<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tacacs authentication denied after Cisco ISE failover in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-denied-after-cisco-ise-failover/m-p/3381359#M547598</link>
    <description>&lt;P&gt;Hi Jeremy,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After multiple changes on the deployment I got the same result as you. We need to break the deployment and rebuild it in order to make it work including redundancy scenarios when one of the PSN goes completely down. I tested each node individually and also shutting down each one at the time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Proceeding to talk to cisco about this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 May 2018 15:27:12 GMT</pubDate>
    <dc:creator>ajc</dc:creator>
    <dc:date>2018-05-10T15:27:12Z</dc:date>
    <item>
      <title>Tacacs authentication denied after Cisco ISE failover</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-denied-after-cisco-ise-failover/m-p/3215810#M547379</link>
      <description>&lt;P&gt;Hello guys,&lt;BR /&gt;&lt;BR /&gt;Could you help me to resolve a problem please.&lt;BR /&gt;&lt;BR /&gt;I use Cisco ISE cluster (version 2.3.0) with Active directory to verify which users are authorized to manage Cisco switch &amp;amp; Router.&lt;BR /&gt;However, when an automatic failover occur, I'm not able to connect to my devices with tacacs protocol&lt;BR /&gt;&lt;BR /&gt;The error show :&lt;BR /&gt;&lt;BR /&gt;login as: &amp;lt;user_x&amp;gt;&lt;BR /&gt;Using keyboard-interactive authentication.&lt;BR /&gt;Password:&lt;BR /&gt;Access denied&lt;BR /&gt;&lt;BR /&gt;I didn't find anything in log of ISE after the failover. Before that, the authentication working fine.&lt;BR /&gt;&lt;BR /&gt;Service on cluster :&lt;BR /&gt;TACACS1(Master) has : PAM, MNT &amp;amp; PSN =&amp;gt; 192.168.0.1&lt;BR /&gt;TACACS2(Standby) has : PAM, MNT &amp;amp; PSN =&amp;gt; 192.168.0.2&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;- Share key on both switch and ISE is OK&lt;BR /&gt;- Communication between AD and ISE is OK&lt;BR /&gt;&lt;BR /&gt;Switch config :&lt;BR /&gt;&lt;BR /&gt;switch1#&lt;BR /&gt;aaa group server tacacs+ TACACS_ADMIN&lt;BR /&gt;&amp;nbsp;server name TACACS1&lt;BR /&gt;&amp;nbsp;server name TACACS2&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default local&lt;BR /&gt;aaa authentication login AUTHENT group TACACS_ADMIN local&lt;BR /&gt;aaa authorization exec default group TACACS_ADMIN none&lt;BR /&gt;aaa accounting exec default start-stop group TACACS_ADMIN&lt;BR /&gt;!&lt;BR /&gt;tacacs server TACACS1&lt;BR /&gt;address ipv4 192.168.0.1&lt;BR /&gt;key 7 095841xxxxxxxxxxxxxxxx&lt;BR /&gt;tacacs server TACACS2&lt;BR /&gt;address ipv4 192.168.0.2&lt;BR /&gt;key 7 150604xxxxxxxxxxxxxxxx&lt;BR /&gt;!&lt;BR /&gt;line vty 0 4&lt;BR /&gt;login authentication AUTHENT&lt;BR /&gt;transport input ssh&lt;BR /&gt;line vty 5 15&lt;BR /&gt;login authentication AUTHENT&lt;BR /&gt;transport input ssh&lt;BR /&gt;&lt;BR /&gt;I did few tests on switch1 before launch manual failover&lt;BR /&gt;&lt;BR /&gt;Test on switch1 to reach TACACS1 (192.168.0.1) before failover&lt;BR /&gt;&lt;BR /&gt;switch1#test aaa group tacacs+ &amp;lt;user account&amp;gt; &amp;lt;pwd&amp;gt; legacy&lt;BR /&gt;Attempting authentication test to server-group tacacs+ using tacacs+&lt;BR /&gt;User was successfully authenticated.&lt;BR /&gt;&lt;BR /&gt;switch1#test aaa group TACACS_ADMIN server 192.168.0.1&amp;lt;user account&amp;gt; &amp;lt;pwd&amp;gt; legacy&lt;BR /&gt;Attempting authentication test to server-group TACACS_ADMIN using tacacs+&lt;BR /&gt;User was successfully authenticated.&lt;BR /&gt;&lt;BR /&gt;switch1#ping 192.168.0.1&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 192.168.0.1, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/2/8 ms&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;switch1#telnet 192.0.0.1 49&lt;BR /&gt;Trying 192.168.0.1, 49 ... Open&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Result:&lt;BR /&gt;&amp;nbsp;- Ping OK&lt;BR /&gt;&amp;nbsp;- Port 49 open&lt;BR /&gt;&amp;nbsp;- Authentication user OK with TACACS1 &amp;amp; AD (192.168.0.1)&lt;BR /&gt;&lt;BR /&gt;Now try the same test on switch1 to reach TACACS2 before failover&lt;BR /&gt;&lt;BR /&gt;switch1#ping 192.168.0.2&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 192.168.0.2, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 1/2/8 ms&lt;BR /&gt;&lt;BR /&gt;swrica05b#telnet 192.168.0.2 49&lt;BR /&gt;Trying 192.168.0.2, 49 ... Open&lt;BR /&gt;[Connection to 192.168.0.2 closed by foreign host]&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;switch1#test aaa group TACACS_ADMIN server 192.168.0.2 &amp;lt;user account&amp;gt; &amp;lt;pwd&amp;gt; legacy&lt;BR /&gt;Attempting authentication test to server-group TACACS_ADMIN using tacacs+&lt;BR /&gt;User was successfully authenticated.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Result :&lt;BR /&gt;- Ping OK&lt;BR /&gt;&amp;nbsp;- Port 49 open but closed immediatly (maybe because it's a standby cluster for PAM)&lt;BR /&gt;&amp;nbsp;- Authentication user OK with TACACS2 &amp;amp; AD (192.168.0.2)&lt;BR /&gt;&lt;BR /&gt;Now, I stop TACACS1 and launch new test. Still Access Denied.