<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: tacacs debug message  in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-debug-message/m-p/581360#M427736</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply. The configs on the acs were fine and were checked multiple times. We restarted the acs service which resolved the issue for us along with the other routers with same issue with same acs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Prashant&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Apr 2008 04:36:38 GMT</pubDate>
    <dc:creator>prashsin1</dc:creator>
    <dc:date>2008-04-02T04:36:38Z</dc:date>
    <item>
      <title>tacacs debug message</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-debug-message/m-p/581356#M427732</link>
      <description>&lt;P&gt;Tacacs not working on router. Here's the debug:&lt;/P&gt;&lt;P&gt;Feb 15 09:01:35: TPLUS: Queuing AAA Authentication request 56 for processing&lt;/P&gt;&lt;P&gt;Feb 15 09:01:35: TPLUS: processing authentication start request id 56&lt;/P&gt;&lt;P&gt;Feb 15 09:01:35: TPLUS: Authentication start packet created for 56()&lt;/P&gt;&lt;P&gt;Feb 15 09:01:35: TPLUS: Using server 10.67.3.68&lt;/P&gt;&lt;P&gt;Feb 15 09:01:35: TPLUS(00000038)/0/NB_WAIT/642887C4: Started 5 sec timeout&lt;/P&gt;&lt;P&gt;Feb 15 09:01:35: TPLUS(00000038)/0/NB_WAIT: socket event 2&lt;/P&gt;&lt;P&gt;Feb 15 09:01:35: TPLUS(00000038)/0/NB_WAIT: wrote entire 35 bytes request&lt;/P&gt;&lt;P&gt;Feb 15 09:01:35: TPLUS(00000038)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;Feb 15 09:01:35: TPLUS(00000038)/0/READ: Would block while reading&lt;/P&gt;&lt;P&gt;Feb 15 09:01:35: TPLUS(00000038)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;Feb 15 09:01:35: TPLUS(00000038)/0/READ: errno 254&lt;/P&gt;&lt;P&gt;Feb 15 09:01:35: TPLUS(00000038)/0/642887C4: Processing the reply packet&lt;/P&gt;&lt;P&gt;Feb 15 09:01:45: TPLUS: Queuing AAA Authentication request 56 for processing&lt;/P&gt;&lt;P&gt;Feb 15 09:01:45: TPLUS: processing authentication start request id 56&lt;/P&gt;&lt;P&gt;Feb 15 09:01:45: TPLUS: Authentication start packet created for 56()&lt;/P&gt;&lt;P&gt;Feb 15 09:01:45: TPLUS: Using server 10.67.3.68&lt;/P&gt;&lt;P&gt;Feb 15 09:01:45: TPLUS(00000038)/0/NB_WAIT/658594B0: Started 5 sec timeout&lt;/P&gt;&lt;P&gt;Feb 15 09:01:45: TPLUS(00000038)/0/NB_WAIT: socket event 2&lt;/P&gt;&lt;P&gt;Feb 15 09:01:45: TPLUS(00000038)/0/NB_WAIT: wrote entire 35 bytes request&lt;/P&gt;&lt;P&gt;Feb 15 09:01:45: TPLUS(00000038)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;Feb 15 09:01:45: TPLUS(00000038)/0/READ: Would block while reading&lt;/P&gt;&lt;P&gt;Feb 15 09:01:45: TPLUS(00000038)/0/READ: socket event 1&lt;/P&gt;&lt;P&gt;Feb 15 09:01:45: TPLUS(00000038)/0/READ: errno 254&lt;/P&gt;&lt;P&gt;Feb 15 09:01:45: TPLUS(00000038)/0/658594B0: Processing the reply packet&lt;/P&gt;&lt;P&gt;Any Ideas? &lt;/P&gt;&lt;P&gt;Any takers?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:28:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-debug-message/m-p/581356#M427732</guid>
      <dc:creator>j-bliss</dc:creator>
      <dc:date>2019-03-10T21:28:34Z</dc:date>
    </item>
    <item>
      <title>Re: tacacs debug message</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-debug-message/m-p/581357#M427733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jason&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The device is sending a request and gets this:READ: errno 254 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you verify that the TACACS server has a correct definintion for this device?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It might be helpful if you would run debug tacacs packet and post its output.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Feb 2006 19:41:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-debug-message/m-p/581357#M427733</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2006-02-16T19:41:44Z</dc:date>
    </item>
    <item>
      <title>Re: tacacs debug message</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-debug-message/m-p/581358#M427734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am facing the same issue Jason mentioned. As you suggested him I am attaching the result of debug tacacs and cannot paste due to word limit. Please suggest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Prashant&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Apr 2008 12:30:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-debug-message/m-p/581358#M427734</guid>
      <dc:creator>prashsin1</dc:creator>
