<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA - ACS-Tacacs+ in ISE 2.1 configuration Issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470252#M530491</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am currently doing a POC in one of our customer and started configuring ACS however i have some issue in authentication. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #575757;"&gt;&lt;STRONG style="text-decoration: underline;"&gt;here is the scenario:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;* i have a reacheability from switch to ISE server.&lt;/P&gt;&lt;P&gt;* no i am geeting access denied and i don't see any hits in my ISE logs.&lt;/P&gt;&lt;P&gt;* From firewall: port 49 is open.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is the sample switch config;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;tacacs server ISE&lt;/P&gt;&lt;P&gt; address ipv4 10.10.x.x&lt;/P&gt;&lt;P&gt; key cisco&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ ISE_GROUP&lt;/P&gt;&lt;P&gt; server name ISE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login AAA group ISE_GROUP local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group ISE_GROUP enable&lt;/P&gt;&lt;P&gt;aaa authorization exec AAA group ISE_GROUP local &lt;/P&gt;&lt;P&gt;aaa authorization commands 0 AAA group ISE_GROUP local &lt;/P&gt;&lt;P&gt;aaa authorization commands 1 AAA group ISE_GROUP local &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 AAA group ISE_GROUP local&lt;/P&gt;&lt;P&gt;aaa authorization config-commands &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group ISE_GROUP&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group ISE_GROUP&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group ISE_GROUP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; authorization commands 0 AAA&lt;/P&gt;&lt;P&gt; authorization commands 1 AAA&lt;/P&gt;&lt;P&gt; authorization commands 15 AAA&lt;/P&gt;&lt;P&gt; authorization exec AAA&lt;/P&gt;&lt;P&gt; login authentication AAA&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;line vty 5 15&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;authorization commands 0 AAA&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt; authorization commands 1 AAA&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt; authorization commands 15 AAA&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt; authorization exec AAA&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt; login authentication AAA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Testing: &lt;/P&gt;&lt;P&gt;Router#test aaa group tacacs+ manny password legacy (this username is from the ISE databaase)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Attempting authentication test to server-group tacacs+ using tacacs+&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;No authoritative response from any server.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have used this procedures to configure my ISE servers;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/servlet/JiveServlet/downloadBody/68194-102-1-125121/How-To_TACACS_for_IOS.pdf" title="https://communities.cisco.com/servlet/JiveServlet/downloadBody/68194-102-1-125121/How-To_TACACS_for_IOS.pdf"&gt;https://communities.cisco.com/servlet/JiveServlet/downloadBody/68194-102-1-125121/How-To_TACACS_for_IOS.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise if there is a missing configuration in the switch.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 28 Mar 2017 13:30:29 GMT</pubDate>
    <dc:creator>mannygawadcco</dc:creator>
    <dc:date>2017-03-28T13:30:29Z</dc:date>
    <item>
      <title>AAA - ACS-Tacacs+ in ISE 2.1 configuration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470252#M530491</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am currently doing a POC in one of our customer and started configuring ACS however i have some issue in authentication. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #575757;"&gt;&lt;STRONG style="text-decoration: underline;"&gt;here is the scenario:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;* i have a reacheability from switch to ISE server.&lt;/P&gt;&lt;P&gt;* no i am geeting access denied and i don't see any hits in my ISE logs.&lt;/P&gt;&lt;P&gt;* From firewall: port 49 is open.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is the sample switch config;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;tacacs server ISE&lt;/P&gt;&lt;P&gt; address ipv4 10.10.x.x&lt;/P&gt;&lt;P&gt; key cisco&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ ISE_GROUP&lt;/P&gt;&lt;P&gt; server name ISE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login AAA group ISE_GROUP local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group ISE_GROUP enable&lt;/P&gt;&lt;P&gt;aaa authorization exec AAA group ISE_GROUP local &lt;/P&gt;&lt;P&gt;aaa authorization commands 0 AAA group ISE_GROUP local &lt;/P&gt;&lt;P&gt;aaa authorization commands 1 AAA group ISE_GROUP local &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 AAA group ISE_GROUP local&lt;/P&gt;&lt;P&gt;aaa authorization config-commands &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group ISE_GROUP&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group ISE_GROUP&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group ISE_GROUP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; authorization commands 0 AAA&lt;/P&gt;&lt;P&gt; authorization commands 1 AAA&lt;/P&gt;&lt;P&gt; authorization commands 15 AAA&lt;/P&gt;&lt;P&gt; authorization exec AAA&lt;/P&gt;&lt;P&gt; login authentication AAA&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;line vty 5 15&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt;authorization commands 0 AAA&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt; authorization commands 1 AAA&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt; authorization commands 15 AAA&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt; authorization exec AAA&lt;/P&gt;&lt;P style="font-size: 13.3333px;"&gt; login authentication AAA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Testing: &lt;/P&gt;&lt;P&gt;Router#test aaa group tacacs+ manny password legacy (this username is from the ISE databaase)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Attempting authentication test to server-group tacacs+ using tacacs+&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;No authoritative response from any server.