<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TACACS: TACACS+ will use the password prompt from global TACACS+ configuration in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3719875#M542172</link>
    <description>&lt;P&gt;Any ideas why the Steps column in the ISE log is empty?&amp;nbsp; What could be wrong?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Fri, 05 Oct 2018 11:50:13 GMT</pubDate>
    <dc:creator>Ditter</dc:creator>
    <dc:date>2018-10-05T11:50:13Z</dc:date>
    <item>
      <title>TACACS: TACACS+ will use the password prompt from global TACACS+ configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3719134#M542166</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i am facing the following problem:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a basic TACACS+ configuration as far as the tacacs policy is concerned and is described in the attached PNG.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also have a local user &lt;STRONG&gt;&lt;U&gt;test&lt;/U&gt; &lt;/STRONG&gt;and a network device.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Overview&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;Request Type &amp;nbsp;&amp;nbsp; &amp;nbsp;Authentication&lt;BR /&gt;Status &amp;nbsp;&amp;nbsp; &amp;nbsp;Fail&lt;BR /&gt;Session Key &amp;nbsp;&amp;nbsp;&amp;nbsp; tacacs-server/327859046/169&lt;BR /&gt;Message Text &amp;nbsp;&amp;nbsp; &amp;nbsp;TACACS: TACACS+ will use the password prompt from global TACACS+ configuration&lt;BR /&gt;Username &amp;nbsp;&amp;nbsp; &amp;nbsp;test&lt;BR /&gt;Authentication Policy &amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Selected Authorization Profile &amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;Authentication Details&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;Generated Time &amp;nbsp;&amp;nbsp; &amp;nbsp;2018-10-04 13:25:43.840000 +03:00&lt;BR /&gt;Logged Time &amp;nbsp;&amp;nbsp; &amp;nbsp;2018-10-04 13:25:43.841&lt;BR /&gt;Epoch Time (sec) &amp;nbsp;&amp;nbsp; &amp;nbsp;1538648743&lt;BR /&gt;ISE Node &amp;nbsp;&amp;nbsp;&amp;nbsp; tacacs-server&lt;BR /&gt;Message Text &amp;nbsp;&amp;nbsp; &amp;nbsp;TACACS: TACACS+ will use the password prompt from global TACACS+ configuration&lt;BR /&gt;Failure Reason &amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Resolution &amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Root Cause &amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Username &amp;nbsp;&amp;nbsp; &amp;nbsp;test&lt;BR /&gt;Network Device Name &amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Network Device IP &amp;nbsp;&amp;nbsp; &amp;nbsp;1.1.1.1&lt;BR /&gt;Network Device Groups &amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Device Type &amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Location &amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Device Port &amp;nbsp;&amp;nbsp; &amp;nbsp;tty3&lt;BR /&gt;Remote Address &amp;nbsp;&amp;nbsp; &amp;nbsp;192.168.1.2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;TACACS Protocol&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;Authentication Action &amp;nbsp;&amp;nbsp; &amp;nbsp;Login&lt;BR /&gt;Authentication Privilege Level &amp;nbsp;&amp;nbsp; &amp;nbsp;1&lt;BR /&gt;Authentication Type &amp;nbsp;&amp;nbsp; &amp;nbsp;ASCII&lt;BR /&gt;Authentication Service &amp;nbsp;&amp;nbsp; &amp;nbsp;Login&lt;BR /&gt;&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;Other Attributes&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;ConfigVersionId &amp;nbsp;&amp;nbsp; &amp;nbsp;86&lt;BR /&gt;Device Port &amp;nbsp;&amp;nbsp; &amp;nbsp;15896&lt;BR /&gt;MajorVersion &amp;nbsp;&amp;nbsp; &amp;nbsp;Default&lt;BR /&gt;MinorVersion &amp;nbsp;&amp;nbsp; &amp;nbsp;Default&lt;BR /&gt;Type &amp;nbsp;&amp;nbsp; &amp;nbsp;Authentication&lt;BR /&gt;Sequence-Number &amp;nbsp;&amp;nbsp; &amp;nbsp;1&lt;BR /&gt;Header-Flags &amp;nbsp;&amp;nbsp; &amp;nbsp;Encrypted&lt;BR /&gt;SessionId &amp;nbsp;&amp;nbsp; &amp;nbsp;2246432117&lt;BR /&gt;EnableSingleConnect &amp;nbsp;&amp;nbsp; &amp;nbsp;false&lt;BR /&gt;CiscoIOS &amp;nbsp;&amp;nbsp; &amp;nbsp;false&lt;BR /&gt;UseSingleConnect &amp;nbsp;&amp;nbsp; &amp;nbsp;false&lt;BR /&gt;SelectedAccessService &amp;nbsp;&amp;nbsp; &amp;nbsp;Default Device Admin&lt;BR /&gt;Sequence-Number &amp;nbsp;&amp;nbsp; &amp;nbsp;2&lt;BR /&gt;CPMSessionID &amp;nbsp;&amp;nbsp; &amp;nbsp;22464321171.1.1.115896Authentication2246432117&lt;BR /&gt;Response &amp;nbsp;&amp;nbsp; &amp;nbsp;{AuthenticationResult=NotPerformed; }&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ditter.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 08:50:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3719134#M542166</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2019-03-11T08:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS: TACACS+ will use the password prompt from global TACACS+ configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3719175#M542167</link>
