<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic switch 3560 and acs 4.2: fail authentication after reboot in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510408#M426404</link>
    <description>&lt;P&gt;we use acs to aaa with network devices.&lt;/P&gt;&lt;P&gt;we have 4 swich 3560 with same problem: after around 10 minutes from reboot switch, I cant login these switchs. But from these switch, i still ping ACS server. IF I reboot again, the same thing happen.&lt;/P&gt;&lt;P&gt;Could you help me, what s the matter with these switchs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The config for AAA on each swich:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login TACACS+ group tacacs+ local&lt;BR /&gt;!&lt;BR /&gt;aaa authorization commands 15 AAA group tacacs+ local &lt;BR /&gt;!&lt;BR /&gt;aaa accounting exec AAA start-stop group tacacs+&lt;BR /&gt;aaa accounting network AAA start-stop group tacacs+&lt;BR /&gt;aaa accounting connection AAA start-stop group tacacs+&lt;BR /&gt;aaa accounting system default start-stop group tacacs+&lt;BR /&gt;!&lt;BR /&gt;tacacs-server host x.x.x.x&lt;BR /&gt;tacacs-server directed-request&lt;BR /&gt;tacacs-server key 7 02050D480809&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt; accounting connection AAA&lt;BR /&gt; accounting commands 15 AAA&lt;BR /&gt; accounting exec AAA&lt;BR /&gt;line vty 0 4&lt;BR /&gt; authorization commands 15 AAA&lt;BR /&gt; accounting connection AAA&lt;BR /&gt; accounting commands 15 AAA&lt;BR /&gt; accounting exec AAA&lt;BR /&gt; login authentication TACACS+&lt;BR /&gt; transport input telnet&lt;BR /&gt;line vty 5 15&lt;BR /&gt; login authentication TACACS+&lt;BR /&gt;!&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 00:22:20 GMT</pubDate>
    <dc:creator>ngo duyen</dc:creator>
    <dc:date>2019-03-11T00:22:20Z</dc:date>
    <item>
      <title>switch 3560 and acs 4.2: fail authentication after reboot</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510408#M426404</link>
      <description>&lt;P&gt;we use acs to aaa with network devices.&lt;/P&gt;&lt;P&gt;we have 4 swich 3560 with same problem: after around 10 minutes from reboot switch, I cant login these switchs. But from these switch, i still ping ACS server. IF I reboot again, the same thing happen.&lt;/P&gt;&lt;P&gt;Could you help me, what s the matter with these switchs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The config for AAA on each swich:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login TACACS+ group tacacs+ local&lt;BR /&gt;!&lt;BR /&gt;aaa authorization commands 15 AAA group tacacs+ local &lt;BR /&gt;!&lt;BR /&gt;aaa accounting exec AAA start-stop group tacacs+&lt;BR /&gt;aaa accounting network AAA start-stop group tacacs+&lt;BR /&gt;aaa accounting connection AAA start-stop group tacacs+&lt;BR /&gt;aaa accounting system default start-stop group tacacs+&lt;BR /&gt;!&lt;BR /&gt;tacacs-server host x.x.x.x&lt;BR /&gt;tacacs-server directed-request&lt;BR /&gt;tacacs-server key 7 02050D480809&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt; accounting connection AAA&lt;BR /&gt; accounting commands 15 AAA&lt;BR /&gt; accounting exec AAA&lt;BR /&gt;line vty 0 4&lt;BR /&gt; authorization commands 15 AAA&lt;BR /&gt; accounting connection AAA&lt;BR /&gt; accounting commands 15 AAA&lt;BR /&gt; accounting exec AAA&lt;BR /&gt; login authentication TACACS+&lt;BR /&gt; transport input telnet&lt;BR /&gt;line vty 5 15&lt;BR /&gt; login authentication TACACS+&lt;BR /&gt;!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:22:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510408#M426404</guid>
      <dc:creator>ngo duyen</dc:creator>
      <dc:date>2019-03-11T00:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: switch 3560 and acs 4.2: fail authentication after reboot</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510409#M426405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the reason seen on ACS' reports for failing the authentication request?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please enable:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug aaa authentication&lt;/P&gt;&lt;P&gt;debug tacacs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then capture the output while the switch is in the failed state and post it here.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Aug 2010 15:34:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510409#M426405</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2010-08-31T15:34:18Z</dc:date>
