<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA Configuration on c9300 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-configuration-on-c9300/m-p/4045153#M558853</link>
    <description>&lt;P&gt;Yeah - I'm an ID10T.&amp;nbsp; I had it at one time but then pulled it out because adding it caused my local user login to no longer dump me into enable mode.&amp;nbsp; Re-entering it gave me access to the tacacs command structure, but as &lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/290824" target="_self"&gt;&lt;SPAN class=""&gt;scottsassin&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt; pointed out, that method is being depreciated.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Mar 2020 18:07:25 GMT</pubDate>
    <dc:creator>jlmickens</dc:creator>
    <dc:date>2020-03-12T18:07:25Z</dc:date>
    <item>
      <title>AAA Configuration on c9300</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-configuration-on-c9300/m-p/3300453#M546900</link>
      <description>&lt;P&gt;I have a stack of C9300 switches. I am trying to configure tacacs+ authentication. I read the documentation, and I'm getting no where .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please post an example of aaa configuration, using a group of tacacs servers.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:42:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-configuration-on-c9300/m-p/3300453#M546900</guid>
      <dc:creator>scottsassin</dc:creator>
      <dc:date>2020-02-21T18:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Configuration on c9300</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-configuration-on-c9300/m-p/3300564#M546902</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below a snippet of the config. Sorry for the order of copy paste, I'm through my iPad.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;aaa new-model&lt;/P&gt;
&lt;P&gt;aaa authentication login CON none&lt;/P&gt;
&lt;P&gt;aaa authentication login default local&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;line con 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;exec-timeout 0 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;login authentication CON&lt;/P&gt;
&lt;P&gt;&amp;nbsp;logging synchronous&lt;/P&gt;
&lt;P&gt;&amp;nbsp;authorization exec CON&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;tacacs server ise-1&lt;/P&gt;
&lt;P&gt;&amp;nbsp; address ipv4&amp;nbsp;10.10.10.10&lt;/P&gt;
&lt;P&gt;&amp;nbsp; key&amp;nbsp;Cisco123&lt;BR /&gt;!&lt;BR /&gt;aaa group server tacacs+ ISE&lt;/P&gt;
&lt;P&gt;&amp;nbsp; server name ise-1&lt;/P&gt;
&lt;P&gt;!&lt;BR /&gt;aaa authentication login VTY group ISE local&lt;/P&gt;
&lt;P&gt;aaa authentication enable default group ISE enable&lt;/P&gt;
&lt;P&gt;aaa authorization config-commands&lt;/P&gt;
&lt;P&gt;aaa authorization exec CON none&lt;BR /&gt;aaa authorization console&lt;BR /&gt;aaa authorization exec VTY group ISE local if-authenticated&lt;/P&gt;
&lt;P&gt;aaa authorization commands 1 VTY group ISE local if-authenticated&lt;/P&gt;
&lt;P&gt;aaa authorization commands 15 VTY group ISE local if-authenticated&lt;/P&gt;
&lt;P&gt;aaa accounting exec default start-stop group ISE&lt;/P&gt;
&lt;P&gt;aaa accounting commands 1 default start-stop group ISE&lt;/P&gt;
&lt;P&gt;aaa accounting commands 15 default start-stop group ISE&lt;BR /&gt;aaa accounting connection default start-stop group ISE&lt;BR /&gt;aaa accounting system default start-stop group ISE&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;BR /&gt;line vty 0 15&lt;/P&gt;
&lt;P&gt;login authentication VTY&lt;/P&gt;
&lt;P&gt;authorization commands 1 VTY&lt;/P&gt;
&lt;P&gt;authorization commands 15 VTY&lt;BR /&gt;authorization exec VTY&lt;/P&gt;
&lt;P&gt;accounting exec default&lt;BR /&gt;&amp;nbsp;accounting commands 1 default&lt;BR /&gt;&amp;nbsp;accounting commands 15 default&lt;BR /&gt;&amp;nbsp;accounting connection default&lt;BR /&gt;!&lt;BR /&gt;!&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2017 02:26:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-configuration-on-c9300/m-p/3300564#M546902</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2017-12-22T02:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Configuration on c9300</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-configuration-on-c9300/m-p/4044253#M558791</link>
      <description>&lt;P&gt;Sorry to raise an old thread, but I'm encountering this exact scenario.&amp;nbsp; I'm reading the documentation, which is giving me commands to use that do not exist.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-9/configuration_guide/sec/b_169_sec_9300_cg/configuring_tacacs_.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/16-9/configuration_guide/sec/b_169_sec_9300_cg/configuring_tacacs_.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the documentation:&lt;/P&gt;&lt;P&gt;SUMMARY STEPS&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;enable&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd CN_CmdName-2A8B56A4"&gt;configure&lt;/SPAN&gt; &lt;SPAN class="keyword kwd"&gt;terminal&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;tacacs server&lt;/SPAN&gt; server-name&amp;nbsp; &lt;EM&gt;&amp;lt;-- this has a space between tacacs and server, but the tacacs command is invalid under 16.9.4 on my C9300.