<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Command authorization error when using aaa cache in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/command-authorization-error-when-using-aaa-cache/m-p/654208#M421737</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to use the aaa cache mode for command authorization. But when I execute a command there is always an error message:&lt;/P&gt;&lt;P&gt;% tty2 Unknown authorization method 6 set for list command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command is then always authorized against the tacacs server.&lt;/P&gt;&lt;P&gt;The 'authentication login', 'authentication enable' and 'authorization exec' are using the cache properly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried it with an Accesspoint AIR-AP1242AG-E-K9, IOS 12.3(8)JEA and a Catalyst WS-C3550-24PWR-SMI, IOS 12.2(35)SE with the same results. &lt;/P&gt;&lt;P&gt;Deleting the cache entry and using only the tacacs group the error message disappears.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;======&lt;/P&gt;&lt;P&gt;config&lt;/P&gt;&lt;P&gt;======&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ group_tacacs&lt;/P&gt;&lt;P&gt; server 10.10.10.10&lt;/P&gt;&lt;P&gt; server 10.10.10.11&lt;/P&gt;&lt;P&gt; cache expiry 12&lt;/P&gt;&lt;P&gt; cache authorization profile admin_user&lt;/P&gt;&lt;P&gt; cache authentication profile admin_user&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default cache group_tacacs group group_tacacs local&lt;/P&gt;&lt;P&gt;aaa authentication enable default cache group_tacacs group group_tacacs enable&lt;/P&gt;&lt;P&gt;aaa authorization console&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;P&gt;aaa authorization exec default cache group_tacacs group group_tacacs local&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default cache group_tacacs group group_tacacs local&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group group_tacacs&lt;/P&gt;&lt;P&gt;aaa cache profile admin_user&lt;/P&gt;&lt;P&gt; profile admin no-auth&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;tacacs-server host 10.10.10.10 single-connection&lt;/P&gt;&lt;P&gt;tacacs-server host 10.10.10.11 single-connection&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;tacacs-server key 7 &amp;lt;removed&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;============&lt;/P&gt;&lt;P&gt;debug output&lt;/P&gt;&lt;P&gt;============&lt;/P&gt;&lt;P&gt;ap#&lt;/P&gt;&lt;P&gt;Feb  7 20:02:37: AAA/BIND(00000004): Bind i/f&lt;/P&gt;&lt;P&gt;Feb  7 20:02:37: AAA/AUTHEN/CACHE(00000004): GET_USER  for username NULL&lt;/P&gt;&lt;P&gt;Feb  7 20:02:39: AAA/AUTHEN/CACHE(00000004): GET_PASSWORD  for username admin&lt;/P&gt;&lt;P&gt;Feb  7 20:02:42: AAA/AUTHEN/CACHE(00000004): PASS  for username ^-&amp;gt;o&lt;/P&gt;&lt;P&gt;Feb  7 20:02:42: AAA/AUTHOR (0x4): Pick method list 'default'&lt;/P&gt;&lt;P&gt;Feb  7 20:02:42: AAA/AUTHOR/EXEC(00000004): processing AV cmd=&lt;/P&gt;&lt;P&gt;Feb  7 20:02:42: AAA/AUTHOR/EXEC(00000004): processing AV priv-lvl=15&lt;/P&gt;&lt;P&gt;Feb  7 20:02:42: AAA/AUTHOR/EXEC(00000004): Authorization successful&lt;/P&gt;&lt;P&gt;ap#&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA: parse name=tty2 idb type=-1 tty=-1&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA: name=tty2 flags=0x11 type=5 shelf=0 slot=0 adapter=0 port=2 channel=0&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA/MEMORY: create_user (0xBA9C34) user='admin' ruser='ap' ds0=0 port='tty2' rem_addr='10.10.1.1' authen_type=ASCII service=NONE priv=15 initial_task_id='0', vrf= (id=0)&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: tty2 AAA/AUTHOR/CMD(787222339): Port='tty2' list='' service=CMD&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA/AUTHOR/CMD: tty2(787222339) user='admin'&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: tty2 AAA/AUTHOR/CMD(787222339): send AV service=shell&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: tty2 AAA/AUTHOR/CMD(787222339): send AV cmd=show&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: tty2 AAA/AUTHOR/CMD(787222339): send AV cmd-arg=running-config&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: tty2 AAA/AUTHOR/CMD(787222339): send AV cmd-arg=&amp;lt;cr&amp;gt;&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: tty2 AAA/AUTHOR/CMD(787222339): found list "default"&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: % tty2 Unknown authorization method 6 set for list command&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA/AUTHOR (787222339): Post authorization status = ERROR&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: tty2 