    </item>
    <item>
      <title>Re: switch 3560 and acs 4.2: fail authentication after reboot</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510410#M426408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nothing special in ACS&lt;/P&gt;&lt;P&gt;my debug on sw:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;S3560-04#debug aaa authentication &lt;BR /&gt;AAA Authentication debugging is on&lt;BR /&gt;S3560-04#&lt;BR /&gt;S3560-04#&lt;BR /&gt;S3560-04#&lt;BR /&gt;1w5d: AAA/AUTHEN (2070922190): status = ERROR&lt;BR /&gt;1w5d: AAA/AUTHEN/START (2070922190): Method=LOCAL&lt;BR /&gt;1w5d: AAA/AUTHEN (2070922190): status = GETUSER&lt;BR /&gt;S3560-04#&lt;BR /&gt;S3560-04#&lt;BR /&gt;S3560-04#&lt;BR /&gt;S3560-04#debug aaa authentication &lt;BR /&gt;AAA Authentication debugging is on&lt;BR /&gt;S3560-04#&lt;BR /&gt;1w5d: AAA/AUTHEN/ABORT: (2070922190) because Login timed out.&lt;BR /&gt;1w5d: AAA/MEMORY: free_user (0x33B00B8) user='NULL' ruser='NULL' port='tty1' rem_addr='10.0.0.63' authen_type=ASCII service=LOGIN priv=1&lt;BR /&gt;1w5d: AAA: parse name=tty1 idb type=-1 tty=-1&lt;BR /&gt;1w5d: AAA: name=tty1 flags=0x11 type=5 shelf=0 slot=0 adapter=0 port=1 channel=0&lt;BR /&gt;1w5d: AAA/MEMORY: create_user (0x3362B98) user='NULL' ruser='NULL' ds0=0 port='tty1' rem_addr='10.0.0.63' authen_type=ASCII service=LOGIN priv=1 initial_task_id='0', vrf= (id=0)&lt;BR /&gt;1w5d: AAA/AUTHEN/START (1041751841): port='tty1' list='TACAS+' action=LOGIN service=LOGIN&lt;BR /&gt;1w5d: AAA/AUTHEN/START (1041751841): found list TACAS+&lt;BR /&gt;1w5d: AAA/AUTHEN/START (1041751841): Method=tacacs+ (tacacs+)&lt;BR /&gt;1w5d: TAC+: send AUTHEN/START packet ver=192 id=1041751841&lt;BR /&gt;1w5d: AAA/AUTHEN (1041751841): status = ERROR&lt;BR /&gt;1w5d: AAA/AUTHEN/START (1041751841): Method=LOCAL&lt;BR /&gt;1w5d: AAA/AUTHEN (1041751841): status = GETUSER&lt;BR /&gt;1w5d: AAA/AUTHEN/CONT (1041751841): continue_login (user='(undef)')&lt;BR /&gt;1w5d: AAA/AUTHEN (1041751841): status = GETUSER&lt;BR /&gt;1w5d: AAA/AUTHEN/CONT (1041751841): Method=LOCAL&lt;BR /&gt;1w5d: AAA/AUTHEN (1041751841): status = GETPASS&lt;BR /&gt;1w5d: AAA/AUTHEN/CONT (1041751841): continue_login (user='tester')&lt;BR /&gt;1w5d: AAA/AUTHEN (1041751841): status = GETPASS&lt;BR /&gt;1w5d: AAA/AUTHEN/CONT (1041751841): Method=LOCAL&lt;BR /&gt;1w5d: AAA/AUTHEN (1041751841): User not found&lt;BR /&gt;1w5d: AAA/AUTHEN (1041751841): status = FAIL&lt;BR /&gt;1w5d: AAA/AUTHEN/ABORT: (1041751841) because Unknown.&lt;BR /&gt;1w5d: AAA/MEMORY: free_user_quiet (0x3362B98) user='tester' ruser='NULL' port='tty1' rem_addr='10.0.0.63' authen_type=1 service=1 priv=1&lt;BR /&gt;1w5d: AAA: parse name=tty1 idb type=-1 tty=-1&lt;BR /&gt;1w5d: AAA: name=tty1 flags=0x11 type=5 shelf=0 slot=0 adapter=0 port=1 channel=0&lt;BR /&gt;1w5d: AAA/MEMORY: create_user (0x34B7470) user='NULL' ruser='NULL' ds0=0 port='tty1' rem_addr='10.0.0.63' authen_type=ASCII service=LOGIN priv=1 initial_task_id='0', vrf= (id=0)&lt;BR /&gt;1w5d: AAA/AUTHEN/START (9466938): port='tty1' list='TACAS+' action=LOGIN service=LOGIN&lt;BR /&gt;1w5d: AAA/AUTHEN/START (9466938): found list TACAS+&lt;BR /&gt;1w5d: AAA/AUTHEN/START (9466938): Method=tacacs+ (tacacs+)&lt;BR /&gt;1w5d: TAC+: send AUTHEN/START packet ver=192 id=9466938&lt;BR /&gt;1w5d: AAA/AUTHEN (9466938): status = ERROR&lt;BR /&gt;1w5d: AAA/AUTHEN/START (9466938): Method=LOCAL&lt;BR /&gt;1w5d: AAA/AUTHEN (9466938): status = GETUSER&lt;BR /&gt;S3560-04#&lt;BR /&gt;1w5d: AAA/AUTHEN/ABORT: (9466938) because Login timed out.&lt;BR /&gt;1w5d: AAA/MEMORY: free_user_quiet (0x34B7470) user='NULL' ruser='NULL' port='tty1' rem_addr='10.0.0.63' authen_type=1 service=1 priv=1&lt;BR /&gt;1w5d: AAA: parse name=tty1 idb type=-1 tty=-1&lt;BR /&gt;1w5d: AAA: name=tty1 flags=0x11 type=5 shelf=0 slot=0 adapter=0 port=1 channel=0&lt;BR /&gt;1w5d: AAA/MEMORY: create_user (0x34B8E10) user='NULL' ruser='NULL' ds0=0 port='tty1' rem_addr='10.0.0.63' authen_type=ASCII service=LOGIN priv=1 initial_task_id='0', vrf= (id=0)&lt;BR /&gt;1w5d: AAA/AUTHEN/START (2867507997): port='tty1' list='TACAS+' action=LOGIN service=LOGIN&lt;BR /&gt;1w5d: AAA/AUTHEN/START (2867507997): found list TACAS+&lt;BR /&gt;1w5d: AAA/AUTHEN/START (2867507997): Method=tacacs+ (tacacs+)&lt;BR /&gt;1w5d: TAC+: send AUTHEN/START packet ver=192 id=2867507997&lt;BR /&gt;1w5d: AAA/AUTHEN (2867507997): status = ERROR&lt;BR /&gt;1w5d: AAA/AUTHEN/START (2867507997): Method=LOCAL&lt;BR /&gt;1w5d: AAA/AUTHEN (2867507997): status = GETUSER &lt;BR /&gt;S3560-04#&lt;BR /&gt;S3560-04#&lt;BR /&gt;S3560-04#&lt;BR /&gt;S3560-04#&lt;BR /&gt;S3560-04#&lt;/P&gt;&lt;P&gt;1w5d: AAA/AUTHEN/ABORT: (2867507997) because Login timed out.