<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AP1200 + ACS + Enable in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373480#M439520</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oke, this is my config on the AP now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ tac_admin&lt;/P&gt;&lt;P&gt; server A.B.C.D&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius rad_pmip&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius dummy&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius rad_admin&lt;/P&gt;&lt;P&gt; server A.B.C.D auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default local group tac_admin group rad_admin&lt;/P&gt;&lt;P&gt;aaa authentication login eap_methods group rad_eap&lt;/P&gt;&lt;P&gt;aaa authentication login mac_methods local&lt;/P&gt;&lt;P&gt;aaa authorization exec default local group tac_admin group rad_admin&lt;/P&gt;&lt;P&gt;aaa authorization ipmobile default group rad_pmip&lt;/P&gt;&lt;P&gt;aaa accounting network acct_methods start-stop group rad_acct&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host A.B.C.D key #########&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;radius-server host A.B.C.D auth-port 1645 acct-port 1646 key 7 ############&lt;/P&gt;&lt;P&gt;radius-server attribute 32 include-in-access-req format %h&lt;/P&gt;&lt;P&gt;radius-server authorization permit missing Service-Type&lt;/P&gt;&lt;P&gt;radius-server vsa send accounting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ACS server I have added a device with the same IP address as the AP but with a different name. Selected Authenticate Using TACACS+ (Cisco IOS) and added the devive to the same group. Restarted the ACS services and tried again. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It allows me to log on with the HTTP interface but on level 1. No failed attempts in the login. When I click on Security and provide the username and password it is not accepted. Again no message in the failed attempts but I do get one in the Passed Authentication log. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;13/01/2005 12:16:27 Authen OK USERNAME CISCO Access Points A.B.C.D. tty2 E.F.G.H&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any more ideas for me to try? I am getting desperate. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Jan 2005 11:15:19 GMT</pubDate>
    <dc:creator>Taruka001</dc:creator>
    <dc:date>2005-01-13T11:15:19Z</dc:date>
    <item>
      <title>AP1200 + ACS + Enable</title>
      <link>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373472#M439422</link>
      <description>&lt;P&gt;My goal is to be able to telnet to the AP1200 by using my Windows account. To make this possible I have configured the AP to use the ACS server for authentication and configured the ACS to verify the username and the password from an external database. &lt;/P&gt;&lt;P&gt;When I telnet I can log on with my Windows credentials but have priv 1. It does not matter what I do on the ACS server to get priv 15, it stay's priv 1. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User Setup &amp;gt; Advanced TACACS+ Settings &amp;gt; Max Privilige for any device (Level 15)&lt;/P&gt;&lt;P&gt;Tacacs+ Enable Password Either "Use External password" or "User separate password".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I try to change to enable mode I get % Error in Authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is besides the obvious setting mentioned above not much to find on this topic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anybody any idea on what to check and try out?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 20:57:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373472#M439422</guid>
      <dc:creator>Taruka001</dc:creator>
      <dc:date>2019-03-10T20:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: AP1200 + ACS + Enable</title>
      <link>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373473#M439447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the TACACS+ Settings section, have you ticked the 'Shell(exec)' option?&lt;/P&gt;&lt;P&gt;If yes then it could be an issue with the aaa config on the AP. Can you provide details of the aaa config on the AP?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jan 2005 08:49:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373473#M439447</guid>
      <dc:creator>will.shaw</dc:creator>
      <dc:date>2005-01-12T08:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: AP1200 + ACS + Enable</title>
      <link>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373474#M439479</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the answer. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The user I am logging on with is part of a group. The group has the setting Shell (exec) ticked (TACACS+ Settings), and I tried to specify the Privilige Level 15 but with no result. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With debug ip http authentication turned on I get a lot of the following.