AAA/AUTHOR/CMD(787222339): Method=group_tacacs (tacacs+)&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA/AUTHOR/TAC+: (787222339): user=admin&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA/AUTHOR/TAC+: (787222339): send AV service=shell&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA/AUTHOR/TAC+: (787222339): send AV cmd=show&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA/AUTHOR/TAC+: (787222339): send AV cmd-arg=running-config&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA/AUTHOR/TAC+: (787222339): send AV cmd-arg=&amp;lt;cr&amp;gt;&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA/AUTHOR (787222339): Post authorization status = PASS_ADD&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA/MEMORY: free_user (0xBA9C34) user='admin' ruser='ap' port='tty2' rem_addr='10.10.1.1' authen_type=ASCII service=NONE&lt;/P&gt;&lt;P&gt;priv=15 vrf= (id=0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 21:58:31 GMT</pubDate>
    <dc:creator>khof</dc:creator>
    <dc:date>2019-03-10T21:58:31Z</dc:date>
    <item>
      <title>Command authorization error when using aaa cache</title>
      <link>https://community.cisco.com/t5/network-access-control/command-authorization-error-when-using-aaa-cache/m-p/654208#M421737</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to use the aaa cache mode for command authorization. But when I execute a command there is always an error message:&lt;/P&gt;&lt;P&gt;% tty2 Unknown authorization method 6 set for list command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command is then always authorized against the tacacs server.&lt;/P&gt;&lt;P&gt;The 'authentication login', 'authentication enable' and 'authorization exec' are using the cache properly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried it with an Accesspoint AIR-AP1242AG-E-K9, IOS 12.3(8)JEA and a Catalyst WS-C3550-24PWR-SMI, IOS 12.2(35)SE with the same results. &lt;/P&gt;&lt;P&gt;Deleting the cache entry and using only the tacacs group the error message disappears.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;======&lt;/P&gt;&lt;P&gt;config&lt;/P&gt;&lt;P&gt;======&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ group_tacacs&lt;/P&gt;&lt;P&gt; server 10.10.10.10&lt;/P&gt;&lt;P&gt; server 10.10.10.11&lt;/P&gt;&lt;P&gt; cache expiry 12&lt;/P&gt;&lt;P&gt; cache authorization profile admin_user&lt;/P&gt;&lt;P&gt; cache authentication profile admin_user&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default cache group_tacacs group group_tacacs local&lt;/P&gt;&lt;P&gt;aaa authentication enable default cache group_tacacs group group_tacacs enable&lt;/P&gt;&lt;P&gt;aaa authorization console&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;P&gt;aaa authorization exec default cache group_tacacs group group_tacacs local&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default cache group_tacacs group group_tacacs local&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group group_tacacs&lt;/P&gt;&lt;P&gt;aaa cache profile admin_user&lt;/P&gt;&lt;P&gt; profile admin no-auth&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;tacacs-server host 10.10.10.10 single-connection&lt;/P&gt;&lt;P&gt;tacacs-server host 10.10.10.11 single-connection&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;tacacs-server key 7 &amp;lt;removed&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;============&lt;/P&gt;&lt;P&gt;debug output&lt;/P&gt;&lt;P&gt;============&lt;/P&gt;&lt;P&gt;ap#&lt;/P&gt;&lt;P&gt;Feb  7 20:02:37: AAA/BIND(00000004): Bind i/f&lt;/P&gt;&lt;P&gt;Feb  7 20:02:37: AAA/AUTHEN/CACHE(00000004): GET_USER  for username NULL&lt;/P&gt;&lt;P&gt;Feb  7 20:02:39: AAA/AUTHEN/CACHE(00000004): GET_PASSWORD  for username admin&lt;/P&gt;&lt;P&gt;Feb  7 20:02:42: AAA/AUTHEN/CACHE(00000004): PASS  for username ^-&amp;gt;o&lt;/P&gt;&lt;P&gt;Feb  7 20:02:42: AAA/AUTHOR (0x4): Pick method list 'default'&lt;/P&gt;&lt;P&gt;Feb  7 20:02:42: AAA/AUTHOR/EXEC(00000004): processing AV cmd=&lt;/P&gt;&lt;P&gt;Feb  7 20:02:42: AAA/AUTHOR/EXEC(00000004): processing AV priv-lvl=15&lt;/P&gt;&lt;P&gt;Feb  7 20:02:42: AAA/AUTHOR/EXEC(00000004): Authorization successful&lt;/P&gt;&lt;P&gt;ap#&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA: parse name=tty2 idb type=-1 tty=-1&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA: name=tty2 flags=0x11 type=5 shelf=0 slot=0 adapter=0 port=2 channel=0&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA/MEMORY: create_user (0xBA9C34) user='admin' ruser='ap' ds0=0 port='tty2' rem_addr='10.10.1.1' authen_type=ASCII service=NONE priv=15 initial_task_id='0', vrf= (id=0)&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: tty2 