<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 2900x., aaa, enable pass in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/2900x-aaa-enable-pass/m-p/187139#M436119</link>
    <description>&lt;P&gt;We have a 2900xl with the following stats:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Internetwork Operating System Software&lt;/P&gt;&lt;P&gt;IOS (tm) C2900XL Software (C2900XL-C3H2S-M), Version 12.0(5.4)WC(1), MAINTENANCE INTERIM SOFTWARE&lt;/P&gt;&lt;P&gt;Copyright (c) 1986-2001 by cisco Systems, Inc.&lt;/P&gt;&lt;P&gt;Compiled Tue 10-Jul-01 11:52 by devgoyal&lt;/P&gt;&lt;P&gt;Image text-base: 0x00003000, data-base: 0x00333CD8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ROM: Bootstrap program is C2900XL boot loader&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;noc-devel uptime is 20 hours, 59 minutes&lt;/P&gt;&lt;P&gt;System returned to ROM by reload&lt;/P&gt;&lt;P&gt;System restarted at 15:26:11 east Wed Jul 23 2003&lt;/P&gt;&lt;P&gt;System image file is "flash:c2900XL-c3h2s-mz.120-5.4.WC.1.bin"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cisco WS-C2924M-XL (PowerPC403GA) processor (revision 0x11) with 8192K/1024K bytes of memory.&lt;/P&gt;&lt;P&gt;Processor board ID FAA0341F0XR, with hardware revision 0x03&lt;/P&gt;&lt;P&gt;Last reset from warm-reset&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Processor is running Enterprise Edition Software&lt;/P&gt;&lt;P&gt;Cluster command switch capable&lt;/P&gt;&lt;P&gt;Cluster member switch capable&lt;/P&gt;&lt;P&gt;25 FastEthernet/IEEE 802.3 interface(s)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;32K bytes of flash-simulated non-volatile configuration memory.&lt;/P&gt;&lt;P&gt;Base ethernet MAC Address: 00:30:19:46:EE:00&lt;/P&gt;&lt;P&gt;Motherboard assembly number: 73-3425-09&lt;/P&gt;&lt;P&gt;Power supply part number: 34-0920-01&lt;/P&gt;&lt;P&gt;Motherboard serial number: FAA03409DFB&lt;/P&gt;&lt;P&gt;Power supply serial number: NONE&lt;/P&gt;&lt;P&gt;Model revision number: A0&lt;/P&gt;&lt;P&gt;Model number: WS-C2924M-XL-EN&lt;/P&gt;&lt;P&gt;System serial number: FAA0341F0XR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Module     Ports  Model                  HW Version            SW version&lt;/P&gt;&lt;P&gt;------     -----  -----                  ----------            ----------&lt;/P&gt;&lt;P&gt;     1      2     WS-X2922-XL-V          xxxx                  xxxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuration register is 0xF&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are trying to configure aaa services on the device.  When we use the standard config which is working on all other devices, it fails on the 2900xl in the following way - it appears that the 2900xl is looking to TACACS/our NT domain controller for the enable pass and not authenticating against the configured password.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is our error:  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;noc-devel&amp;gt;en&lt;/P&gt;&lt;P&gt;Password:&lt;/P&gt;&lt;P&gt;% Error in authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is our config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ cisacs&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa accounting update newinfo&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 0 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting network default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting connection default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting system default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 14:25:23 GMT</pubDate>
    <dc:creator>kimlong</dc:creator>
    <dc:date>2019-03-10T14:25:23Z</dc:date>
    <item>
      <title>2900x., aaa, enable pass</title>
      <link>https://community.cisco.com/t5/network-access-control/2900x-aaa-enable-pass/m-p/187139#M436119</link>
      <description>&lt;P&gt;We have a 2900xl with the following stats:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco Internetwork Operating System Software&lt;/P&gt;&lt;P&gt;IOS (tm) C2900XL Software (C2900XL-C3H2S-M), Version 12.0(5.4)WC(1), MAINTENANCE INTERIM SOFTWARE&lt;/P&gt;&lt;P&gt;Copyright (c) 1986-2001 by cisco Systems, Inc.&lt;/P&gt;&lt;P&gt;Compiled Tue 10-Jul-01 11:52 by devgoyal&lt;/P&gt;&lt;P&gt;Image text-base: 0x00003000, data-base: 0x00333CD8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ROM: Bootstrap program is C2900XL boot loader&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;noc-devel uptime is 20 hours, 59 minutes&lt;/P&gt;&lt;P&gt;System returned to ROM by reload&lt;/P&gt;&lt;P&gt;System restarted at 15:26:11 east Wed Jul 23 2003&lt;/P&gt;&lt;P&gt;System image file is "flash:c2900XL-c3h2s-mz.120-5.4.WC.1.bin"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cisco WS-C2924M-XL (PowerPC403GA) processor (revision 0x11) with 8192K/1024K bytes of memory.&lt;/P&gt;&lt;P&gt;Processor board ID FAA0341F0XR, with hardware revision 0x03&lt;/P&gt;&lt;P&gt;Last reset from warm-reset&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Processor is running Enterprise Edition Software&lt;/P&gt;&lt;P&gt;Cluster command switch capable&lt;/P&gt;&lt;P&gt;Cluster member switch capable&lt;/P&gt;&lt;P&gt;25 FastEthernet/IEEE 802.3 interface(s)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;32K bytes of flash-simulated non-volatile configuration memory.&lt;/P&gt;&lt;P&gt;Base ethernet MAC Address: 00:30:19:46:EE:00&lt;/P&gt;&lt;P&gt;Motherboard assembly number: 73-3425-09&lt;/P&gt;&lt;P&gt;Power supply part number: 34-0920-01&lt;/P&gt;&lt;P&gt;Motherboard serial number: FAA03409DFB&lt;/P&gt;&lt;P&gt;Power supply serial number: NONE&lt;/P&gt;&lt;P&gt;Model revision number: A0&lt;/P&gt;&lt;P&gt;Model number: WS-C2924M-XL-EN&lt;/P&gt;&lt;P&gt;System serial number: FAA0341F0XR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Module     Ports  Model                  HW Version            SW version&lt;/P&gt;&lt;P&gt;------     -----  -----                  ----------            ----------&lt;/P&gt;&lt;P&gt;     1      2     WS-X2922-XL-V          xxxx                  xxxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuration register is 0xF&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are trying to configure aaa services on the device.  When we use the standard config which is working on all other devices, it fails on the 2900xl in the following way - it appears that the 2900xl is looking to TACACS/our NT domain controller for the enable pass and not authenticating against the configured password.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is our error:  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;noc-devel&amp;gt;en&lt;/P&gt;&lt;P&gt;Password:&lt;/P&gt;&lt;P&gt;% Error in authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is our config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ cisacs&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa accounting update newinfo&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 0 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting network default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting connection default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting system default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:25:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/2900x-aaa-enable-pass/m-p/187139#M436119</guid>
      <dc:creator>kimlong</dc:creator>
      <dc:date>2019-03-10T14:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: 2900x., aaa, enable pass</title>
      <link>https://community.cisco.com/t5/network-access-control/2900x-aaa-enable-pass/m-p/187140#M436120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What privilege level have you assigned for the users?  Is it between 2-15.  If not, please assign the priv-lvl between 2-15 and see if that helps.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mynul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Jul 2003 20:54:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/2900x-aaa-enable-pass/m-p/187140#M436120</guid>
      <dc:creator>mhoda</dc:creator>
      <dc:date>2003-07-24T20:54:33Z</dc:date>
    </item>
  </channel>
</rss>

