt;&lt;P&gt;Apr 17 11:30:31: TAC+: Opened TCP/IP handle 0x80ED50DC to 10.10.10.24/49&lt;/P&gt;&lt;P&gt;Apr 17 11:30:31: TAC+: Opened 10.10.10.24 index=1&lt;/P&gt;&lt;P&gt;Apr 17 11:30:31: TAC+: 10.10.10.24 (3808800626) AUTHOR/START queued&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: (3808800626) AUTHOR/START processed&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: (3808800626): received author response status = PASS_ADD&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: Closing TCP/IP 0x80ED50DC connection to 10.10.10.24/49&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: Received Attribute "priv-lvl=15"&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: using previously set server 10.10.10.24 from group tacacs+&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: Opening TCP/IP to 10.10.10.24/49 timeout=5&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: Opened TCP/IP handle 0x80EC2B94 to 10.10.10.24/49&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: Opened 10.10.10.24 index=1&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: 10.10.10.24 (422749886) ACCT/REQUEST/START queued&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: (422749886) ACCT/REQUEST/START processed&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: (422749886): received acct response status = SUCCESS&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: Closing TCP/IP 0x80EC2B94 connection to 10.10.10.24/49&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What TACACS+ server are you using?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Apr 2007 10:35:07 GMT</pubDate>
    <dc:creator>Craig Balfour</dc:creator>
    <dc:date>2007-04-17T10:35:07Z</dc:date>
    <item>
      <title>Problem with ACS authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-acs-authentication/m-p/746914#M421026</link>
      <description>&lt;P&gt;I'm busy upgrading our network at the moment and we're replacing the archaic switches with new 3750s.  At one of the sites, the new switch didn't boot up, so I configured a 2950 as a temporary solution.  My problems is with TACACS authentication.  I'm using TACACS as the first method of authentication, with local database as backup.  But TACACS authentication isn't happening.  It just skips straight past method 1 to local authentication.  The TACACS servers are up and running as other devices are authenticating correctly and this 2950 can ping the servers in question.  The key is entered correctly as well.  Any suggestions?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:06:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-acs-authentication/m-p/746914#M421026</guid>
      <dc:creator>chris.snyman</dc:creator>
      <dc:date>2019-03-10T22:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ACS authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-acs-authentication/m-p/746915#M421027</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The TACACS+ configuration for the Catalyst 3750 and 2950 should be identical. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does your AAA configuration on the 2950 look like? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It should look something like this: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting system default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;tacacs-server host 10.10.10.24&lt;/P&gt;&lt;P&gt;tacacs-server key 7 0329483905743665657&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does the output of "debug aaa authentication" look like?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For a successful TACACS+ login I get the following: &lt;/P&gt;&lt;P&gt;Apr 17 08:06:07: AAA/AUTHEN/START (1370004964): port='tty2' list='' action=LOGIN service=LOGIN&lt;/P&gt;&lt;P&gt;Apr 17 08:06:07: AAA/AUTHEN/START (1370004964): Restart&lt;/P&gt;&lt;P&gt;Apr 17 08:06:07: AAA/AUTHEN/START (1370004964): Method=tacacs+ (tacacs+)&lt;/P&gt;&lt;P&gt;Apr 17 08:06:07: TAC+: send AUTHEN/START packet ver=192 id=1370004964&lt;/P&gt;&lt;P&gt;Apr 17 08:06:07: TAC+: ver=192 id=1370004964 received AUTHEN status = GETPASS&lt;/P&gt;&lt;P&gt;Apr 17 08:06:07: AAA/AUTHEN (1370004964): status = GETPASS&lt;/P&gt;&lt;P&gt;Apr 17 08:06:20: