<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authorization Error in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3510005#M499358</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My version is 2.4. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below, some configurations...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Resposta-001.PNG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/117469_Resposta-001.PNG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Resposta-002.PNG" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/117473_Resposta-002.PNG" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Jun 2018 00:32:08 GMT</pubDate>
    <dc:creator>jaert.aguiar</dc:creator>
    <dc:date>2018-06-08T00:32:08Z</dc:date>
    <item>
      <title>Authorization Error</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3509998#M499351</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to connect to an ethernet switch that is configurated to access the ISE CISCO server.&lt;/P&gt;&lt;P&gt;Before I start the tests with ISE CISCO, I used the TACACS.net server. I configured in this server a local user and defined the default profile Authorization Policy with this parameter: priv-lvl=7. The authentication and authorization were OK to TACACS.net server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, I'm trying to configurate the access to the ISE CISCO. I have downloaded the ISE CISCO Evaluation virtual machine and configured access:&lt;/P&gt;&lt;P&gt;1 - Definition of Network Device&lt;/P&gt;&lt;P&gt;2 - Definitiion of TACACS Profile with rules to authentication and authorization&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to login in the ethernet switch using ISE CISCO like a TACACS server and received the error in the authorization. The authentication as OK.&lt;/P&gt;&lt;P&gt;I checked the authentication report and was used the policy that I defined.&lt;/P&gt;&lt;P&gt;In the authorization report, the column "Authorization Policy" is empty.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I define the ISE Server to apply the authorization policy and avoid the error?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 15:44:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3509998#M499351</guid>
      <dc:creator>jaert.aguiar</dc:creator>
      <dc:date>2018-06-07T15:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Error</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3509999#M499352</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you seen our how-to guides on setting up TACACS+ support in ISE for IOS devices?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https://communities.cisco.com/docs/DOC-64031&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 17:03:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3509999#M499352</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2018-06-07T17:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Error</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3510000#M499353</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seen the tutorials, but I'm trying to connect a ethernet swith from NR manufacturer that is used in a energy substation. &lt;/P&gt;&lt;P&gt;This ethernet switch has just a place where we can put the TACACS server IP, port, timeout and shared key. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to understant why the ISE CISCO not run any authorization policy, even the default policy. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In some youtube videos, I could see that when there is a error of authorization, is showed what policy was tested.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 17:21:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3510000#M499353</guid>
      <dc:creator>jaert.aguiar</dc:creator>
      <dc:date>2018-06-07T17:21:10Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Error</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3510001#M499354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So authentication is showing green, can you post the step data?&lt;/P&gt;&lt;P&gt;Authorization is usually checking commands against the set command set, so will not see a policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a snipit from mine. Authentication show polict, authz does not.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.JPG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/117460_Capture.JPG" style="height: 307px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 21:46:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3510001#M499354</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2018-06-07T21:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Error</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3510002#M499355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dustin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your return. &lt;/P&gt;&lt;P&gt;I could see in your report that the column Authorization Policy has values when the type is "Authorization". &lt;/P&gt;&lt;P&gt;This is the point. &lt;/P&gt;&lt;P&gt;In my case, this column never has values, indicating that the Authorization Police is never checked.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 23:23:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3510002#M499355</guid>
      <dc:creator>jaert.aguiar</dc:creator>
      <dc:date>2018-06-07T23:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Error</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3510003#M499356</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is my Tacacs Live Log... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Authorization-Error.PNG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/117466_Authorization-Error.PNG" style="height: 316px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2018 23:55:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3510003#M499356</guid>
      <dc:creator>jaert.aguiar</dc:creator>
