<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.0 Radius NAS-IP and TACACS Source-IP are the same and failing in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-0-radius-nas-ip-and-tacacs-source-ip-are-the-same-and/m-p/3592751#M538926</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Brian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the AAA Server Group in your AnyConnect Connection profile for VPN users?&amp;nbsp; Please be sure you have the server group that has RADIUS as the protocol selected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 10 May 2016 18:51:22 GMT</pubDate>
    <dc:creator>Timothy Abbott</dc:creator>
    <dc:date>2016-05-10T18:51:22Z</dc:date>
    <item>
      <title>ISE 2.0 Radius NAS-IP and TACACS Source-IP are the same and failing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-radius-nas-ip-and-tacacs-source-ip-are-the-same-and/m-p/3592750#M538925</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This seems like it should be a no brainer for ISE to handle, but I can't seem to get an answer from Cisco yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have added my ASA firewall as a network object in ISE and I have selected the TACACS and RADIUS options within that network object. My firewall configuration is as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server TACACS protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TACACS (inside) host 10.12.12.61&lt;/P&gt;&lt;P&gt; key *****&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius&lt;/P&gt;&lt;P&gt; authorize-only&lt;/P&gt;&lt;P&gt; interim-accounting-update periodic 1&lt;/P&gt;&lt;P&gt; dynamic-authorization&lt;/P&gt;&lt;P&gt;aaa-server RADIUS (inside) host 10.12.12.61&lt;/P&gt;&lt;P&gt; key *****&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Because both TACACS and RADIUS are both pointing to ISE and TACACS comes first in the configuration, my VPN users are getting a "Dynamic Authorization Failed" message.&amp;nbsp; If I remove TACACS configuration or point it to our old ACS server than everything works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am also unable to move the TACACS configuration below the Radius.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone run into this or have a workaround?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 May 2016 18:41:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-radius-nas-ip-and-tacacs-source-ip-are-the-same-and/m-p/3592750#M538925</guid>
      <dc:creator>bforan</dc:creator>
      <dc:date>2016-05-10T18:41:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.0 Radius NAS-IP and TACACS Source-IP are the same and failing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-radius-nas-ip-and-tacacs-source-ip-are-the-same-and/m-p/3592751#M538926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Brian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the AAA Server Group in your AnyConnect Connection profile for VPN users?&amp;nbsp; Please be sure you have the server group that has RADIUS as the protocol selected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 May 2016 18:51:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-radius-nas-ip-and-tacacs-source-ip-are-the-same-and/m-p/3592751#M538926</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2016-05-10T18:51:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.0 Radius NAS-IP and TACACS Source-IP are the same and failing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-radius-nas-ip-and-tacacs-source-ip-are-the-same-and/m-p/3592752#M538928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yup, I do have the AAA Server Group for that specific Tunnel-Group set as RADIUS:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tunnel-group SSL-NETENG general-attributes&lt;/P&gt;&lt;P&gt; authentication-server-group RADIUS&lt;/P&gt;&lt;P&gt; authorization-server-group RADIUS&lt;/P&gt;&lt;P&gt; accounting-server-group RADIUS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 May 2016 18:58:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-radius-nas-ip-and-tacacs-source-ip-are-the-same-and/m-p/3592752#M538928</guid>
      <dc:creator>bforan</dc:creator>
      <dc:date>2016-05-10T18:58:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.0 Radius NAS-IP and TACACS Source-IP are the same and failing</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-radius-nas-ip-and-tacacs-source-ip-are-the-same-and/m-p/3592753#M538930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since RADIUS configuration is authorize-only, are you performing cert auth against ASA and then ISE for authorization only?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What errors in details are in the CoA attempts? It might worth to try enabling a 2nd interface on ISE with different IP address for T+ and see whether it would help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 15 May 2016 06:11:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-radius-nas-ip-and-tacacs-source-ip-are-the-same-and/m-p/3592753#M538930</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2016-05-15T06:11:02Z</dc:date>
    </item>
  </channel>
</rss>

