<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue with tacacs plus in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/issue-with-tacacs-plus/m-p/385459#M432550</link>
    <description>&lt;P&gt;I hava a tacacs server running on redhat. When I try to telnet to my router I get a bunch of garbage on the screen. Sometimes I get an authorization failed. Any ideas what I might have wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current configuration : 1063 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;version 12.2&lt;/P&gt;&lt;P&gt;no service single-slot-reload-enable&lt;/P&gt;&lt;P&gt;no service pad&lt;/P&gt;&lt;P&gt;service timestamps debug uptime&lt;/P&gt;&lt;P&gt;service timestamps log uptime&lt;/P&gt;&lt;P&gt;service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname Home&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;logging rate-limit console 10 except errors&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login tac group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;enable secret removed&lt;/P&gt;&lt;P&gt;enable password removed&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;username cisco password removed&lt;/P&gt;&lt;P&gt;ip subnet-zero&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip ssh time-out 120&lt;/P&gt;&lt;P&gt;ip ssh authentication-retries 3&lt;/P&gt;&lt;P&gt;no ip dhcp-client network-discovery&lt;/P&gt;&lt;P&gt;lcp max-session-starts 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0&lt;/P&gt;&lt;P&gt; ip address 192.168.1.105 255.255.255.0&lt;/P&gt;&lt;P&gt; no cdp enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet1&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; ip access-group 101 in&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no cdp enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip classless&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no cdp run&lt;/P&gt;&lt;P&gt;tacacs-server host 192.168.1.102&lt;/P&gt;&lt;P&gt;tacacs-server timeout 15&lt;/P&gt;&lt;P&gt;tacacs-server key cisco&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt; exec-timeout 120 0&lt;/P&gt;&lt;P&gt; transport input none&lt;/P&gt;&lt;P&gt; stopbits 1&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; exec-timeout 0 0&lt;/P&gt;&lt;P&gt; login authentication tac&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;scheduler max-task-time 5000&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;03:10:38: TPLUS: Queuing AAA Authentication request 25 for processing&lt;/P&gt;&lt;P&gt;03:10:38: TPLUS: processing authentication start request id 25&lt;/P&gt;&lt;P&gt;03:10:38: TPLUS: Authentication start packet created for 25()&lt;/P&gt;&lt;P&gt;03:10:38: TPLUS: Using server 192.168.1.102&lt;/P&gt;&lt;P&gt;03:10:38: TPLUS(00000019): connected to server 192.168.1.102&lt;/P&gt;&lt;P&gt;03:10:38: TPLUS: response received for AAA request 25&lt;/P&gt;&lt;P&gt;03:10:38: TPLUS: Received authentication response with status FAIL&lt;/P&gt;&lt;P&gt;03:10:40: TPLUS: Queuing AAA Authentication request 25 for processing&lt;/P&gt;&lt;P&gt;03:10:40: TPLUS: processing authentication start request id 25&lt;/P&gt;&lt;P&gt;03:10:40: TPLUS: Authentication start packet created for 25()&lt;/P&gt;&lt;P&gt;03:10:40: TPLUS: Using server 192.168.1.102&lt;/P&gt;&lt;P&gt;03:10:40: TPLUS(00000019): connected to server 192.168.1.102&lt;/P&gt;&lt;P&gt;03:10:40: TPLUS: response received for AAA request 25&lt;/P&gt;&lt;P&gt;03:10:40: TPLUS: Received authentication response with status FAIL&lt;/P&gt;&lt;P&gt;03:10:42: TPLUS: Queuing AAA Authentication request 25 for processing&lt;/P&gt;&lt;P&gt;03:10:42: TPLUS: processing authentication start request id 25&lt;/P&gt;&lt;P&gt;03:10:42: TPLUS: Authentication start packet created for 25()&lt;/P&gt;&lt;P&gt;03:10:42: TPLUS: Using server 192.168.1.102&lt;/P&gt;&lt;P&gt;03:10:42: TPLUS(00000019): connected to server 192.168.1.102&lt;/P&gt;&lt;P&gt;03:10:42: TPLUS: response received for AAA request 25&lt;/P&gt;&lt;P&gt;03:10:42: TPLUS: Received authentication response with status FAIL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 21:02:42 GMT</pubDate>
    <dc:creator>etucker</dc:creator>
    <dc:date>2019-03-10T21:02:42Z</dc:date>
    <item>
      <title>Issue with tacacs plus</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-tacacs-plus/m-p/385459#M432550</link>
      <description>&lt;P&gt;I hava a tacacs server running on redhat. When I try to telnet to my router I get a bunch of garbage on the screen. Sometimes I get an authorization failed. Any ideas what I might have wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current configuration : 1063 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;version 12.2&lt;/P&gt;&lt;P&gt;no service single-slot-reload-enable&lt;/P&gt;&lt;P&gt;no service pad&lt;/P&gt;&lt;P&gt;service timestamps debug uptime&lt;/P&gt;&lt;P&gt;service timestamps log uptime&lt;/P&gt;&lt;P&gt;service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname Home&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;logging rate-limit console 10 except errors&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login tac group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;enable secret removed&lt;/P&gt;&lt;P&gt;enable password removed&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;username cisco password removed&lt;/P&gt;&lt;P&gt;ip subnet-zero&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip ssh time-out 120&lt;/P&gt;&lt;P&gt;ip ssh authentication-retries 3&lt;/P&gt;&lt;P&gt;no ip dhcp-client network-discovery&lt;/P&gt;&lt;P&gt;lcp max-session-starts 