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have used this procedures to configure my ISE servers;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/servlet/JiveServlet/downloadBody/68194-102-1-125121/How-To_TACACS_for_IOS.pdf" title="https://communities.cisco.com/servlet/JiveServlet/downloadBody/68194-102-1-125121/How-To_TACACS_for_IOS.pdf"&gt;https://communities.cisco.com/servlet/JiveServlet/downloadBody/68194-102-1-125121/How-To_TACACS_for_IOS.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise if there is a missing configuration in the switch.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Mar 2017 13:30:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470252#M530491</guid>
      <dc:creator>mannygawadcco</dc:creator>
      <dc:date>2017-03-28T13:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: AAA - ACS-Tacacs+ in ISE 2.1 configuration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470253#M530492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;did you verified the the tacacs services are running on the ise?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="t+service.JPG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/105743_t+service.JPG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i receive this error if either the tacacs service is down or the ise isn't aware of the nad and isn't responding.&lt;/P&gt;&lt;P&gt;But you'll see a log entry on the ise if the nad isn't configured&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="t+unknownnad.JPG" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/105744_t+unknownnad.JPG" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Mar 2017 14:01:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470253#M530492</guid>
      <dc:creator>Oliver Laue</dc:creator>
      <dc:date>2017-03-28T14:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: AAA - ACS-Tacacs+ in ISE 2.1 configuration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470254#M530493</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Oliver for the response, however the Enable Device Admin Service has been selected and it was running from the beginning. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please note also that I haven't received any logs from ISE.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Mar 2017 17:21:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470254#M530493</guid>
      <dc:creator>mannygawadcco</dc:creator>
      <dc:date>2017-03-28T17:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: AAA - ACS-Tacacs+ in ISE 2.1 configuration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470255#M530494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;did you fired some debug commands on the switch to see what it does also did you checked the ise application logs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Mar 2017 17:48:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470255#M530494</guid>
      <dc:creator>Oliver Laue</dc:creator>
      <dc:date>2017-03-28T17:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: AAA - ACS-Tacacs+ in ISE 2.1 configuration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470256#M530495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I did some debug for aaa and authentication, but what i've got is only access denied.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Mar 2017 17:59:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470256#M530495</guid>
      <dc:creator>mannygawadcco</dc:creator>
      <dc:date>2017-03-28T17:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: AAA - ACS-Tacacs+ in ISE 2.1 configuration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470257#M530496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try debug tacacs on the device to see what's going on. If the device has multiple IP addresses make sure the correct one is configured in ISE.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Mar 2017 20:15:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470257#M530496</guid>
      <dc:creator>ruhearn</dc:creator>
      <dc:date>2017-03-28T20:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: AAA - ACS-Tacacs+ in ISE 2.1 configuration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470258#M530497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the debug output for tacacs authentication and aaa autentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;QYS-GFC-SW#debug tacacs authentication&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;TACACS+ authentication debugging is on&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;QYS-GFC-SW#debug aaa authe&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;QYS-GFC-SW#debug aaa authentication&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;AAA Authentication debugging is on&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;QYS-GFC-SW#terminal monitor&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;QYS-GFC-SW#terminal monitor&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;QYS-GFC-SW#&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: AAA/MEMORY: free_user (0x5093FE0) user='cisco' ruser='QYS-GFC-SW' port='tty1' rem_addr='10.10.45.