&lt;BR /&gt;1w5d: AAA/MEMORY: free_user (0x34B8E10) user='NULL' ruser='NULL' port='tty1' rem_addr='10.0.0.63' authen_type=ASCII service=LOGIN priv=1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Sep 2010 03:40:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510410#M426408</guid>
      <dc:creator>ngo duyen</dc:creator>
      <dc:date>2010-09-01T03:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: switch 3560 and acs 4.2: fail authentication after reboot</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510411#M426409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1w5d: AAA/AUTHEN/START (1041751841): port='tty1' list='TACAS+' action=LOGIN service=LOGIN&lt;BR /&gt;1w5d: AAA/AUTHEN/START (1041751841): found list TACAS+&lt;BR /&gt;1w5d: AAA/AUTHEN/START (1041751841): Method=tacacs+ (tacacs+)&lt;BR /&gt;1w5d: TAC+: send AUTHEN/START packet ver=192 id=1041751841&lt;BR /&gt;1w5d: AAA/AUTHEN (1041751841): status = ERROR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the switch can't talk to the ACS server anymore for some reason. Since it works at first, I assume that the TACACS+ shared secret is correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you ping the ACS server after the authentications start to fail?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Sep 2010 10:50:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510411#M426409</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2010-09-01T10:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: switch 3560 and acs 4.2: fail authentication after reboot</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510412#M426411</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank your help, I have topology and more detail info.&lt;/P&gt;&lt;P&gt;sw3560-01 havent got this error. All other sw3560 have this error.&lt;/P&gt;&lt;P&gt;when error happen, I still ping server 10.a.b.22 (the same subnet with ACS, ACS doesnt allow ping it)&lt;/P&gt;&lt;P&gt;And at that time, I can access that switch ( 3,4,5,6,7) by using a local username/password when I connect with a vlan in the system.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All thing work well, only thing that these switchs lost authentication after short time. I really want to know what happen with these switchs&lt;/P&gt;&lt;P&gt;&lt;SPAN __jive_emoticon_name="confused" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/confused.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Sep 2010 05:08:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510412#M426411</guid>
      <dc:creator>ngo duyen</dc:creator>
      <dc:date>2010-09-08T05:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: switch 3560 and acs 4.2: fail authentication after reboot</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510413#M426413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When the problem happens, can you telnet to port 49 on the ACS server from the affected switches?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Sep 2010 11:43:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510413#M426413</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2010-09-08T11:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: switch 3560 and acs 4.2: fail authentication after reboot</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510414#M426415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tacacs+ port?&lt;/P&gt;&lt;P&gt;I try telnet ip_of_ACS and port 2002&lt;/P&gt;&lt;P&gt;and it work for short time after reboot and doesnt work when it get error.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Sep 2010 13:29:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510414#M426415</guid>
      <dc:creator>ngo duyen</dc:creator>
