<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic aaa auth failed via ACS, but prompts for enable password in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-auth-failed-via-acs-but-prompts-for-enable-password/m-p/732455#M421220</link>
    <description>&lt;P&gt;I have aaa working on a switch in my network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The prolem I have is when a user fails the password authentication with a known ldap user, it prompts them for the enable password. If that user enters the enable password, they are then logged into the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like for the enable password prompt to only come up if the AAA server is unavailable. Oddly enough, if I was to type in a user that doesn't exist in our LDAP tree, and type a bogus password, the enable password prompt never comes up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User Joe(In ldap tree)&lt;/P&gt;&lt;P&gt;username: joe&lt;/P&gt;&lt;P&gt;password: &amp;lt;mis types password&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;enable password: &amp;lt;---they can now enter the enable password here&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User Jimmy (not in ldap tree)&lt;/P&gt;&lt;P&gt;username: jimmy&lt;/P&gt;&lt;P&gt;password: &amp;lt;---anything cuz jimmy isn't in tree&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username: &amp;lt;--prompts for username again&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regardless if they are in the tree or not, I want it to prompt for the username and force them to log in through ldap.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions? Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 22:03:30 GMT</pubDate>
    <dc:creator>dbobeldyk</dc:creator>
    <dc:date>2019-03-10T22:03:30Z</dc:date>
    <item>
      <title>aaa auth failed via ACS, but prompts for enable password</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-auth-failed-via-acs-but-prompts-for-enable-password/m-p/732455#M421220</link>
      <description>&lt;P&gt;I have aaa working on a switch in my network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The prolem I have is when a user fails the password authentication with a known ldap user, it prompts them for the enable password. If that user enters the enable password, they are then logged into the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like for the enable password prompt to only come up if the AAA server is unavailable. Oddly enough, if I was to type in a user that doesn't exist in our LDAP tree, and type a bogus password, the enable password prompt never comes up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User Joe(In ldap tree)&lt;/P&gt;&lt;P&gt;username: joe&lt;/P&gt;&lt;P&gt;password: &amp;lt;mis types password&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;enable password: &amp;lt;---they can now enter the enable password here&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User Jimmy (not in ldap tree)&lt;/P&gt;&lt;P&gt;username: jimmy&lt;/P&gt;&lt;P&gt;password: &amp;lt;---anything cuz jimmy isn't in tree&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username: &amp;lt;--prompts for username again&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regardless if they are in the tree or not, I want it to prompt for the username and force them to log in through ldap.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions? Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:03:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-auth-failed-via-acs-but-prompts-for-enable-password/m-p/732455#M421220</guid>
      <dc:creator>dbobeldyk</dc:creator>
      <dc:date>2019-03-10T22:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: aaa auth failed via ACS, but prompts for enable password</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-auth-failed-via-acs-but-prompts-for-enable-password/m-p/732456#M421221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looks like there is a failover on "Fail" instead of failover on "Error". Never seen it happen before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What Radius/Tacacs Server are you using ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you show the aaa config from the device and maybe debugs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vivek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Mar 2007 20:17:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-auth-failed-via-acs-but-prompts-for-enable-password/m-p/732456#M421221</guid>
      <dc:creator>Vivek Santuka</dc:creator>
      <dc:date>2007-03-26T20:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: aaa auth failed via ACS, but prompts for enable password</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-auth-failed-via-acs-but-prompts-for-enable-password/m-p/732457#M421222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;TACACS Server: Cisco Secure ACS 4.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config fragment (scrubbed):&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ siteTACACS&lt;/P&gt;&lt;P&gt; server x.x.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication banner ^C&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unauthorized use strictly prohibited.&lt;/P&gt;&lt;P&gt;Please login with your LDAP credentials&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;^C&lt;/P&gt;&lt;P&gt;aaa authentication fail-message ^C&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I.m sorry, your login credentials failed. Please try again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;^C&lt;/P&gt;&lt;P&gt;aaa authentication password-prompt Enable-Password:&lt;/P&gt;&lt;P&gt;aaa authentication login default enable&lt;/P&gt;&lt;P&gt;aaa authentication login siteMethodList group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa accounting exec siteAccountingList start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 siteAccountingList start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; access-class 50 in&lt;/P&gt;&lt;P&gt; exec-timeout 120 0&lt;/P&gt;&lt;P&gt; password 7 xxxxxxx&lt;/P&gt;&lt;P&gt; accounting commands 15 siteAccountingList&lt;/P&gt;&lt;P&gt; accounting exec siteAccountingList&lt;/P&gt;&lt;P&gt; logging synchronous&lt;/P&gt;&lt;P&gt; login authentication siteMethodList&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Mar 2007 13:33:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-auth-failed-via-acs-but-prompts-for-enable-password/m-p/732457#M421222</guid>