&lt;/P&gt;&lt;P&gt;*Mar  2 13:15:04.019: setting privlevel to 1&lt;/P&gt;&lt;P&gt;*Mar  2 13:15:04.019: HTTP: Authentication for url '/' '/' level 1  privless '/'&lt;/P&gt;&lt;P&gt;*Mar  2 13:15:04.021: HTTP: authentication required, no authentication information was provided&lt;/P&gt;&lt;P&gt;*Mar  2 13:15:09.471: setting privlevel to 1&lt;/P&gt;&lt;P&gt;*Mar  2 13:15:09.471: HTTP: Authentication for url '/' '/' level 1  privless '/'&lt;/P&gt;&lt;P&gt;*Mar  2 13:15:09.471: HTTP: Authentication username = 'my-user-name' priv-level = 1 auth-type = aaa&lt;/P&gt;&lt;P&gt;*Mar  2 13:15:09.777: setting privlevel to 1&lt;/P&gt;&lt;P&gt;*Mar  2 13:15:09.777: HTTP: Authentication for url '/config.js' '/config.js' level 1  privless '/config.js'&lt;/P&gt;&lt;P&gt;*Mar  2 13:15:09.778: HTTP: Authentication username = 'my-user-name' priv-level = 1 auth-type = a&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it allows me to get in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I click on "Security" in the webinterface I am prompted with the logon box. When I enter my credentials I get the following information in the debug window&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Mar  2 13:19:14.552: setting privlevel to 15&lt;/P&gt;&lt;P&gt;*Mar  2 13:19:14.552: HTTP: Authentication for url '/ap_sec.htm' '/ap_sec.htm' level 15  privless '/ap_sec.htm'&lt;/P&gt;&lt;P&gt;*Mar  2 13:19:14.552: HTTP: Authentication username = 'my-user-name' priv-level = 15 auth-type = aaa&lt;/P&gt;&lt;P&gt;*Mar  2 13:19:14.596: HTTP: Authentication failed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this help? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jan 2005 09:51:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373474#M439479</guid>
      <dc:creator>Taruka001</dc:creator>
      <dc:date>2005-01-12T09:51:46Z</dc:date>
    </item>
    <item>
      <title>Re: AP1200 + ACS + Enable</title>
      <link>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373475#M439492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there any information on the ACS in the TACACS+ Administration or the Failed attempts section?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jan 2005 10:22:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373475#M439492</guid>
      <dc:creator>will.shaw</dc:creator>
      <dc:date>2005-01-12T10:22:15Z</dc:date>
    </item>
    <item>
      <title>Re: AP1200 + ACS + Enable</title>
      <link>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373476#M439500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, no messages in the failed authentication attempts. Only messages in the passed authentication attempts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jan 2005 10:37:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373476#M439500</guid>
      <dc:creator>Taruka001</dc:creator>
      <dc:date>2005-01-12T10:37:50Z</dc:date>
    </item>
    <item>
      <title>Re: AP1200 + ACS + Enable</title>
      <link>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373477#M439508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Doubt this is an issue with your ACS server. Can you provide the aaa config? Also what have you set the 'ip http authentication' line to?&lt;/P&gt;&lt;P&gt;Which software version are you running?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jan 2005 10:56:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373477#M439508</guid>
      <dc:creator>will.shaw</dc:creator>
      <dc:date>2005-01-12T10:56:37Z</dc:date>
    </item>
    <item>
      <title>Re: AP1200 + ACS + Enable</title>
      <link>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373478#M439511</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Personally I am also starting the suspect the AP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AP software is 12.2(13)JA1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The config on the AP for AAA is pasted below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius rad_eap&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius rad_mac&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius rad_acct&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius rad_admin&lt;/P&gt;&lt;P&gt; server IPA.IPB.IPC.IPD auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ tac_admin&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius rad_pmip&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius dummy&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default local group tac_admin group rad_admin&lt;/P&gt;&lt;P&gt;aaa authentication login eap_methods group rad_eap&lt;/P&gt;&lt;P&gt;aaa authentication login mac_methods local&lt;/P&gt;&lt;P&gt;aaa authorization exec default local group tac_admin group rad_admin&lt;/P&gt;&lt;P&gt;aaa authorization ipmobile default group rad_pmip&lt;/P&gt;&lt;P&gt;aaa accounting network acct_methods start-stop group rad_acct&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;radius-server host IPA.IPB.IPC.IPD auth-port 1645 acct-port 1646 key 7 ##################&lt;/P&gt;&lt;P&gt;radius-server attribute 32 include-in-access-req format %h&lt;/P&gt;&lt;P&gt;radius-server authorization permit missing Service-Type&lt;/P&gt;&lt;P&gt;radius-server vsa send accounting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jan 2005 11:17:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373478#M439511</guid>
      <dc:creator>Taruka001</dc:creator>
      <dc:date>2005-01-12T11:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: AP1200 + ACS + Enable</title>
      <link>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373479#M439517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You don't appear to be using tacacs+, just radius. Radius won't give you anymore than level1 access&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;try&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ tac_admin&lt;/P&gt;&lt;P&gt;  server ipa.ipb.ipc.ipd&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip http authentication aaa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host ipa.ipb.ipc.ipd key 7 ############&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you will also need to define the AP on the ACS as a tacacs+ device as well as a radius device, this is possible if use a different name for the device on the ACS. &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jan 2005 11:34:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373479#M439517</guid>