      <dc:date>2018-06-07T23:55:14Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Error</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3510004#M499357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, I was mis-interpreting, I get what you are saying now.&lt;/P&gt;&lt;P&gt;1: Does authentication show a profile?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure what version of ISE you have, I have 2.3, so may be somewhat different.&lt;/P&gt;&lt;P&gt;if you go to work center/Device admin policy sets, you should have the default. I'm assuming you have made a rule under that for the switch to hit. Below is mine for an NX-OS device.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="117467" alt="Capture.JPG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/117467_Capture.JPG" style="height: 27px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;Now, for one of the ones you have without the policy, can you click on the details. Can you post the step data omitting any personal info. An example of mine is below. Do you see it hitting a permit rule?&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="117468" alt="Capture1.JPG" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/117468_Capture1.JPG" style="height: 77px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;13005 Received TACACS+ Authorization Request - my.domain&lt;/P&gt;&lt;P&gt;15049 Evaluating Policy Group - networker&lt;/P&gt;&lt;P&gt;15008 Evaluating Service Selection Policy - my.domain&lt;/P&gt;&lt;P&gt;15041 Evaluating Identity Policy - my.domain&lt;/P&gt;&lt;P&gt;22072 Selected identity source sequence - All_User_ID_Stores&lt;/P&gt;&lt;P&gt;15013 Selected Identity Source - my.domain&lt;/P&gt;&lt;P&gt;24432 Looking up user in Active Directory - my.domain&lt;/P&gt;&lt;P&gt;24325 Resolving identity - networker&lt;/P&gt;&lt;P&gt;24313 Search for matching accounts at join point - my.domain&lt;/P&gt;&lt;P&gt;24319 Single matching account found in forest - my.domain&lt;/P&gt;&lt;P&gt;24323 Identity resolution detected single matching account&lt;/P&gt;&lt;P&gt;22037 Authentication Passed&lt;/P&gt;&lt;P&gt;15036 Evaluating Authorization Policy&lt;/P&gt;&lt;P&gt;24432 Looking up user in Active Directory&lt;/P&gt;&lt;P&gt;24325 Resolving identity&lt;/P&gt;&lt;P&gt;24313 Search for matching accounts at join point&lt;/P&gt;&lt;P&gt;24319 Single matching account found in forest&lt;/P&gt;&lt;P&gt;24323 Identity resolution detected single matching account&lt;/P&gt;&lt;P&gt;24355 LDAP fetch succeeded&lt;/P&gt;&lt;P&gt;24416 User's Groups retrieval from Active Directory succeeded&lt;/P&gt;&lt;P&gt;15048 Queried PIP - my.domain.ExternalGroups&lt;/P&gt;&lt;P&gt;15048 Queried PIP - TACACS.User&lt;/P&gt;&lt;P&gt;15048 Queried PIP - DEVICE.Device Type&lt;/P&gt;&lt;P&gt;15048 Queried PIP - Network Access.UserName&lt;/P&gt;&lt;P&gt;15018 Selected Command Set&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;13024 Command matched a Permit rule&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;13034 Returned TACACS+ Authorization Reply&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 00:02:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3510004#M499357</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2018-06-08T00:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Error</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3510005#M499358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My version is 2.4. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below, some configurations...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Resposta-001.PNG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/117469_Resposta-001.PNG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Resposta-002.PNG" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/117473_Resposta-002.PNG" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 00:32:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3510005#M499358</guid>
      <dc:creator>jaert.aguiar</dc:creator>
      <dc:date>2018-06-08T00:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Error</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3510006#M499359</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Below some configurations...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Policy-Tacacs-000.PNG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/117474_Policy-Tacacs-000.PNG" style="height: 260px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Policy-Tacacs-001.PNG" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/117475_Policy-Tacacs-001.PNG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Policy-Tacacs-002.PNG" class="jive-image image-3" src="https://community.cisco.com/legacyfs/online/fusion/117476_Policy-Tacacs-002.PNG" style="height: 281px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Policy-Tacacs-004.PNG" class="jive-image image-4" src="https://community.cisco.com/legacyfs/online/fusion/117477_Policy-Tacacs-004.PNG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Policy-Tacacs-005.PNG" class="jive-image image-5" src="https://community.cisco.com/legacyfs/online/fusion/117478_Policy-Tacacs-005.PNG" style="height: 273px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 00:34:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3510006#M499359</guid>
      <dc:creator>jaert.aguiar</dc:creator>
      <dc:date>2018-06-08T00:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Error</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3510007#M499360</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok, there are no hits on the rules, and it fails with an invalid request. Sounds like the switch is not sending the request correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the switch you are using, what brand and model?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may want to dry different device and TACACS modes under the ISE network devices.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 01:03:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3510007#M499360</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2018-06-08T01:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Error</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3510008#M499361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The energy substation is using an ethernet switch PCS-9882GD, from NR Company.&lt;/P&gt;&lt;P&gt;This company just implement this TACACS function now and I tested with TACACS.NET server without problems.&lt;/P&gt;&lt;P&gt;But you can be right, they must to check the authorization request.&lt;/P&gt;&lt;P&gt;I will check with others devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for your support.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 01:12:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3510008#M499361</guid>
      <dc:creator>jaert.aguiar</dc:creator>
      <dc:date>2018-06-08T01:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Error</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3510009#M499362</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No problem, you can maybe also contact NR Company to see if they have implemented TACACS with ISE.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 01:30:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-error/m-p/3510009#M499362</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2018-06-08T01:30:08Z</dc:date>
    </item>
  </channel>
</rss>