AAA/AUTHEN/CONT (1370004964): continue_login (user='craig')&lt;/P&gt;&lt;P&gt;Apr 17 08:06:20: AAA/AUTHEN (1370004964): status = GETPASS&lt;/P&gt;&lt;P&gt;Apr 17 08:06:20: AAA/AUTHEN (1370004964): Method=tacacs+ (tacacs+)&lt;/P&gt;&lt;P&gt;Apr 17 08:06:20: TAC+: send AUTHEN/CONT packet id=1370004964&lt;/P&gt;&lt;P&gt;Apr 17 08:06:21: TAC+: ver=192 id=1370004964 received AUTHEN status = PASS&lt;/P&gt;&lt;P&gt;Apr 17 08:06:21: AAA/AUTHEN (1370004964): status = PASS&lt;/P&gt;&lt;P&gt;Apr 17 08:06:21: TAC+: (2581335929): received author response status = PASS_ADD&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2007 07:08:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-acs-authentication/m-p/746915#M421027</guid>
      <dc:creator>Craig Balfour</dc:creator>
      <dc:date>2007-04-17T07:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ACS authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-acs-authentication/m-p/746916#M421028</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authentication ppp default local&lt;/P&gt;&lt;P&gt;aaa accounting suppress null-username&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting network default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting connection default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting system default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;tacacs-server key correctkey&lt;/P&gt;&lt;P&gt;tacacs-server host 10.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The correct IPs have been ommited, but are correct in the configs and the switch can ping all four of the servers.  I'm not on site at the moment, but when I Telnet into the device and use the debug command, it gives me no output whatsoever.  It's as if it just skips the TACACS+ authentication completely.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2007 08:14:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-acs-authentication/m-p/746916#M421028</guid>
      <dc:creator>chris.snyman</dc:creator>
      <dc:date>2007-04-17T08:14:15Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ACS authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-acs-authentication/m-p/746917#M421029</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To get the switch debugging output via telnet you probably need to do the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;logging console &lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;debug aaa authentication&lt;/P&gt;&lt;P&gt;terminal mon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should see aaa authentication debugging as long as you are using "aaa new-model" - even if you are using local and not TACACS+.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2007 08:47:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-acs-authentication/m-p/746917#M421029</guid>
      <dc:creator>Craig Balfour</dc:creator>
      <dc:date>2007-04-17T08:47:21Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ACS authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-acs-authentication/m-p/746918#M421030</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks.  That worked!  This is what I get when entering enable mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apr 17 11:52:27: AAA/MEMORY: dup_user (0x80CD1528) user='root' ruser='' port='tt&lt;/P&gt;&lt;P&gt;y1' rem_addr='10.247.81.22' authen_type=ASCII service=ENABLE priv=15 source='AAA&lt;/P&gt;&lt;P&gt; dup enable'&lt;/P&gt;&lt;P&gt;Apr 17 11:52:27: AAA/AUTHEN/START (3171050843): port='tty1' list='' action=LOGIN&lt;/P&gt;&lt;P&gt; service=ENABLE&lt;/P&gt;&lt;P&gt;Apr 17 11:52:27: AAA/AUTHEN/START (3171050843): using "default" list&lt;/P&gt;&lt;P&gt;Apr 17 11:52:27: AAA/AUTHEN/START (3171050843): Method=tacacs+ (tacacs+)&lt;/P&gt;&lt;P&gt;Apr 17 11:52:27: TAC+: send AUTHEN/START packet ver=192 id=3171050843&lt;/P&gt;&lt;P&gt;Apr 17 11:52:28: AAA/AUTHEN (3171050843): status = ERROR&lt;/P&gt;&lt;P&gt;Apr 17 11:52:28: AAA/AUTHEN/START (3171050843): Method=ENABLE&lt;/P&gt;&lt;P&gt;Apr 17 11:52:28: AAA/AUTHEN (3171050843): status = GETPASS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2007 08:54:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-acs-authentication/m-p/746918#M421030</guid>