&lt;BR /&gt;I don't see anything in Operation =&amp;gt; Tacacs =&amp;gt; live logs on TACACS2&lt;BR /&gt;I launch debug on the switch. In attachment the result (Tacacs Log.txt).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- debug tacacs&lt;BR /&gt;&amp;nbsp;- debug aaa authentication&lt;BR /&gt;&lt;BR /&gt;switch1#sh tacacs&lt;BR /&gt;Tacacs+ Server -&amp;nbsp; public&amp;nbsp; :&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Server name: TACACS1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Server address: 192.168.0.1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Server port: 49&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Socket opens:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 24&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Socket closes:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 24&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Socket aborts:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Socket errors:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Socket Timeouts:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Failed Connect Attempts:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Packets Sent:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 26&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Packets Recv:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 21&lt;BR /&gt;&lt;BR /&gt;Tacacs+ Server -&amp;nbsp; public&amp;nbsp; :&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Server name: TACACS2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Server address: 192.168.0.2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Server port: 49&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Socket opens:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Socket closes:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Socket aborts:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Socket errors:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Socket Timeouts:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; Failed Connect Attempts:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Packets Sent:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Total Packets Recv:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;&lt;BR /&gt;I launch a tcpdump and I see this&lt;BR /&gt;&lt;BR /&gt;Sequence 1 src: switch1 dst: 192.168.0.2 protocol:tcp paquet : [syn]&lt;BR /&gt;Sequence 2 src: 192.168.0.2 dst: switch1 protocol:tcp paquet : [syn, ack]&lt;BR /&gt;Sequence 3 src: switch1 dst: 192.168.0.2 protocol:tcp paquet : [ack]&lt;BR /&gt;Sequence 4 src: 192.168.0.2 dst: switch1 protocol:tcp paquet : [fin, ack]&lt;BR /&gt;&lt;BR /&gt;Sequence 5 src: switch1 dst: 192.168.0.2 protocol:tacacs+ paquet : [authentication]&lt;BR /&gt;Sequence 6 src: 192.168.0.2 dst: switch1 protocol:tcp paquet : [RST]&lt;BR /&gt;&lt;BR /&gt;I think TACACS2 close the TCP/IP session before the tacacs authentication frame is sent. After that, a TCP/IP Reset occur.&lt;BR /&gt;&lt;BR /&gt;When I restart TACACS1 (which have secondary administration role now), I'm able to connect to my device. So I think I have a misconfiguration or problem on TACACS2.&lt;BR /&gt;&lt;BR /&gt;Someone can help me please.&lt;BR /&gt;&lt;BR /&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:38:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-denied-after-cisco-ise-failover/m-p/3215810#M547379</guid>
      <dc:creator>jeremytetart</dc:creator>
      <dc:date>2020-02-21T18:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs authentication denied after Cisco ISE failover</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-denied-after-cisco-ise-failover/m-p/3215963#M547380</link>
      <description>&lt;P&gt;dumb question perhaps, but does your license include TACACS for both servers (both UDI's)?&amp;nbsp; This can be a common thing to forget when creating the license - you have to include both UDI's when creating the license key.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2017 00:22:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-denied-after-cisco-ise-failover/m-p/3215963#M547380</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-11-14T00:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs authentication denied after Cisco ISE failover</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-denied-after-cisco-ise-failover/m-p/3216133#M547595</link>
      <description>&lt;P&gt;Hi Arme Bier,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The cluster is 90 days evaluation so all licences are god. (See attachment).&lt;/P&gt;
&lt;P&gt;I'm still investigating.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2017 08:35:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-denied-after-cisco-ise-failover/m-p/3216133#M547595</guid>
      <dc:creator>jeremytetart</dc:creator>