&amp;nbsp; It defaults to "tacacs-server" if I use the tab to complete the command.&amp;nbsp; Is this just an error in the documentation?&amp;nbsp; The command structure under tacacs-server is completely different.&lt;/EM&gt; &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd CN_CmdName-2A8B56A4"&gt;address &lt;/SPAN&gt;{&lt;SPAN class="keyword kwd"&gt;ipv4 | ipv6&lt;/SPAN&gt;} ip address &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd CN_CmdName-2A8B56A4"&gt;exit &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;aaa new-model&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;aaa group server tacacs+&lt;/SPAN&gt; group-name &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;server&lt;/SPAN&gt; ip-address &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd CN_CmdName-2A8B56A4"&gt;end&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd CN_CmdName-2A8B56A4"&gt;show running-config&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd CN_CmdName-2A8B56A4"&gt;copy running-config startup-config&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN class="ph synph"&gt;Additionally, why would the server IP addresses need to be defined in two different places (both under tacacs server and aaa groups).&amp;nbsp; It also appears you can provide the server key under the aaa group server command structure.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="ph synph"&gt;I also found indications that the tacacs-server host command will be deprecated soon. It says you can use the server command instead of the tacacs-server host command, but the server command doesn't seem to exist either.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 14:35:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-configuration-on-c9300/m-p/4044253#M558791</guid>
      <dc:creator>jlmickens</dc:creator>
      <dc:date>2020-03-11T14:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Configuration on c9300</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-configuration-on-c9300/m-p/4044380#M558805</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;Do you have "aaa new-model" enabled?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 17:05:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-configuration-on-c9300/m-p/4044380#M558805</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-03-11T17:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Configuration on c9300</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-configuration-on-c9300/m-p/4044566#M558825</link>
      <description>&lt;P&gt;The command&amp;nbsp;&lt;STRONG&gt;&lt;SPAN class="keyword kwd"&gt;tacacs server&lt;/SPAN&gt;&amp;nbsp;server-name&amp;nbsp;&lt;/STRONG&gt;has been depreciated. The new command structure is:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa group server tacacs+ &amp;lt;Name&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;server x.x.x.x&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;server y.y.y.y&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;ip tacacs source-interface &amp;lt;Interface&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The servers are identified in the group, by the group name, and are referenced as such:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa authentication login default group &amp;lt;Name&amp;gt; local&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;aaa authentication enable default group &amp;lt;Name&amp;gt; enable&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;aaa authorization config-commands&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;aaa authorization exec default group &amp;lt;Name&amp;gt; local &lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;aaa authorization commands 15 default group &amp;lt;Name&amp;gt; if-authenticated &lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;aaa accounting exec default start-stop group tacacs+&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;aaa accounting commands 1 default stop-only group &amp;lt;Name&amp;gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;aaa accounting commands 15 default stop-only group tacacs+&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;It took me a long time to get the meaning of this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Mar 2020 21:37:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-configuration-on-c9300/m-p/4044566#M558825</guid>
      <dc:creator>scottsassin</dc:creator>
      <dc:date>2020-03-11T21:37:11Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Configuration on c9300</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-configuration-on-c9300/m-p/4045153#M558853</link>
      <description>&lt;P&gt;Yeah - I'm an ID10T.&amp;nbsp; I had it at one time but then pulled it out because adding it caused my local user login to no longer dump me into enable mode.&amp;nbsp; Re-entering it gave me access to the tacacs command structure, but as &lt;SPAN class="UserName lia-user-name lia-user-rank-Beginner lia-component-message-view-widget-author-username"&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/290824" target="_self"&gt;&lt;SPAN class=""&gt;scottsassin&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt; pointed out, that method is being depreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2020 18:07:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-configuration-on-c9300/m-p/4045153#M558853</guid>