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 25' authen_type=ASCII service=NONE priv=15&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: AAA/BIND(000000ED): Bind i/f&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: AAA/AUTHEN/LOGIN (000000ED): Pick method list 'AAA'&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS: Queuing AAA Authentication request 237 for processing&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS: processing authentication start request id 237&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS: Authentication start packet created for 237(manny)&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS: Using server 10.10.201.35&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS(000000ED)/0/NB_WAIT/4FC8790: Started 5 sec timeout&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS(000000ED)/0/NB_WAIT/4FC8790: timed out&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS: Choosing next server 10.10.201.35&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS(000000ED)/1/NB_WAIT/4FC8790: Started 5 sec timeout&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS(000000ED)/4FC8790: releasing old socket 0&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS(000000ED)/1/NB_WAIT/4FC8790: timed out&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS(000000ED)/1/NB_WAIT/4FC8790: timed out, clean up&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS(000000ED)/1/4FC8790: Processing the reply packet&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: %SEC_LOGIN-4-LOGIN_FAILED: Login failed [user: manny] [Source: 10.10.45.25] [localport: 22] [Reas&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on: Login Authentication Failed] at 01:40:40 UTC Thu Jan 20 1994&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: AAA/AUTHEN/LOGIN (000000ED): Pick method list 'AAA'&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS: Queuing AAA Authentication request 237 for processing&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS: processing authentication start request id 237&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS: Authentication start packet created for 237(manny)&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS: Using server 10.10.201.35&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS(000000ED)/0/NB_WAIT/5017030: Started 5 sec timeout&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS(000000ED)/0/NB_WAIT/5017030: timed out&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS: Choosing next server 10.10.201.35&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS(000000ED)/1/NB_WAIT/5017030: Started 5 sec timeout&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS(000000ED)/5017030: releasing old socket 0&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS(000000ED)/1/NB_WAIT/5017030: timed out&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS(000000ED)/1/NB_WAIT/5017030: timed out, clean up&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS(000000ED)/1/5017030: Processing the reply packet&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: %SEC_LOGIN-4-LOGIN_FAILED: Login failed [user: manny] [Source: 10.10.45.25] [localport: 22] [Reason: Login Authentication Failed] at 01:41:07 UTC Thu Jan 20 1994&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: AAA/AUTHEN/LOGIN (000000ED): Pick method list 'AAA'&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS: Queuing AAA Authentication request 237 for processing&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS: processing authentication start request id 237&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS: Authentication start packet created for 237(manny)&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS: Using server 10.10.201.35&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS(000000ED)/0/NB_WAIT/4ED4574: Started 5 sec timeout&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS(000000ED)/0/NB_WAIT/4ED4574: timed out&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;46w2d: TPLUS(000000ED)/0/NB_WAIT/4ED4574: timed out, clean up&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;46w2d: TPLUS(000000ED)/0/4ED4574: Processing the reply packet&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Mar 2017 07:16:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470258#M530497</guid>
      <dc:creator>mannygawadcco</dc:creator>
      <dc:date>2017-03-29T07:16:16Z</dc:date>
    </item>
    <item>
      <title>Re: AAA - ACS-Tacacs+ in ISE 2.1 configuration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470259#M530498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Additional Information (Tacacs Server's IP is Correct)&lt;/P&gt;&lt;P&gt;QYS-GFC-SW#show tacacs&lt;/P&gt;&lt;P&gt;Tacacs+ Server -&amp;nbsp; public&amp;nbsp; :&amp;nbsp; 10.10.201.35/49&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Socket opens:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 62&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Socket closes:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 62&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Socket aborts:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Socket errors:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Socket Timeouts:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Failed Connect Attempts:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 58&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Packets Sent:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Packets Recv:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tacacs+ Server -&amp;nbsp; private&amp;nbsp; :&amp;nbsp; 10.10.201.35/49&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Socket opens:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 52&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Socket closes:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 52&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Socket aborts:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Socket errors:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Socket Timeouts:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Failed Connect Attempts:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 40&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Packets Sent:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Packets Recv:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ise capture.JPG" class="image-1 jive-image" src="/legacyfs/online/fusion/105778_ise capture.JPG" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Mar 2017 07:20:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470259#M530498</guid>
