<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: syslog messages in AAA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/syslog-messages-in-aaa/m-p/505366#M427513</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you perhaps have this switch console connected on a terminal server, and if so, does the terminal server have "no exec" configured on the lines used for reverse telnet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seen symptoms similar to what you describe in a situation where I had a switch whose console port was connected to a terminal server and the terminal server lines did not have no exec. It looks like there was some activity on the switch which the terminal server presented a login prompt. The next text displayed on the switch was interpreted by the terminal server as the login id and was logged in the failed attempts log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Apr 2006 02:20:16 GMT</pubDate>
    <dc:creator>Richard Burts</dc:creator>
    <dc:date>2006-04-05T02:20:16Z</dc:date>
    <item>
      <title>syslog messages in AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/syslog-messages-in-aaa/m-p/505363#M427487</link>
      <description>&lt;P&gt;I have an issue with a switch's syslog messages showing up in the failed authentication attempts report in the AAA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone has any thoughts, let me know!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CHRIS&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:31:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/syslog-messages-in-aaa/m-p/505363#M427487</guid>
      <dc:creator>cplatt01</dc:creator>
      <dc:date>2019-03-10T21:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: syslog messages in AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/syslog-messages-in-aaa/m-p/505364#M427496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is not uncommon! I've seen all types of random stuff (usually via TACACS+).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The request packets were perfectly formed T+ requests but had data that contain what looks like random parts of the device's onboard RAM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most likely a similar thing.&lt;/P&gt;&lt;P&gt;Darran&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Apr 2006 17:36:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/syslog-messages-in-aaa/m-p/505364#M427496</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2006-04-03T17:36:17Z</dc:date>
    </item>
    <item>
      <title>Re: syslog messages in AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/syslog-messages-in-aaa/m-p/505365#M427505</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hmmm...It seems to only be happening with 1 switch.  Is there anyway to prevent/stop it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Apr 2006 17:55:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/syslog-messages-in-aaa/m-p/505365#M427505</guid>
      <dc:creator>cplatt01</dc:creator>
      <dc:date>2006-04-03T17:55:01Z</dc:date>
    </item>
    <item>
      <title>Re: syslog messages in AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/syslog-messages-in-aaa/m-p/505366#M427513</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you perhaps have this switch console connected on a terminal server, and if so, does the terminal server have "no exec" configured on the lines used for reverse telnet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seen symptoms similar to what you describe in a situation where I had a switch whose console port was connected to a terminal server and the terminal server lines did not have no exec. It looks like there was some activity on the switch which the terminal server presented a login prompt. The next text displayed on the switch was interpreted by the terminal server as the login id and was logged in the failed attempts log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Apr 2006 02:20:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/syslog-messages-in-aaa/m-p/505366#M427513</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2006-04-05T02:20:16Z</dc:date>
    </item>
  </channel>
</rss>