      <dc:date>2008-04-01T12:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: tacacs debug message</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-debug-message/m-p/581359#M427735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Prashant&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have looked at the file that you posted (which is the right way to get large amounts of information into a posting) and I believe that it is helpful. I see this type of error message quite a few times:&lt;/P&gt;&lt;P&gt;Apr  1 12:22:54.718: TAC+: Invalid AUTHOR/START packet (check keys).&lt;/P&gt;&lt;P&gt;Apr  1 12:22:54.718: TAC+: Closing TCP/IP 0x641C40B8 connection to 10.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe in particular the part that says (check keys) is a clue. I believe that it indicates that there is a mismatch between the configuration on the router and the configuration on  the ACS server. Check the configuration of the ACS server to be sure that it has an entry for 10.127.0.202 remote client and make sure that the key configured on the server is the same as the key configured on the router (it might be best to reconfigure the keys just to be sure that they match).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Apr 2008 19:35:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-debug-message/m-p/581359#M427735</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2008-04-01T19:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: tacacs debug message</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-debug-message/m-p/581360#M427736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply. The configs on the acs were fine and were checked multiple times. We restarted the acs service which resolved the issue for us along with the other routers with same issue with same acs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Prashant&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Apr 2008 04:36:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-debug-message/m-p/581360#M427736</guid>
      <dc:creator>prashsin1</dc:creator>
      <dc:date>2008-04-02T04:36:38Z</dc:date>
    </item>
    <item>
      <title>Re: tacacs debug message</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-debug-message/m-p/581361#M427737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Prashant&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for posting back to the forum indicating that you had resolved the issue and what you did that resolved the issue. It helps make the forum more useful when people can read about a problem and can read what was done that resolved the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The forum is an excellent place to learn about Cisco networking. I encourage you to continue your participation in the forum.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Apr 2008 18:07:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-debug-message/m-p/581361#M427737</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2008-04-02T18:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: tacacs debug message</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-debug-message/m-p/581362#M427738</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The same problem has become bigger one now.we have been restarting the services here and there to resolve the login issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But now every 4 - 5 hrs we have to restart the service.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using acs 4.1 ( two boxes for redundancy  - with data replication)&lt;/P&gt;&lt;P&gt;Note : second box is not having any issues.&lt;/P&gt;&lt;P&gt; --is there any patch to be applied ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;error is as same as Prashant has posted above from the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. we have more than 5000 + devices getting auth from this box.&lt;/P&gt;&lt;P&gt;2.Not all devices are having issues&lt;/P&gt;&lt;P&gt;3.randomly devices are having issues whilie logging in / processing commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;example : first two logins will fail third will be a success&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can any one please help .........&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Aug 2009 13:13:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-debug-message/m-p/581362#M427738</guid>
      <dc:creator>rajivrajan1</dc:creator>
      <dc:date>2009-08-24T13:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: tacacs debug message</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-debug-message/m-p/581363#M427739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rajeev,&lt;/P&gt;&lt;P&gt;There are some known bugs on 4.1. I would suggest to upgrade it to 4.2 patch 12 and if you have single connect enabled, please disable it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate helpful post&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Aug 2009 13:40:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-debug-message/m-p/581363#M427739</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2009-08-24T13:40:14Z</dc:date>
    </item>
  </channel>
</rss>