      <description>&lt;P&gt;Asking our SME on this one.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 11:37:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3719175#M542167</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2018-10-04T11:37:04Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS: TACACS+ will use the password prompt from global TACACS+ configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3719196#M542168</link>
      <description>&lt;P&gt;Perhaps, it was not clear from my previous answer, the problem with this configuration is that the authentication fails, although the users logs in the switch. I would suppose that the ISE would show in the logs a green tickbox instead of a red circle as far as the authentication is concerned. The message that show in the logs is the following:&lt;/P&gt;
&lt;P&gt;TACACS: TACACS+ will use the password prompt from global TACACS+ configuration&amp;nbsp;&amp;nbsp; which confuses me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ditter&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 12:05:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3719196#M542168</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2018-10-04T12:05:11Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS: TACACS+ will use the password prompt from global TACACS+ configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3719258#M542169</link>
      <description>&lt;P&gt;Can you please provide the logs from the right side under "Steps" (its the same page you provided for "Overview" and "Authorization Details")&lt;/P&gt;
&lt;P&gt;If you can also provide a debug of the runtime-AAA log file that would also help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks,&lt;/P&gt;
&lt;P&gt;Danny&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 13:19:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3719258#M542169</guid>
      <dc:creator>ldanny</dc:creator>
      <dc:date>2018-10-04T13:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS: TACACS+ will use the password prompt from global TACACS+ configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3719279#M542170</link>
      <description>&lt;P&gt;The problem is that the right side of the log window is blank ! I have nothing there....&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 13:37:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3719279#M542170</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2018-10-04T13:37:12Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS: TACACS+ will use the password prompt from global TACACS+ configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3719284#M542171</link>
      <description>&lt;P&gt;in addition i do not see the aaa log in debug level menu, see attached&lt;/P&gt;</description>
      <pubDate>Thu, 04 Oct 2018 13:42:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3719284#M542171</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2018-10-04T13:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS: TACACS+ will use the password prompt from global TACACS+ configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3719875#M542172</link>
      <description>&lt;P&gt;Any ideas why the Steps column in the ISE log is empty?&amp;nbsp; What could be wrong?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2018 11:50:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3719875#M542172</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2018-10-05T11:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS: TACACS+ will use the password prompt from global TACACS+ configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3720150#M542173</link>
      <description>&lt;P&gt;Not sure why your not seeing "Steps" on the right of that same page , seems very odd . You might want to follow up with TAC on that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The log file which you need to change the status to debug is runtime-AAA&lt;/P&gt;
&lt;P&gt;Its in the list.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2018 18:14:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3720150#M542173</guid>
      <dc:creator>ldanny</dc:creator>
      <dc:date>2018-10-05T18:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS: TACACS+ will use the password prompt from global TACACS+ configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3722402#M542174</link>
      <description>&lt;P&gt;Just following up if you have had a chance to provide us the debug file as you mention you cannot see anything under "Steps"&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 06:15:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3722402#M542174</guid>
      <dc:creator>ldanny</dc:creator>