      <dc:creator>will.shaw</dc:creator>
      <dc:date>2005-01-12T11:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: AP1200 + ACS + Enable</title>
      <link>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373480#M439520</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oke, this is my config on the AP now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ tac_admin&lt;/P&gt;&lt;P&gt; server A.B.C.D&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius rad_pmip&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius dummy&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius rad_admin&lt;/P&gt;&lt;P&gt; server A.B.C.D auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default local group tac_admin group rad_admin&lt;/P&gt;&lt;P&gt;aaa authentication login eap_methods group rad_eap&lt;/P&gt;&lt;P&gt;aaa authentication login mac_methods local&lt;/P&gt;&lt;P&gt;aaa authorization exec default local group tac_admin group rad_admin&lt;/P&gt;&lt;P&gt;aaa authorization ipmobile default group rad_pmip&lt;/P&gt;&lt;P&gt;aaa accounting network acct_methods start-stop group rad_acct&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host A.B.C.D key #########&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;radius-server host A.B.C.D auth-port 1645 acct-port 1646 key 7 ############&lt;/P&gt;&lt;P&gt;radius-server attribute 32 include-in-access-req format %h&lt;/P&gt;&lt;P&gt;radius-server authorization permit missing Service-Type&lt;/P&gt;&lt;P&gt;radius-server vsa send accounting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ACS server I have added a device with the same IP address as the AP but with a different name. Selected Authenticate Using TACACS+ (Cisco IOS) and added the devive to the same group. Restarted the ACS services and tried again. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It allows me to log on with the HTTP interface but on level 1. No failed attempts in the login. When I click on Security and provide the username and password it is not accepted. Again no message in the failed attempts but I do get one in the Passed Authentication log. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;13/01/2005 12:16:27 Authen OK USERNAME CISCO Access Points A.B.C.D. tty2 E.F.G.H&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any more ideas for me to try? I am getting desperate. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2005 11:15:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373480#M439520</guid>
      <dc:creator>Taruka001</dc:creator>
      <dc:date>2005-01-13T11:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: AP1200 + ACS + Enable</title>
      <link>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373481#M439523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In your cisco ACS, check in the Tacacs+ accounting and the radius Accounting to see which is being used for the authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure in your AP config you are using the &lt;/P&gt;&lt;P&gt;#ip http authentication aaa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My aaa configuration is setup as the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius rad_eap&lt;/P&gt;&lt;P&gt; server #.#.#.# auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ tac_admin&lt;/P&gt;&lt;P&gt; server #.#.#.#&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default local group tac_admin group rad_admin&lt;/P&gt;&lt;P&gt;aaa authentication login eap_methods group rad_eap&lt;/P&gt;&lt;P&gt;aaa authentication login mac_methods local&lt;/P&gt;&lt;P&gt;aaa authorization exec default local group tac_admin group rad_admin &lt;/P&gt;&lt;P&gt;aaa accounting network acct_methods start-stop group rad_acct&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host #.#.#.# key 7 #############&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;radius-server attribute 32 include-in-access-req format %h&lt;/P&gt;&lt;P&gt;radius-server host #.#.#.# auth-port 1645 acct-port 1646 key #####&lt;/P&gt;&lt;P&gt;radius-server key 7 #####&lt;/P&gt;&lt;P&gt;radius-server vsa send accounting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip http authentication aaa&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2005 12:36:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373481#M439523</guid>
      <dc:creator>will.shaw</dc:creator>
      <dc:date>2005-01-13T12:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: AP1200 + ACS + Enable</title>
      <link>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373482#M439525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi again,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The config is below. I did the commands you gave and it did not work. Nothing shows up in the RADIUS and TACACS accounting logs. No a single row. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius rad_eap&lt;/P&gt;&lt;P&gt; server #.#.#.# auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius rad_mac&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius rad_acct&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius rad_admin&lt;/P&gt;&lt;P&gt; server #.#.#.# auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ tac_admin&lt;/P&gt;&lt;P&gt; server #.#.#.