      <dc:creator>jlmickens</dc:creator>
      <dc:date>2020-03-12T18:07:25Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Configuration on c9300</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-configuration-on-c9300/m-p/4045156#M558855</link>
      <description>&lt;P&gt;Is there any methodology to the sequence of entering these commands?&amp;nbsp; When I was playing with it (before your post) I managed to enter something that caused me to no longer be able to enter commands.&amp;nbsp; I wound up having to reload the switch from the console.&amp;nbsp; Is there a way to test the tacacs server connectivity before adding the "aaa authentication login default group" command?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2020 18:11:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-configuration-on-c9300/m-p/4045156#M558855</guid>
      <dc:creator>jlmickens</dc:creator>
      <dc:date>2020-03-12T18:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Configuration on c9300</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-configuration-on-c9300/m-p/4045181#M558856</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; I'm guessing here. If you lasted the commands from the console, unauthenticated, it makes sense you lost access, when the exec authorization command was issued, as you lost exec access, so all further commands were ignored. Connect via telnet/ssh with username/password, paste the commands and there should be no issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2020 18:59:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-configuration-on-c9300/m-p/4045181#M558856</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-03-12T18:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Configuration on c9300</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-configuration-on-c9300/m-p/4045213#M558858</link>
      <description>&lt;P&gt;I was ssh'd in with a username on the switch, but I may have been out of order with the commands.&amp;nbsp; I'd have to go back through my ssh logs to see exactly what I did. Thanks for confirming the order laid out will work without issue.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Mar 2020 20:00:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-configuration-on-c9300/m-p/4045213#M558858</guid>
      <dc:creator>jlmickens</dc:creator>
      <dc:date>2020-03-12T20:00:44Z</dc:date>
    </item>
    <item>
      <title>Re: AAA Configuration on c9300</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-configuration-on-c9300/m-p/4056315#M559315</link>
      <description>&lt;P&gt;The command order wasn't entirely without issues.&amp;nbsp; While logged in as a local user with priv 15, I proceeded to add the commands as stated.&amp;nbsp; Once the "aaa authorization commands 15 default group RAAS-ISE if-authenticated" command was entered, I could no longer enter any other commands because I was logged in as a local user and once you enter that it starts pushing everything to the tacacs server.&amp;nbsp; I had to log in with a tacacs account to complete the last three commands.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2" face="courier new,courier"&gt;CorpCore#conf t&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" face="courier new,courier"&gt;Enter configuration commands, one per line. End with CNTL/Z.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" face="courier new,courier"&gt;CorpCore(config)#aaa authentication login default group RAAS-ISE local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" face="courier new,courier"&gt;CorpCore(config)#aaa authentication enable default group RAAS-ISE enable&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" face="courier new,courier"&gt;CorpCore(config)#aaa authorization config-commands&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" face="courier new,courier"&gt;CorpCore(config)#aaa authorization exec default group RAAS-ISE local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" face="courier new,courier"&gt;CorpCore(config)#aaa authorization commands 15 default group RAAS-ISE if-authenticated&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" face="courier new,courier"&gt;CorpCore(config)#aaa accounting exec default start-stop group tacacs+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" face="courier new,courier"&gt;Command authorization failed.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2" face="courier new,courier"&gt;CorpCore(config)#aaa accounting commands 1 default stop-only group RAAS-ISE&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" face="courier new,courier"&gt;Command authorization failed.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2" face="courier new,courier"&gt;CorpCore(config)#aaa accounting commands 15 default stop-only group tacacs+&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" face="courier new,courier"&gt;Command authorization failed.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Mar 2020 21:39:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-configuration-on-c9300/m-p/4056315#M559315</guid>
      <dc:creator>jlmickens</dc:creator>
      <dc:date>2020-03-31T21:39:41Z</dc:date>
    </item>
  </channel>
</rss>

