<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tacacs and GRE Tunnel in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-and-gre-tunnel/m-p/122619#M438242</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK - here is some more info:&lt;/P&gt;&lt;P&gt;router versions local 12.2(6b) remote 12.2(5d)&lt;/P&gt;&lt;P&gt;Ping sweep min to max OK&lt;/P&gt;&lt;P&gt;ACS message "Unknown NAS" &lt;/P&gt;&lt;P&gt;Source address is serial int of remote router in ACS device config&lt;/P&gt;&lt;P&gt;debug aaa on remote router shows a TAC+ send authen/start&lt;/P&gt;&lt;P&gt;then it has status "error" - then drops to line authentication&lt;/P&gt;&lt;P&gt;Thanks...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Apr 2003 16:24:53 GMT</pubDate>
    <dc:creator>awairlines</dc:creator>
    <dc:date>2003-04-02T16:24:53Z</dc:date>
    <item>
      <title>Tacacs and GRE Tunnel</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-gre-tunnel/m-p/122617#M438240</link>
      <description>&lt;P&gt;Tacacs authentication doesn't work after passing thru GRE tunnel with Crypto map.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:14:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-gre-tunnel/m-p/122617#M438240</guid>
      <dc:creator>awairlines</dc:creator>
      <dc:date>2019-03-10T14:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs and GRE Tunnel</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-gre-tunnel/m-p/122618#M438241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We need more information than that please if we're going to help you.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What version of router code on both sides?  Can you ping to the TACACS server over the tunnel with all different sizes of packets (up to and including 1500bytes)?  What does the log on the ACS server say, anything in Failed Attempts or Passed Authentications?  Are you sure you're sourcing the TACACS packets from the same interface as the IP address you have entered in as the NAS on the ACS server (check for Unknown NAS errors in the Failed Attempts log)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Apr 2003 00:45:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-gre-tunnel/m-p/122618#M438241</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2003-04-02T00:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs and GRE Tunnel</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-gre-tunnel/m-p/122619#M438242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK - here is some more info:&lt;/P&gt;&lt;P&gt;router versions local 12.2(6b) remote 12.2(5d)&lt;/P&gt;&lt;P&gt;Ping sweep min to max OK&lt;/P&gt;&lt;P&gt;ACS message "Unknown NAS" &lt;/P&gt;&lt;P&gt;Source address is serial int of remote router in ACS device config&lt;/P&gt;&lt;P&gt;debug aaa on remote router shows a TAC+ send authen/start&lt;/P&gt;&lt;P&gt;then it has status "error" - then drops to line authentication&lt;/P&gt;&lt;P&gt;Thanks...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Apr 2003 16:24:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-gre-tunnel/m-p/122619#M438242</guid>
      <dc:creator>awairlines</dc:creator>
      <dc:date>2003-04-02T16:24:53Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs and GRE Tunnel</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-gre-tunnel/m-p/122620#M438243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, thanks.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you're getting Unknown NAS in ACS, then the TACACS packet is being sourced with a different router address than what you entered in ACS for that NAS.  You should be able to see what address the router is using by looking at the Unknown NAS error message.  you can either then add that address is for the NAS, or use the "ip tacacs source-interface ..." command to specify what address the router uses.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Apr 2003 01:20:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-gre-tunnel/m-p/122620#M438243</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2003-04-03T01:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs and GRE Tunnel</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-gre-tunnel/m-p/122621#M438244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The "ip tacacs source-interface" resolved the issue...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Apr 2003 16:15:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-gre-tunnel/m-p/122621#M438244</guid>
      <dc:creator>awairlines</dc:creator>
      <dc:date>2003-04-03T16:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs and GRE Tunnel</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-gre-tunnel/m-p/122622#M438245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had a similar problem where the router was on the end of a GRE tunnel and could ping the ACS (tacacs) server but could not use it for authentication.  The "ip tacacs source-interface" command resolved my problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Ben.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Apr 2008 01:28:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-gre-tunnel/m-p/122622#M438245</guid>
      <dc:creator>ben_johnson</dc:creator>
      <dc:date>2008-04-24T01:28:31Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs and GRE Tunnel</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-gre-tunnel/m-p/122623#M438246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello All, [Pls Rate if HELPS]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Normally in the CRYPTO Configuration the Crypto Sessions will be formed with some Private Loopback available in the Configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the TACACS Server will be in the same domain, so the "ip tacacs source-interface" command solved the problem of Urs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Crypto Originating LOCAL Interface at SPOKE Location, should be normally used for tacacs Source Interface in a general scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope I am Informative.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls Rate if HELPS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Guru Prasad R&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 Apr 2008 19:11:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-gre-tunnel/m-p/122623#M438246</guid>
      <dc:creator>guruprasadr</dc:creator>
      <dc:date>2008-04-27T19:11:38Z</dc:date>
    </item>
  </channel>
</rss>