      <dc:creator>chris.snyman</dc:creator>
      <dc:date>2007-04-17T08:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ACS authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-acs-authentication/m-p/746919#M421033</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And the output of "debug tacacs"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My output looks like this: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apr 17 11:30:27: TAC+: send AUTHEN/START packet ver=192 id=3801177964&lt;/P&gt;&lt;P&gt;Apr 17 11:30:27: TAC+: Using default tacacs server-group "tacacs+" list.&lt;/P&gt;&lt;P&gt;Apr 17 11:30:27: TAC+: Opening TCP/IP to 10.10.10.24/49 timeout=5&lt;/P&gt;&lt;P&gt;Apr 17 11:30:27: TAC+: Opened TCP/IP handle 0x80EC2700 to 10.10.10.24/49&lt;/P&gt;&lt;P&gt;Apr 17 11:30:27: TAC+: 10.10.10.24 (3801177964) AUTHEN/START/LOGIN/ASCII queued&lt;/P&gt;&lt;P&gt;Apr 17 11:30:28: TAC+: (3801177964) AUTHEN/START/LOGIN/ASCII processed&lt;/P&gt;&lt;P&gt;Apr 17 11:30:28: TAC+: ver=192 id=3801177964 received AUTHEN status = GETPASS&lt;/P&gt;&lt;P&gt;Apr 17 11:30:31: TAC+: send AUTHEN/CONT packet id=3801177964&lt;/P&gt;&lt;P&gt;Apr 17 11:30:31: TAC+: 10.10.10.24 (3801177964) AUTHEN/CONT queued&lt;/P&gt;&lt;P&gt;Apr 17 11:30:31: TAC+: (3801177964) AUTHEN/CONT processed&lt;/P&gt;&lt;P&gt;Apr 17 11:30:31: TAC+: ver=192 id=3801177964 received AUTHEN status = PASS&lt;/P&gt;&lt;P&gt;Apr 17 11:30:31: TAC+: Closing TCP/IP 0x80EC2700 connection to 10.10.10.24/49&lt;/P&gt;&lt;P&gt;Apr 17 11:30:31: TAC+: using previously set server 10.10.10.24 from group tacacs+&lt;/P&gt;&lt;P&gt;Apr 17 11:30:31: TAC+: Opening TCP/IP to 10.10.10.24/49 timeout=5&lt;/P&gt;&lt;P&gt;Apr 17 11:30:31: TAC+: Opened TCP/IP handle 0x80ED50DC to 10.10.10.24/49&lt;/P&gt;&lt;P&gt;Apr 17 11:30:31: TAC+: Opened 10.10.10.24 index=1&lt;/P&gt;&lt;P&gt;Apr 17 11:30:31: TAC+: 10.10.10.24 (3808800626) AUTHOR/START queued&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: (3808800626) AUTHOR/START processed&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: (3808800626): received author response status = PASS_ADD&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: Closing TCP/IP 0x80ED50DC connection to 10.10.10.24/49&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: Received Attribute "priv-lvl=15"&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: using previously set server 10.10.10.24 from group tacacs+&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: Opening TCP/IP to 10.10.10.24/49 timeout=5&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: Opened TCP/IP handle 0x80EC2B94 to 10.10.10.24/49&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: Opened 10.10.10.24 index=1&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: 10.10.10.24 (422749886) ACCT/REQUEST/START queued&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: (422749886) ACCT/REQUEST/START processed&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: (422749886): received acct response status = SUCCESS&lt;/P&gt;&lt;P&gt;Apr 17 11:30:32: TAC+: Closing TCP/IP 0x80EC2B94 connection to 10.10.10.24/49&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What TACACS+ server are you using?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2007 10:35:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-acs-authentication/m-p/746919#M421033</guid>
      <dc:creator>Craig Balfour</dc:creator>
      <dc:date>2007-04-17T10:35:07Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ACS authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-acs-authentication/m-p/746920#M421035</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The encrypted key I was using isn't the same for both switch models.  I can only assume that the encryption algorithm used on the 3750 differs to that of the 2950.  When i typed in the unencrypted password, TACACS+ authentication kicked in immediately!  Thanks for the advice!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2007 10:58:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-acs-authentication/m-p/746920#M421035</guid>
      <dc:creator>chris.snyman</dc:creator>
      <dc:date>2007-04-17T10:58:21Z</dc:date>
    </item>
  </channel>
</rss>

