<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with TACACS+ (ACS) and Cat 2950 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-acs-and-cat-2950/m-p/530284#M426765</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will agree with AK that I do not see any obvious problems with the aaa configuration on the switch. I note that you specify authorization for level 15 commands. My guess is that in the configuration of ACS you are not allowing these commands for this user ID. A quick way to verify this would be to remove the aaa authorization for level 15 commands from the switch config and see if the behavior changes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 31 Jul 2006 15:31:12 GMT</pubDate>
    <dc:creator>Richard Burts</dc:creator>
    <dc:date>2006-07-31T15:31:12Z</dc:date>
    <item>
      <title>Problem with TACACS+ (ACS) and Cat 2950</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-acs-and-cat-2950/m-p/530282#M426757</link>
      <description>&lt;P&gt;I've configured the 2950 as below and configured ACS correctly and I can login to the 2950 using this config, the problem lies after I go into enable and try any command I get the following error Command authorization failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What have I missed out of the config that will allow me to run any commands?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local if-authenticated&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;aaa authorization network default group tacacs+ local if-authenticated&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting network default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host ***.***.***&lt;/P&gt;&lt;P&gt;tacacs-server key 7 ***********&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:41:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-acs-and-cat-2950/m-p/530282#M426757</guid>
      <dc:creator>jonhill</dc:creator>
      <dc:date>2019-03-10T21:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with TACACS+ (ACS) and Cat 2950</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-acs-and-cat-2950/m-p/530283#M426760</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The switch's AAA looks ok, maybe you need to take a look at your ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the following info, where you might need to apply it into your ACS config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps5338/products_configuration_guide_chapter09186a00801fd6fc.html#wp676529" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps5338/products_configuration_guide_chapter09186a00801fd6fc.html#wp676529&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rgds,&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jul 2006 12:53:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-acs-and-cat-2950/m-p/530283#M426760</guid>
      <dc:creator>a.kiprawih</dc:creator>
      <dc:date>2006-07-31T12:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with TACACS+ (ACS) and Cat 2950</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-acs-and-cat-2950/m-p/530284#M426765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will agree with AK that I do not see any obvious problems with the aaa configuration on the switch. I note that you specify authorization for level 15 commands. My guess is that in the configuration of ACS you are not allowing these commands for this user ID. A quick way to verify this would be to remove the aaa authorization for level 15 commands from the switch config and see if the behavior changes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jul 2006 15:31:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-tacacs-acs-and-cat-2950/m-p/530284#M426765</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2006-07-31T15:31:12Z</dc:date>
    </item>
  </channel>
</rss>

