<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA Authorization + Switch Cluster = Fail? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-switch-cluster-fail/m-p/2165086#M507</link>
    <description>&lt;P&gt;Hi, I had a Switch Cluster running with local authentication and authorization just fine (with aaa new-model). It's a stack of 3750-Xs and several 2960s, they've all been configured more or less the same way with a configuration template. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I added AAA authentication and authorization and I can still reach each of the switches individually, but when I try to rcommand "x" from the cluster commander, I get:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#rcommand 2&lt;/P&gt;&lt;P&gt;% Authorization failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of the 2960s is a stack and when I run rcommand to that switch I get something different:&lt;/P&gt;&lt;P&gt;#rcommand 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EBMIASWF1LB-01 tty1 is now available&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Press RETURN to get started.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; All other 2960s give me "% Authorization failed."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3750s are running: &lt;/P&gt;&lt;P&gt;Cisco IOS Software, C3750E Software (C3750E-UNIVERSALK9-M), Version 12.2(55)SE3, RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt;2960Ses are running:&lt;/P&gt;&lt;P&gt;Cisco IOS Software, C2960S Software (C2960S-UNIVERSALK9-M), Version 12.2(55)SE5, RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt;2960s are running:&lt;/P&gt;&lt;P&gt;Cisco IOS Software, C2960 Software (C2960-LANLITEK9-M), Version 12.2(55)SE5, RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried a debug aaa authentication and aaa authorization on the member (destination) 2960 switch and I got this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;541120: Mar&amp;nbsp; 7 2013 17:14:30.729 EST: CLUSTER_MEMBER_2: AAA/BIND(00004788): Bind i/f&amp;nbsp; &lt;/P&gt;&lt;P&gt;541121: Mar&amp;nbsp; 7 2013 17:14:30.729 EST: CLUSTER_MEMBER_2: AAA: parse name=tty4 idb type=-1 tty=-1&lt;/P&gt;&lt;P&gt;541122: Mar&amp;nbsp; 7 2013 17:14:30.729 EST: CLUSTER_MEMBER_2: AAA: name=tty4 flags=0x11 type=5 shelf=0 slot=0 adapter=0 port=4 channel=0&lt;/P&gt;&lt;P&gt;541123: Mar&amp;nbsp; 7 2013 17:14:30.729 EST: CLUSTER_MEMBER_2: AAA/MEMORY: create_user (0x29DA580) user='radiususer' ruser='NULL' ds0=0 port='tty4' rem_addr='10.183.182.128' authen_type=ASCII service=LOGIN priv=15 initial_task_id='0', vrf= (id=0)&lt;/P&gt;&lt;P&gt;541124: Mar&amp;nbsp; 7 2013 17:14:30.729 EST: CLUSTER_MEMBER_2: AAA/AUTHOR (0x4788): Pick method list 'default'&lt;/P&gt;&lt;P&gt;541125: Mar&amp;nbsp; 7 2013 17:14:30.754 EST: CLUSTER_MEMBER_2: AAA/AUTHOR/EXEC(00004788): Authorization FAILED&lt;/P&gt;&lt;P&gt;541126: Mar&amp;nbsp; 7 2013 17:14:32.859 EST: CLUSTER_MEMBER_2: AAA/MEMORY: free_user (0x29DA580) user='radiususer' ruser='NULL' port='tty4' rem_addr='10.183.182.128' authen_type=ASCII service=LOGIN priv=15&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Debug on 2960S (stack) is the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The radius server is a Microsoft NPS (IAS on 2012) and all switches have AAA configured the same:&lt;/P&gt;&lt;P&gt;NPS is sending these AV Pairs:&lt;/P&gt;&lt;P&gt;shell:priv-lvl=15&lt;/P&gt;&lt;P&gt;Service-Type = Administrative&lt;/P&gt;&lt;P&gt;Service-Type = NAS-Prompt-User&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switches are configured like this:&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius RadiusAAA&lt;/P&gt;&lt;P&gt; server x.x.x.x auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt; server y.y.y.y auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt; ip radius source-interface VlanXX&lt;/P&gt;&lt;P&gt; deadtime 1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default group RadiusAAA local&lt;/P&gt;&lt;P&gt;aaa authorization exec default group RadiusAAA if-authenticated local &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;! etc etc&lt;/P&gt;&lt;P&gt;radius-server host x.x.x.x auth-port 1645 acct-port 1646 key 7 &amp;lt;radius key&amp;gt;&lt;/P&gt;&lt;P&gt;radius-server host y.y.y.y auth-port 1645 acct-port 1646 key 7 &amp;lt;radius key&amp;gt;&lt;/P&gt;&lt;P&gt;radius-server deadtime 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've also tried moving around the &lt;/P&gt;&lt;P&gt;aaa authorization exec default group RadiusAAA if-authenticated local &lt;/P&gt;&lt;P&gt;to:&lt;/P&gt;&lt;P&gt;aaa authorization exec default group RadiusAAA local &lt;SPAN style="font-size: 10pt;"&gt;if-authenticated&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the results are the same... Telnet and SSH work great, but I'd like for the cluster to keep working!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for your help, I've spent a lot of time on this, and I don't even know if it's supported!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Esteban&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:28:10 GMT</pubDate>
    <dc:creator>estebanzarikian</dc:creator>
    <dc:date>2020-02-21T18:28:10Z</dc:date>
    <item>