      <dc:date>2018-10-10T06:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS: TACACS+ will use the password prompt from global TACACS+ configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3722658#M542175</link>
      <description>&lt;P&gt;Thank you for your followup.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found out the culprit why the live log file was partially empty.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;More specifically as i was trying to reduce the mass of logged messages, i accidentally erased LogCollector from passed authentication logging categories.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The strange thing was that i got Authentication Fail in the Live logs (the red circle with the x on it). When i&lt;/P&gt;
&lt;P&gt;re-enabled the LogCollector the authentication succeeded again with the green tick box !!&amp;nbsp; Please note that i did not change anything except from adding back the LogCollector in the Passed Authentication Category !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It seems to me more of a bug and not a normal behavior.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One idea would be the admin user not to be able to remove logcollector from this logging event.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas why there is this dependency between logcollector and authentication behavior?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ditter&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 12:45:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3722658#M542175</guid>
      <dc:creator>Ditter</dc:creator>
      <dc:date>2018-10-10T12:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS: TACACS+ will use the password prompt from global TACACS+ configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3738515#M542176</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;More specifically as i was trying to reduce the mass of logged messages, i accidentally erased LogCollector from passed authentication logging categories.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The strange thing was that i got Authentication Fail in the Live logs (the red circle with the x on it). When i&lt;/P&gt;
&lt;P&gt;re-enabled the LogCollector the authentication succeeded again with the green tick box !!&amp;nbsp; Please note that i did not change anything except from adding back the LogCollector in the Passed Authentication Category !&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It seems to me more of a bug and not a normal behavior.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;This could be a bug. Please engage Cisco TAC to recreate this behavior so TAC may file a bug. I tried it by removing LogCollector from Passed Authentication but did not observed any auth failure events.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;One idea would be the admin user not to be able to remove logcollector from this logging event.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;ISE allows three types (UDP SysLog, TCP SysLog, and Secure SysLog) of remote syslog targets so LogCollector needs not be the one forwarding the events to MnT.&lt;/P&gt;</description>
      <pubDate>Sat, 03 Nov 2018 19:12:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/3738515#M542176</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-11-03T19:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS: TACACS+ will use the password prompt from global TACACS+ c</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/5139970#M590407</link>
      <description>&lt;P&gt;was the issue resolve ? I have identical error adding ADVA box on tacacs&amp;nbsp;&lt;/P&gt;
&lt;P&gt;13045 TACACS+ will use the password prompt from global TACACS+ configuration ( [Step latency=0ms] Step latency=0ms)&lt;BR /&gt;13015 Returned TACACS+ Authentication Reply ( [Step latency=0ms] Step latency=0ms)&lt;BR /&gt;13014 Received TACACS+ Authentication CONTINUE Request ( [Step latency=2191ms] Step latency=2191ms)&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2024 08:47:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/5139970#M590407</guid>
      <dc:creator>piotr1970</dc:creator>
      <dc:date>2024-07-04T08:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS: TACACS+ will use the password prompt from global TACACS+ c</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/5295192#M596583</link>
      <description>&lt;P&gt;in my case verified with Adva support ,legacy adva software related issue. solution was adva upgrade or workaround would be ISE user password same with user "enable" setup.&lt;/P&gt;</description>
      <pubDate>Fri, 30 May 2025 09:51:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-tacacs-will-use-the-password-prompt-from-global-tacacs/m-p/5295192#M596583</guid>
      <dc:creator>piotr1970</dc:creator>
      <dc:date>2025-05-30T09:51:03Z</dc:date>
    </item>
  </channel>
</rss>