#&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius rad_pmip&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius dummy&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default local group tac_admin group rad_admin&lt;/P&gt;&lt;P&gt;aaa authentication login eap_methods group rad_eap&lt;/P&gt;&lt;P&gt;aaa authentication login mac_methods local&lt;/P&gt;&lt;P&gt;aaa authorization exec default local group tac_admin group rad_admin&lt;/P&gt;&lt;P&gt;aaa authorization ipmobile default group rad_pmip&lt;/P&gt;&lt;P&gt;aaa accounting network acct_methods start-stop group rad_acct&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host #.#.#.# key SHARED-SECRET&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;radius-server host #.#.#.# auth-port 1645 acct-port 1646 key 7 SHARED-SECRET&lt;/P&gt;&lt;P&gt;radius-server attribute 32 include-in-access-req format %h&lt;/P&gt;&lt;P&gt;radius-server key 7 shared_secret&lt;/P&gt;&lt;P&gt;radius-server authorization permit missing Service-Type&lt;/P&gt;&lt;P&gt;radius-server vsa send accounting&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;13/01/2005 14:46:45 Authen OK MYNAME CISCO Access Points A.B.C.D tty6 E.F.G.H &lt;/P&gt;&lt;P&gt;13/01/2005 14:47:26 Authen OK MYNAME CISCO Access Points A.B.C.D tty2 E.F.G.H&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After the first login attempt I added rad_admin line as well. Still nothing in the logs and no level 15 access for me...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2005 13:52:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373482#M439525</guid>
      <dc:creator>Taruka001</dc:creator>
      <dc:date>2005-01-13T13:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: AP1200 + ACS + Enable</title>
      <link>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373483#M439526</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You might want to raise a TAC on this one, it will be difficult to diagnose the issue without being able to debug etc and see the acs config etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It should work ok from what you've told me, however it still looks like it's using Radius to authenticate. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It doesn't look like your using radius for user authentication, if this is the case then I would take all the radius config off and work from a blank config. Make sure you configure a local username with level 15 access before doing this. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2005 14:06:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373483#M439526</guid>
      <dc:creator>will.shaw</dc:creator>
      <dc:date>2005-01-13T14:06:22Z</dc:date>
    </item>
    <item>
      <title>Re: AP1200 + ACS + Enable</title>
      <link>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373484#M439528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your help... This morning a router 1600 was made redundant so I have 'stolen' it to work with this one. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to all information everyhting is OK but for some reason it does not work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll see what comes out of the TAC case. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for the help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jan 2005 14:48:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373484#M439528</guid>
      <dc:creator>Taruka001</dc:creator>
      <dc:date>2005-01-13T14:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: AP1200 + ACS + Enable</title>
      <link>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373485#M439530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I understand you correct, you want to telnet on the device and logging in directly to the enable mode. That's the only thing you can do with Radius, there is no way to login first to user mode, then to go to enable mode with radius authentication. To do so, you have to send the following line as a Vendor Specific Attribute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;priv-level = 15 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(I'm not 100% sure about the syntax, as I'm not the my office to check it out correctly)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you should find information about this in the AP Documentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps you on your problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Simon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jan 2005 15:29:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373485#M439530</guid>
      <dc:creator>simonstoll</dc:creator>
      <dc:date>2005-01-14T15:29:28Z</dc:date>
    </item>
    <item>
      <title>Re: AP1200 + ACS + Enable</title>
      <link>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373486#M439532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Curious if you got any resolution from TAC,  I'm seeing the same thing here.   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The logs on the ACS server do show a passed authentication but authorization fail and the message on the telnet session says authentication unsuccessful.  I can even remove the authorization line from the AAA config on the AP.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also when I do a Show AAA Servers on the Radius server shows up not TACACS.   I can do a show TACACS and show that the correct IP address is configured but all of the entries are 0.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Feb 2005 17:26:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ap1200-acs-enable/m-p/373486#M439532</guid>
      <dc:creator>dopenfield</dc:creator>
      <dc:date>2005-02-10T17:26:30Z</dc:date>
    </item>
  </channel>
</rss>