      <dc:creator>dbobeldyk</dc:creator>
      <dc:date>2007-03-27T13:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: aaa auth failed via ACS, but prompts for enable password</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-auth-failed-via-acs-but-prompts-for-enable-password/m-p/732458#M421223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you tell me what happens if a wrong password is entered after changing :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default enable &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default none&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't think ACS would send an error on failed authentication. Looks more like an IOS problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vivek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Mar 2007 15:28:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-auth-failed-via-acs-but-prompts-for-enable-password/m-p/732458#M421223</guid>
      <dc:creator>Vivek Santuka</dc:creator>
      <dc:date>2007-03-27T15:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: aaa auth failed via ACS, but prompts for enable password</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-auth-failed-via-acs-but-prompts-for-enable-password/m-p/732459#M421224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I placed the aaa authen login default none command in, but the behavior is still the same.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Mar 2007 16:21:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-auth-failed-via-acs-but-prompts-for-enable-password/m-p/732459#M421224</guid>
      <dc:creator>dbobeldyk</dc:creator>
      <dc:date>2007-03-27T16:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: aaa auth failed via ACS, but prompts for enable password</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-auth-failed-via-acs-but-prompts-for-enable-password/m-p/732460#M421225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Along the same sort of thinking I tried:&lt;/P&gt;&lt;P&gt;aaa authentication login siteMethodList group tacacs+ none&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I entered the wrong password.... it automatically let me in...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not exactly the security I'd be looking for. My understanding is that if the first method returns a fail, it won't try the second one. Is there  flag or hook somewhere I have to set to enforce that type of behavior?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Mar 2007 16:28:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-auth-failed-via-acs-but-prompts-for-enable-password/m-p/732460#M421225</guid>
      <dc:creator>dbobeldyk</dc:creator>
      <dc:date>2007-03-27T16:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: aaa auth failed via ACS, but prompts for enable password</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-auth-failed-via-acs-but-prompts-for-enable-password/m-p/732461#M421226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi dbobeldyk,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am facing the problem in loging through TACACS LDAP ID,but i can able to login through Local login.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;configuration present in my router is:&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login Masis group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization console&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;P&gt;aaa authorization exec Masis group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 10 Masis group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 Masis group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa accounting exec Masis start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 Masis start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 Masis start-stop group tacacs+&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;tacacs-server host 172.*.*.* key ****&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; exec-timeout 5 0&lt;/P&gt;&lt;P&gt; authorization commands 15 Masis&lt;/P&gt;&lt;P&gt; authorization commands 1 Masis&lt;/P&gt;&lt;P&gt; authorization exec Masis&lt;/P&gt;&lt;P&gt; accounting connection Masis&lt;/P&gt;&lt;P&gt; accounting commands 1 Masis&lt;/P&gt;&lt;P&gt; accounting commands 15 Masis&lt;/P&gt;&lt;P&gt; accounting exec Masis&lt;/P&gt;&lt;P&gt; login authentication Masis&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line vty 5 15&lt;/P&gt;&lt;P&gt; exec-timeout 5 0&lt;/P&gt;&lt;P&gt; authorization commands 15 Masis&lt;/P&gt;&lt;P&gt; authorization commands 1 Masis&lt;/P&gt;&lt;P&gt; authorization exec Masis&lt;/P&gt;&lt;P&gt; accounting connection Masis&lt;/P&gt;&lt;P&gt; accounting commands 1 Masis&lt;/P&gt;&lt;P&gt; accounting commands 15 Masis&lt;/P&gt;&lt;P&gt; accounting exec Masis&lt;/P&gt;&lt;P&gt; login authentication Masis&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What may be the problem and how to trouble shoot it..&lt;/P&gt;&lt;P&gt;Please give the solution for my problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Apr 2007 12:41:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-auth-failed-via-acs-but-prompts-for-enable-password/m-p/732461#M421226</guid>