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0&lt;/P&gt;&lt;P&gt; ip address 192.168.1.105 255.255.255.0&lt;/P&gt;&lt;P&gt; no cdp enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet1&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; ip access-group 101 in&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; no cdp enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip classless&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no cdp run&lt;/P&gt;&lt;P&gt;tacacs-server host 192.168.1.102&lt;/P&gt;&lt;P&gt;tacacs-server timeout 15&lt;/P&gt;&lt;P&gt;tacacs-server key cisco&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt; exec-timeout 120 0&lt;/P&gt;&lt;P&gt; transport input none&lt;/P&gt;&lt;P&gt; stopbits 1&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; exec-timeout 0 0&lt;/P&gt;&lt;P&gt; login authentication tac&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;scheduler max-task-time 5000&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;03:10:38: TPLUS: Queuing AAA Authentication request 25 for processing&lt;/P&gt;&lt;P&gt;03:10:38: TPLUS: processing authentication start request id 25&lt;/P&gt;&lt;P&gt;03:10:38: TPLUS: Authentication start packet created for 25()&lt;/P&gt;&lt;P&gt;03:10:38: TPLUS: Using server 192.168.1.102&lt;/P&gt;&lt;P&gt;03:10:38: TPLUS(00000019): connected to server 192.168.1.102&lt;/P&gt;&lt;P&gt;03:10:38: TPLUS: response received for AAA request 25&lt;/P&gt;&lt;P&gt;03:10:38: TPLUS: Received authentication response with status FAIL&lt;/P&gt;&lt;P&gt;03:10:40: TPLUS: Queuing AAA Authentication request 25 for processing&lt;/P&gt;&lt;P&gt;03:10:40: TPLUS: processing authentication start request id 25&lt;/P&gt;&lt;P&gt;03:10:40: TPLUS: Authentication start packet created for 25()&lt;/P&gt;&lt;P&gt;03:10:40: TPLUS: Using server 192.168.1.102&lt;/P&gt;&lt;P&gt;03:10:40: TPLUS(00000019): connected to server 192.168.1.102&lt;/P&gt;&lt;P&gt;03:10:40: TPLUS: response received for AAA request 25&lt;/P&gt;&lt;P&gt;03:10:40: TPLUS: Received authentication response with status FAIL&lt;/P&gt;&lt;P&gt;03:10:42: TPLUS: Queuing AAA Authentication request 25 for processing&lt;/P&gt;&lt;P&gt;03:10:42: TPLUS: processing authentication start request id 25&lt;/P&gt;&lt;P&gt;03:10:42: TPLUS: Authentication start packet created for 25()&lt;/P&gt;&lt;P&gt;03:10:42: TPLUS: Using server 192.168.1.102&lt;/P&gt;&lt;P&gt;03:10:42: TPLUS(00000019): connected to server 192.168.1.102&lt;/P&gt;&lt;P&gt;03:10:42: TPLUS: response received for AAA request 25&lt;/P&gt;&lt;P&gt;03:10:42: TPLUS: Received authentication response with status FAIL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:02:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-tacacs-plus/m-p/385459#M432550</guid>
      <dc:creator>etucker</dc:creator>
      <dc:date>2019-03-10T21:02:42Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with tacacs plus</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-tacacs-plus/m-p/385460#M432551</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have looked at the config that you posted and do not see any serious issues, though there are a couple of things that may be worth a comment. You have configured an authentication method for the vty ports so telnet access will use tacacs. But you have not configured an authentication method for the console and you have not configured (or at least not included in the posted config) any default authentication method for login.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also the tac authentication method used by the vty ports specifes that the tacacs server is the preferred method of authentication but if the server is not available the user can login in by specifying the enable password. I wonder if that is really what you intend. A more common configuration would be:&lt;/P&gt;&lt;P&gt;aaa authentication login tac group tacacs+ line&lt;/P&gt;&lt;P&gt;this would prefer tacacs and as a backup would use the configured line password.&lt;/P&gt;&lt;P&gt;Or you could configure:&lt;/P&gt;&lt;P&gt;aaa authentication login tac group tacacs+ local&lt;/P&gt;&lt;P&gt;if you have user names and passwords configured on the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The debug messages that you include are interesting and may give a clue to the problem. They do demonstrate that you are communicating with the tacacs server (it shows that you are sending messages and getting responses). This tells us that there is not a problem with the configuration of the server address or password. I think it also tells us that this router has been configured on the tacacs server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think that it is interesting that you are building a start packet and sending it to the tacacs server. And that you immediately get a response from the server of FAIL. There was no prompt for username or password which would be normal. This makes me wonder if there is some issue in the way that this router has been configured on the tacacs server. Is this router in a group by itself? and if so are there users who have access rights in this group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have other routers that do work with tacacs, I would suggest that you compare the tacacs server configuration of this router to the configuration of some other router that works and see if you can identify a difference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Mar 2005 03:29:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-tacacs-plus/m-p/385460#M432551</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2005-03-07T03:29:08Z</dc:date>
    </item>
  </channel>
</rss>

