<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TACACS+ Server not logging events. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-server-not-logging-events/m-p/399163#M432526</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did both of those commands and then logged into the router from another crt term and did not see any debug msgs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 Mar 2005 18:59:58 GMT</pubDate>
    <dc:creator>nos</dc:creator>
    <dc:date>2005-03-10T18:59:58Z</dc:date>
    <item>
      <title>TACACS+ Server not logging events.</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-server-not-logging-events/m-p/399158#M432521</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having an issue with the tacacs+ server not logging login requests or commands entered. I am running the tac_plus.F4.0.4.alpha release that cisco provides for free on a mandrake 10.1 linux box.  I am able to use the server to authenticate logins to the routers but it is not logging those requests.&lt;/P&gt;&lt;P&gt;Here is the config I used on one of our routers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ prego&lt;/P&gt;&lt;P&gt; server xxx.xxx.xxx.xxx&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group prego&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;ip subnet-zero&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also here is a sh verion&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Internetwork Operating System Software &lt;/P&gt;&lt;P&gt;IOS (tm) 3700 Software (C3725-IS-M), Version 12.2(15)ZJ3, EARLY DEPLOYMENT RELEASE SOFTWARE (fc2)&lt;/P&gt;&lt;P&gt;TAC Support: &lt;A class="jive-link-custom" href="http://www.cisco.com/tac" target="_blank"&gt;http://www.cisco.com/tac&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Copyright (c) 1986-2003 by cisco Systems, Inc.&lt;/P&gt;&lt;P&gt;Compiled Thu 25-Sep-03 22:23 by eaarmas&lt;/P&gt;&lt;P&gt;Image text-base: 0x60008954, data-base: 0x61C2C000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ROM: System Bootstrap, Version 12.2(8r)T2, RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt;ROM: 3700 Software (C3725-I-M), Version 12.2(8)T10,  RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PRVGW3725 uptime is 10 weeks, 1 day, 7 hours, 35 minutes&lt;/P&gt;&lt;P&gt;System returned to ROM by power-on&lt;/P&gt;&lt;P&gt;System image file is "flash:c3725-is-mz.122-15.ZJ3.bin"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cisco 3725 (R7000) processor (revision 0.1) with 121856K/9216K bytes of memory.&lt;/P&gt;&lt;P&gt;Processor board ID JMX0749L1XC&lt;/P&gt;&lt;P&gt;R7000 CPU at 240Mhz, Implementation 39, Rev 3.3, 256KB L2 Cache&lt;/P&gt;&lt;P&gt;Bridging software.&lt;/P&gt;&lt;P&gt;X.25 software, Version 3.0.0.&lt;/P&gt;&lt;P&gt;SuperLAT software (copyright 1990 by Meridian Technology Corp).&lt;/P&gt;&lt;P&gt;2 FastEthernet/IEEE 802.3 interface(s)&lt;/P&gt;&lt;P&gt;2 Serial network interface(s)&lt;/P&gt;&lt;P&gt;DRAM configuration is 64 bits wide with parity disabled.&lt;/P&gt;&lt;P&gt;55K bytes of non-volatile configuration memory.&lt;/P&gt;&lt;P&gt;31360K bytes of ATA System CompactFlash (Read/Write)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuration register is 0x2102&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be great.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Joseph Jackson&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:02:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-server-not-logging-events/m-p/399158#M432521</guid>
      <dc:creator>nos</dc:creator>
      <dc:date>2019-03-10T21:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+ Server not logging events.</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-server-not-logging-events/m-p/399159#M432522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you need to enable aaa authorisation on the router ( ios ) device&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for e.g you want to log level 15 cmds then it would be like this&lt;/P&gt;&lt;P&gt;aaa authorisation commands level 15 default group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;explore the Cisco IOS aaa authorisation cmds a little more &amp;amp; you will know what to do&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2005 05:07:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-server-not-logging-events/m-p/399159#M432522</guid>
      <dc:creator>dbshah2000</dc:creator>
      <dc:date>2005-03-10T05:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+ Server not logging events.</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-server-not-logging-events/m-p/399160#M432523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I do not configure my routers with aaa authorization commands level 15 and my routers are reporting (accounting) level 15 commands just fine. So I disagree that this is required to get the results that he wants.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I notice in the original config that the accounting exec uses group prego while the authentication uses group tacacs+. I am not sure if there is an issue with the group prego but I would suggest changing the config for accounting to use group tacacs+ and see what happens.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2005 14:45:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-server-not-logging-events/m-p/399160#M432523</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2005-03-10T14:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+ Server not logging events.</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-server-not-logging-events/m-p/399161#M432524</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you both for replying to my post.  I have entered what you both said but still no luck.  Here is the updated config file showing the aaa stuff&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;ip subnet-zero&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you guys can think of anything else I'll give it a try. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2005 17:02:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-server-not-logging-events/m-p/399161#M432524</guid>
      <dc:creator>nos</dc:creator>
      <dc:date>2005-03-10T17:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+ Server not logging events.</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-server-not-logging-events/m-p/399162#M432525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are able to authenticate via TACACS I would believe that this indicates that there is not a problem with your configuration of the TACACS server(s) (addresses are correct, keys are correct, etc) and that the TACACS server recognizes the router ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I assume that either there is some problem on the router generating the accounting records. Or that there might be a problem on the server and receiving and processing the accounting records.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a next step in investigating this issue I suggest that you run two debugs on the router:&lt;/P&gt;&lt;P&gt;debug aaa accounting&lt;/P&gt;&lt;P&gt;debug tacacs accounting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While the debug is running have someone access the router and login, access privilege mode, and execute several commands. Then post any debug output.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2005 17:59:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-server-not-logging-events/m-p/399162#M432525</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2005-03-10T17:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+ Server not logging events.</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-server-not-logging-events/m-p/399163#M432526</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did both of those commands and then logged into the router from another crt term and did not see any debug msgs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2005 18:59:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-server-not-logging-events/m-p/399163#M432526</guid>
      <dc:creator>nos</dc:creator>
      <dc:date>2005-03-10T18:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+ Server not logging events.</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-server-not-logging-events/m-p/399164#M432527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How are you looking for the debug messages? (are you logging to logging buffered debug and then using the show log command, or are you logged on somewhere with terminal monitor enabled while the testing activity takes place?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do the test again and this time add another debug: debug tacacs authentication&lt;/P&gt;&lt;P&gt;That should generate some debug output. If we see the authentication output but no accounting output then there is a problem that the router is not generating accounting. If the authentication does not produce output then we have to look more carefully at where the output is going and how to find it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2005 21:24:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-server-not-logging-events/m-p/399164#M432527</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2005-03-10T21:24:14Z</dc:date>
    </item>
  </channel>
</rss>