      <dc:date>2010-09-08T13:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: switch 3560 and acs 4.2: fail authentication after reboot</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510415#M426417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, TCP/49 is the TACACS+ port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suspect a networking issue, and concentrate troubleshooting there. Could the firewall shown in the diagram that you uploaded be a factor?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Sep 2010 13:51:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510415#M426417</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2010-09-08T13:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: switch 3560 and acs 4.2: fail authentication after reboot</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510416#M426418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we get that error around 2 month ago, before that time the system work well for very long time.&lt;/P&gt;&lt;P&gt;If that s a firewall problem, I dont know why it happen after it work well for few minutes. Is there any kind of dynamic ACL?&lt;/P&gt;&lt;P&gt;After reboot it work again and ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thinkink about ip default-gateway. all L2 switch work without default-gateway. Is int vlan1 enough for this topology?&lt;/P&gt;&lt;P&gt;I read somewhere and they said that, we need ip default-gateway when we want to manage from other subnet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Sep 2010 14:26:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510416#M426418</guid>
      <dc:creator>ngo duyen</dc:creator>
      <dc:date>2010-09-08T14:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: switch 3560 and acs 4.2: fail authentication after reboot</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510417#M426419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;pls give me some ideas to resol this problem!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also try change IOS but nothing change&lt;IMG class="jive_macro jive_macro_emoticon" src="https://community.cisco.com/resources/scripts/tiny_mce3/plugins/jiveemoticons/images/spacer.gif" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Sep 2010 01:41:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510417#M426419</guid>
      <dc:creator>ngo duyen</dc:creator>
      <dc:date>2010-09-13T01:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: switch 3560 and acs 4.2: fail authentication after reboot</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510418#M426420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have checked ACS, it work well. And we have many other device using ACS.&lt;/P&gt;&lt;P&gt;port 49, 2002 work in short time and doesnt work after that.&lt;/P&gt;&lt;P&gt;Firewall I use: permit ip any for testing.&lt;/P&gt;&lt;P&gt;From fail switchs, I can ping 10.a.b.22 without problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when I change L2 sw to L3 sw using these command, AAA work well:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip routing&lt;/P&gt;&lt;P&gt;interface Loopback10&lt;BR /&gt; ip address 10.x.x.x 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.x.y.1&lt;BR /&gt;ip tacacs source-interface Loopback10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 10.x.y.1 is ip address of L3 switch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls help me. thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Sep 2010 06:04:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510418#M426420</guid>
      <dc:creator>ngo duyen</dc:creator>
      <dc:date>2010-09-13T06:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: switch 3560 and acs 4.2: fail authentication after reboot</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510419#M426421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I add&lt;/P&gt;&lt;P&gt;ip default-gateway 10.x.y.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and .... it works well &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I dont underscant why it work around 3 minustes after reboot &lt;IMG class="jive_macro jive_macro_emoticon" src="https://community.cisco.com/resources/scripts/tiny_mce3/plugins/jiveemoticons/images/spacer.gif" /&gt; without this command&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Sep 2010 02:46:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-3560-and-acs-4-2-fail-authentication-after-reboot/m-p/1510419#M426421</guid>
      <dc:creator>ngo duyen</dc:creator>
      <dc:date>2010-09-15T02:46:35Z</dc:date>
    </item>
  </channel>
</rss>