AAA/AUTHOR/CMD(787222339): Port='tty2' list='' service=CMD&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA/AUTHOR/CMD: tty2(787222339) user='admin'&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: tty2 AAA/AUTHOR/CMD(787222339): send AV service=shell&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: tty2 AAA/AUTHOR/CMD(787222339): send AV cmd=show&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: tty2 AAA/AUTHOR/CMD(787222339): send AV cmd-arg=running-config&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: tty2 AAA/AUTHOR/CMD(787222339): send AV cmd-arg=&amp;lt;cr&amp;gt;&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: tty2 AAA/AUTHOR/CMD(787222339): found list "default"&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: % tty2 Unknown authorization method 6 set for list command&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA/AUTHOR (787222339): Post authorization status = ERROR&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: tty2 AAA/AUTHOR/CMD(787222339): Method=group_tacacs (tacacs+)&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA/AUTHOR/TAC+: (787222339): user=admin&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA/AUTHOR/TAC+: (787222339): send AV service=shell&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA/AUTHOR/TAC+: (787222339): send AV cmd=show&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA/AUTHOR/TAC+: (787222339): send AV cmd-arg=running-config&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA/AUTHOR/TAC+: (787222339): send AV cmd-arg=&amp;lt;cr&amp;gt;&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA/AUTHOR (787222339): Post authorization status = PASS_ADD&lt;/P&gt;&lt;P&gt;Feb  7 20:02:54: AAA/MEMORY: free_user (0xBA9C34) user='admin' ruser='ap' port='tty2' rem_addr='10.10.1.1' authen_type=ASCII service=NONE&lt;/P&gt;&lt;P&gt;priv=15 vrf= (id=0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:58:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-authorization-error-when-using-aaa-cache/m-p/654208#M421737</guid>
      <dc:creator>khof</dc:creator>
      <dc:date>2019-03-10T21:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: Command authorization error when using aaa cache</title>
      <link>https://community.cisco.com/t5/network-access-control/command-authorization-error-when-using-aaa-cache/m-p/654209#M421738</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;These are event logs which show that these are just informational messages of sev 6.&lt;/P&gt;&lt;P&gt;Try removing the cache related commands and add the following commands,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authen login default  group &amp;lt; group name &amp;gt; local&lt;/P&gt;&lt;P&gt;and  aaa authorization exec default group &lt;GROUP name=""&gt; local&lt;/GROUP&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Feb 2007 20:22:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-authorization-error-when-using-aaa-cache/m-p/654209#M421738</guid>
      <dc:creator>sbilgi</dc:creator>
      <dc:date>2007-02-13T20:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: Command authorization error when using aaa cache</title>
      <link>https://community.cisco.com/t5/network-access-control/command-authorization-error-when-using-aaa-cache/m-p/654210#M421739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I really do not think that command authorization results will be cached. The cache keeps the user credentials and attributes passed during exec authorization but for command authorization it would have to check with the tacacs server always.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vivek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Feb 2007 14:40:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-authorization-error-when-using-aaa-cache/m-p/654210#M421739</guid>
      <dc:creator>Vivek Santuka</dc:creator>
      <dc:date>2007-02-14T14:40:50Z</dc:date>
    </item>
    <item>
      <title>Re: Command authorization error when using aaa cache</title>
      <link>https://community.cisco.com/t5/network-access-control/command-authorization-error-when-using-aaa-cache/m-p/654211#M421740</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vivek,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have almost expected to see this answer. Then I have to go another way to finish this task.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Feb 2007 15:13:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/command-authorization-error-when-using-aaa-cache/m-p/654211#M421740</guid>
      <dc:creator>khof</dc:creator>
      <dc:date>2007-02-14T15:13:43Z</dc:date>
    </item>
  </channel>
</rss>