      <title>AAA Authorization + Switch Cluster = Fail?</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-switch-cluster-fail/m-p/2165086#M507</link>
      <description>&lt;P&gt;Hi, I had a Switch Cluster running with local authentication and authorization just fine (with aaa new-model). It's a stack of 3750-Xs and several 2960s, they've all been configured more or less the same way with a configuration template. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I added AAA authentication and authorization and I can still reach each of the switches individually, but when I try to rcommand "x" from the cluster commander, I get:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#rcommand 2&lt;/P&gt;&lt;P&gt;% Authorization failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of the 2960s is a stack and when I run rcommand to that switch I get something different:&lt;/P&gt;&lt;P&gt;#rcommand 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EBMIASWF1LB-01 tty1 is now available&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Press RETURN to get started.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; All other 2960s give me "% Authorization failed."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3750s are running: &lt;/P&gt;&lt;P&gt;Cisco IOS Software, C3750E Software (C3750E-UNIVERSALK9-M), Version 12.2(55)SE3, RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt;2960Ses are running:&lt;/P&gt;&lt;P&gt;Cisco IOS Software, C2960S Software (C2960S-UNIVERSALK9-M), Version 12.2(55)SE5, RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt;2960s are running:&lt;/P&gt;&lt;P&gt;Cisco IOS Software, C2960 Software (C2960-LANLITEK9-M), Version 12.2(55)SE5, RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried a debug aaa authentication and aaa authorization on the member (destination) 2960 switch and I got this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;541120: Mar&amp;nbsp; 7 2013 17:14:30.729 EST: CLUSTER_MEMBER_2: AAA/BIND(00004788): Bind i/f&amp;nbsp; &lt;/P&gt;&lt;P&gt;541121: Mar&amp;nbsp; 7 2013 17:14:30.729 EST: CLUSTER_MEMBER_2: AAA: parse name=tty4 idb type=-1 tty=-1&lt;/P&gt;&lt;P&gt;541122: Mar&amp;nbsp; 7 2013 17:14:30.729 EST: CLUSTER_MEMBER_2: AAA: name=tty4 flags=0x11 type=5 shelf=0 slot=0 adapter=0 port=4 channel=0&lt;/P&gt;&lt;P&gt;541123: Mar&amp;nbsp; 7 2013 17:14:30.729 EST: CLUSTER_MEMBER_2: AAA/MEMORY: create_user (0x29DA580) user='radiususer' ruser='NULL' ds0=0 port='tty4' rem_addr='10.183.182.128' authen_type=ASCII service=LOGIN priv=15 initial_task_id='0', vrf= (id=0)&lt;/P&gt;&lt;P&gt;541124: Mar&amp;nbsp; 7 2013 17:14:30.729 EST: CLUSTER_MEMBER_2: AAA/AUTHOR (0x4788): Pick method list 'default'&lt;/P&gt;&lt;P&gt;541125: Mar&amp;nbsp; 7 2013 17:14:30.754 EST: CLUSTER_MEMBER_2: AAA/AUTHOR/EXEC(00004788): Authorization FAILED&lt;/P&gt;&lt;P&gt;541126: Mar&amp;nbsp; 7 2013 17:14:32.859 EST: CLUSTER_MEMBER_2: AAA/MEMORY: free_user (0x29DA580) user='radiususer' ruser='NULL' port='tty4' rem_addr='10.183.182.128' authen_type=ASCII service=LOGIN priv=15&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Debug on 2960S (stack) is the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The radius server is a Microsoft NPS (IAS on 2012) and all switches have AAA configured the same:&lt;/P&gt;&lt;P&gt;NPS is sending these AV Pairs:&lt;/P&gt;&lt;P&gt;shell:priv-lvl=15&lt;/P&gt;&lt;P&gt;Service-Type = Administrative&lt;/P&gt;&lt;P&gt;Service-Type = NAS-Prompt-User&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switches are configured like this:&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius RadiusAAA&lt;/P&gt;&lt;P&gt; server x.x.x.x auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt; server y.y.y.y auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt; ip radius source-interface VlanXX&lt;/P&gt;&lt;P&gt; deadtime 1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default group RadiusAAA local&lt;/P&gt;&lt;P&gt;aaa authorization exec default group RadiusAAA if-authenticated local &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;! etc etc&lt;/P&gt;&lt;P&gt;radius-server host x.x.x.x auth-port 1645 acct-port 1646 key 7 &amp;lt;radius key&amp;gt;&lt;/P&gt;&lt;P&gt;radius-server host y.y.y.y auth-port 1645 acct-port 1646 key 7 &amp;lt;radius key&amp;gt;&lt;/P&gt;&lt;P&gt;radius-server deadtime 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've also tried moving around the &lt;/P&gt;&lt;P&gt;aaa authorization exec default group RadiusAAA if-authenticated local &lt;/P&gt;&lt;P&gt;to:&lt;/P&gt;&lt;P&gt;aaa authorization exec default group RadiusAAA local &lt;SPAN style="font-size: 10pt;"&gt;if-authenticated&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the results are the same... Telnet and SSH work great, but I'd like for the cluster to keep working!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for your help, I've spent a lot of time on this, and I don't even know if it's supported!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Esteban&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:28:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization-switch-cluster-fail/m-p/2165086#M507</guid>
      <dc:creator>estebanzarikian</dc:creator>
      <dc:date>2020-02-21T18:28:10Z</dc:date>
    </item>
  </channel>
</rss>