      <dc:creator>mtechnology</dc:creator>
      <dc:date>2007-04-01T12:41:30Z</dc:date>
    </item>
    <item>
      <title>Re: aaa auth failed via ACS, but prompts for enable password</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-auth-failed-via-acs-but-prompts-for-enable-password/m-p/732462#M421227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If I am understanding corretly the authentication through tacacs is not working but the authentication local is working. If authentication through tacacs is not working there are several things that it could be. I suggest that you check on these things:&lt;/P&gt;&lt;P&gt;- verify that the configured address for the tacacs server is correct.&lt;/P&gt;&lt;P&gt;- do you have IP connectivity to the tacacs server? Do an extended ping specifying the server address as the destination and specifying the source of the ping. If you have more than one interface that could be used to get to the tacacs server it is helpful to use ip tacacs source-address to specify which interface address to use (this can be important since the tacacs server can only be configured to recognize one address from this router). You want to be sure that you have a route and a valid path to the server and that the server has a route and a valid path back to you.&lt;/P&gt;&lt;P&gt;- if you do have IP connectivity, then look for the possibility that an access list somewhere is not permitting the tacacs request or response to go through.&lt;/P&gt;&lt;P&gt;- Verify that the key that you configured on the router is the same as the key you configured on the server.&lt;/P&gt;&lt;P&gt;- check the logs on the server. is it seeing the request from the router? if it is seeing the request and not authenticating then look in the failed attempts report and see why the server is not authenticating.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Apr 2007 18:43:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-auth-failed-via-acs-but-prompts-for-enable-password/m-p/732462#M421227</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2007-04-01T18:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: aaa auth failed via ACS, but prompts for enable password</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-auth-failed-via-acs-but-prompts-for-enable-password/m-p/732463#M421228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems that the ACS is returning an ERROR. I think it should be returning a FAIL perhaps?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug log shown here:&lt;/P&gt;&lt;P&gt;MAN-209-TestSwitch#&lt;/P&gt;&lt;P&gt;Apr  5 10:25:33.413: AAA/AUTHEN/CONT (408942267): continue_login (user='bobeldde')&lt;/P&gt;&lt;P&gt;Apr  5 10:25:33.417: AAA/AUTHEN (408942267): status = GETPASS&lt;/P&gt;&lt;P&gt;Apr  5 10:25:33.417: AAA/AUTHEN (408942267): Method=tacacs+ (tacacs+)&lt;/P&gt;&lt;P&gt;Apr  5 10:25:33.417: TAC+: send AUTHEN/CONT packet id=408942267&lt;/P&gt;&lt;P&gt;Apr  5 10:25:33.417: TAC+: periodic timer started&lt;/P&gt;&lt;P&gt;Apr  5 10:25:33.417: TAC+: x.x.x.x req=80BC03B8 Qd id=408942267 ver=192 handle=0x80D7447C (ESTAB) expire=5 AUTHEN/CONT queued&lt;/P&gt;&lt;P&gt;Apr  5 10:25:33.417: TAC+: x.x.x.x (408942267) AUTHEN/CONT queued&lt;/P&gt;&lt;P&gt;Apr  5 10:25:33.517: TAC+: x.x.x.x ESTAB id=408942267 wrote 19 of 19 bytes&lt;/P&gt;&lt;P&gt;MAN-209-TestSwitch#&lt;/P&gt;&lt;P&gt;Apr  5 10:25:33.517: TAC+: x.x.x.x req=80BC03B8 Qd id=408942267 ver=192 handle=0x80D7447C (ESTAB) expire=4 AUTHEN/CONT sent&lt;/P&gt;&lt;P&gt;MAN-209-TestSwitch#&lt;/P&gt;&lt;P&gt;Apr  5 10:25:38.417: TAC+: x.x.x.x (408942267) AUTHEN/CONT -- TIMED OUT&lt;/P&gt;&lt;P&gt;Apr  5 10:25:38.417: TAC+: req=80BC03B8 Tx id=408942267 ver=192 handle=0x80D7447C (ESTAB) expire=0 AUTHEN/CONT processed&lt;/P&gt;&lt;P&gt;Apr  5 10:25:38.417: TAC+: (408942267) AUTHEN/CONT processed&lt;/P&gt;&lt;P&gt;Apr  5 10:25:38.417: TAC+: periodic timer stopped (queue empty)&lt;/P&gt;&lt;P&gt;Apr  5 10:25:38.417: TAC+: Error sending continue packet.&lt;/P&gt;&lt;P&gt;Apr  5 10:25:38.417: TAC+: Closing TCP/IP 0x80D7447C connection to x.x.x.x/49&lt;/P&gt;&lt;P&gt;Apr  5 10:25:38.421: AAA/AUTHEN (408942267): status = ERROR&lt;/P&gt;&lt;P&gt;Apr  5 10:25:38.421: AAA/AUTHEN/START (209030656): port='tty2' list='' action=LOGIN service=LOGIN&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2007 14:43:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-auth-failed-via-acs-but-prompts-for-enable-password/m-p/732463#M421228</guid>
      <dc:creator>dbobeldyk</dc:creator>
      <dc:date>2007-04-05T14:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: aaa auth failed via ACS, but prompts for enable password</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-auth-failed-via-acs-but-prompts-for-enable-password/m-p/732464#M421229</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;tacacs-server timeout 30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above command solved my problem. It appears that there is a default of 5 seconds for the acs server to respond. The ldap query (and fail) was taking longer than the default 5 seconds. I up'ed the timeout to 30 seconds which allowed for enough time to return a FAIL, aso opposed to the ERROR it was returning.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2007 15:55:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-auth-failed-via-acs-but-prompts-for-enable-password/m-p/732464#M421229</guid>
      <dc:creator>dbobeldyk</dc:creator>
      <dc:date>2007-04-12T15:55:46Z</dc:date>
    </item>
  </channel>
</rss>