      <dc:date>2017-11-14T08:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs authentication denied after Cisco ISE failover</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-denied-after-cisco-ise-failover/m-p/3216328#M547596</link>
      <description>&lt;P&gt;Update: Broken and re-create the cluster has resolved my issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2017 14:27:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-denied-after-cisco-ise-failover/m-p/3216328#M547596</guid>
      <dc:creator>jeremytetart</dc:creator>
      <dc:date>2017-11-14T14:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs authentication denied after Cisco ISE failover</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-denied-after-cisco-ise-failover/m-p/3380962#M547597</link>
      <description>&lt;P&gt;I am having the exact same issue. Looks like we have a bug here because I have valid base and tacacs license with entries for both ISE nodes (I have a similar deployment like yours). Authentication works on PrimaryMNT/SecPAN/PSN but not the same on PrimaryPAN/SecMNT/PSN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will take a look again on the licenses just to be safe but I suspect that breaking the deployment and rebuilding is the only option. I will keep it post.&lt;/P&gt;</description>
      <pubDate>Wed, 09 May 2018 20:48:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-denied-after-cisco-ise-failover/m-p/3380962#M547597</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2018-05-09T20:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs authentication denied after Cisco ISE failover</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-denied-after-cisco-ise-failover/m-p/3381359#M547598</link>
      <description>&lt;P&gt;Hi Jeremy,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After multiple changes on the deployment I got the same result as you. We need to break the deployment and rebuild it in order to make it work including redundancy scenarios when one of the PSN goes completely down. I tested each node individually and also shutting down each one at the time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Proceeding to talk to cisco about this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 May 2018 15:27:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-denied-after-cisco-ise-failover/m-p/3381359#M547598</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2018-05-10T15:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs authentication denied after Cisco ISE failover</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-denied-after-cisco-ise-failover/m-p/3385663#M547599</link>
      <description>&lt;P&gt;Hi Abraham,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any news about Cisco ?&lt;/P&gt;</description>
      <pubDate>Fri, 18 May 2018 17:27:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-denied-after-cisco-ise-failover/m-p/3385663#M547599</guid>
      <dc:creator>jeremytetart</dc:creator>
      <dc:date>2018-05-18T17:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs authentication denied after Cisco ISE failover</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-denied-after-cisco-ise-failover/m-p/3385684#M547600</link>
      <description>&lt;P&gt;Looks like we are hitting the following &lt;A href="https://cdetsng.cisco.com/webui/#view=CSCvi18260" target="_blank"&gt;&lt;STRONG&gt;CSCvi18260&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;based on the information provided but NOT confirmed yet. I will keep you posted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 May 2018 18:09:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-denied-after-cisco-ise-failover/m-p/3385684#M547600</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2018-05-18T18:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs authentication denied after Cisco ISE failover</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-denied-after-cisco-ise-failover/m-p/3385926#M547601</link>
      <description>&lt;P&gt;I can't view the bug and the solution &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See the screenshoot in attachment.&lt;/P&gt;</description>
      <pubDate>Sat, 19 May 2018 14:50:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-denied-after-cisco-ise-failover/m-p/3385926#M547601</guid>
      <dc:creator>jeremytetart</dc:creator>
      <dc:date>2018-05-19T14:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs authentication denied after Cisco ISE failover</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-denied-after-cisco-ise-failover/m-p/4972688#M585571</link>
      <description>&lt;P&gt;If you are seeing resets on pcaps from ISE server, it might be Device Administration service is not enabled on the PSN.&lt;BR /&gt;In you case, you could have checked if device admin service is enabled under deployments page on you failover device.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 22:04:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-denied-after-cisco-ise-failover/m-p/4972688#M585571</guid>
      <dc:creator>Sri Harsha Dasari</dc:creator>
      <dc:date>2023-12-06T22:04:32Z</dc:date>
    </item>
  </channel>
</rss>