      <dc:creator>mannygawadcco</dc:creator>
      <dc:date>2017-03-29T07:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: AAA - ACS-Tacacs+ in ISE 2.1 configuration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470260#M530499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, this is what I use for TACACS+, we are a smaller install, so don't use groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is my switch commands.&lt;/P&gt;&lt;P&gt;tacacs-server host &amp;lt;IP_Sever1&amp;gt; key &amp;lt;VARIABLE&amp;gt;&lt;/P&gt;&lt;P&gt;tacacs-server host &lt;SPAN style="font-size: 13.3333px;"&gt;&amp;lt;IP_Sever2&amp;gt;&lt;/SPAN&gt; key &amp;lt;VARIABLE&amp;gt;&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;tacacs-server administration&lt;/P&gt;&lt;P&gt;radius-server dead-criteria time 5 tries 2&lt;/P&gt;&lt;P&gt;radius-server deadtime 2&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local &lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs+ local &lt;/P&gt;&lt;P&gt;aaa authorization commands 8 default group tacacs+ local &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ local &lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 8 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE settings are basically default.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.JPG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/105867_Capture.JPG" style="height: 682px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Mar 2017 17:45:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470260#M530499</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2017-03-30T17:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: AAA - ACS-Tacacs+ in ISE 2.1 configuration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470261#M530500</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would suggest to try a wireshark/TCPDUMP capture between ISE PSN and the switch. Also, enable DEBUG on ISE component AAA-runtime and check prrt-server.log.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Mar 2017 22:33:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470261#M530500</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-03-30T22:33:31Z</dc:date>
    </item>
    <item>
      <title>Re: AAA - ACS-Tacacs+ in ISE 2.1 configuration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470262#M530501</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's working now, i found out the i have issue with my device management license, so after applying it, it worked perfectly. Thanks folks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 02 Apr 2017 10:43:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470262#M530501</guid>
      <dc:creator>mannygawadcco</dc:creator>
      <dc:date>2017-04-02T10:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: AAA - ACS-Tacacs+ in ISE 2.1 configuration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470263#M530502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Manny,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if you tested the redundancy scenario but I am getting the same error message even though licenses (base + tacacs) are properly installed on each ISE. My situation is the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using an INTEGRATED DEPLOYMENT with 2 ISE Nodes. One of them is Primary PAN, Sec MNT and PSN. The other one is Sec PAN, Primary MNT and PSN. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not using AAA Groups for tacacs on the LAN Switch. I was testing the redundancy scenario on which Secondary PSN/Primary MNT was completely shutdown (halt command from cli). The Primary PAN/PSN did not work so I decided to test each node individually from the LAN Switch. I mean:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the only entry in the LAN switch is the Primary MNT/PSN, I get the following and tacacs authc worked.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SW#test aaa group tacacs+ test testing legacy&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Attempting authentication test to server-group tacacs+ using tacacs+&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;User was successfully authenticated.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then, I removed the IP entry for the Primary MNT/PSN in the switch and replaced it by the PRIMARY PAN/PSN but it failed and I got this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SW#test aaa group tacacs+ test testing legacy&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Attempting authentication test to server-group tacacs+ using tacacs+&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;No authoritative response from any server.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you seen this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2018 20:39:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470263#M530502</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2018-05-09T20:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: AAA - ACS-Tacacs+ in ISE 2.1 configuration Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470264#M530503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please try what I suggested. Use TCPDUMP to check whether the T+ requests are sending out and received by the ISE PSN. Then, use ISE live log and runtime DEBUG to debug further.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2018 21:32:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-acs-tacacs-in-ise-2-1-configuration-issue/m-p/3470264#M530503</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-05-09T21:32:49Z</dc:date>
    </item>
  </channel>
</rss>

