<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tacacs and CATOS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-and-catos/m-p/117482#M436499</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have authentication login tacacs on to lets say line/enable password as secondary?  It should only ask you for the password not the uname/password when ACS server is down.  What version of code are you running?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding your second q. yes it is possible to go to enable mode directly, but for that you need to have "shell/exec" checked and priv-lvl set to 15.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.  Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mynul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 02 Jun 2003 16:27:54 GMT</pubDate>
    <dc:creator>mhoda</dc:creator>
    <dc:date>2003-06-02T16:27:54Z</dc:date>
    <item>
      <title>Tacacs and CATOS</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-catos/m-p/117481#M436498</link>
      <description>&lt;P&gt;I am finding when the TACACS server is unavailable that when telnetting to the Catalyst (CATOS) switch I am being prompted for the username even after it tells you that the server is unavailable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The TACACS configuration is;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;set authentication login tacacs enable telnet primary&lt;/P&gt;&lt;P&gt;set authentication enable tacacs enable telnet primary&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;set authorisation exec enable tacacs+ if-authenticated telnet &lt;/P&gt;&lt;P&gt;set authorisation enable enable tacacs+ if-authenticated telnet&lt;/P&gt;&lt;P&gt;set authorisation commands enable all if-authenticated telnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also can you telnet directly into the enable mode if you are authenticated to do so based on your username/password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:19:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-catos/m-p/117481#M436498</guid>
      <dc:creator>ijohnstone</dc:creator>
      <dc:date>2019-03-10T14:19:57Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs and CATOS</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-catos/m-p/117482#M436499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have authentication login tacacs on to lets say line/enable password as secondary?  It should only ask you for the password not the uname/password when ACS server is down.  What version of code are you running?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding your second q. yes it is possible to go to enable mode directly, but for that you need to have "shell/exec" checked and priv-lvl set to 15.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.  Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mynul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jun 2003 16:27:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-catos/m-p/117482#M436499</guid>
      <dc:creator>mhoda</dc:creator>
      <dc:date>2003-06-02T16:27:54Z</dc:date>
    </item>
  </channel>
</rss>

