<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE 2.6.0.156 Patch 7, Error: 13078 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4143326#M562587</link>
    <description>&lt;P&gt;I have been tasked to manually move all devices using TACACS+ authentication on an ACS 5.3.0.40 to ISE 2.6 (Patch 7).&amp;nbsp; I have moved a majority of our switches and routers to ISE successfully and I am currently attempting to move two Nexus 5548 switches.&amp;nbsp; When I change the config on the Nexus 5548 to add the new TACACS server host (ISE) and remove the old ACS hosts, an error pops up in the TACACS+ logs on ISE:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;13078 Invalid TACACS+ authorization request packet - possibly malformed packet&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The following is the old config on the 5548:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tacacs-server host &amp;lt;ip of ACS host 1&amp;gt; key 7 "shared secret"&lt;BR /&gt;tacacs-server host &amp;lt;ip of ACS host 2&amp;gt; key 7 "shared secret"&lt;BR /&gt;aaa group server tacacs+ ACS-SERVERS&lt;BR /&gt;&amp;nbsp; server&amp;nbsp;&amp;lt;ip of ACS host 1&amp;gt;&lt;BR /&gt;&amp;nbsp; server&amp;nbsp;&amp;lt;ip of ACS host 2&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The following is the new config I inputted:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tacacs-server host &amp;lt;ip of ACS host 3&amp;gt; key 7 "shared secret"&lt;BR /&gt;aaa group server tacacs+ ACS-SERVERS&lt;BR /&gt;&amp;nbsp; server&amp;nbsp;&amp;lt;ip of ACS host 3&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the aaa section remained untouched:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa authentication login default group&amp;nbsp;ACS-SERVERS local&lt;BR /&gt;aaa authentication login console group&amp;nbsp;ACS-SERVERS local&lt;BR /&gt;aaa authorization config-commands default group&amp;nbsp;ACS-SERVERS local&lt;BR /&gt;aaa authorization commands default group&amp;nbsp;ACS-SERVERS local&lt;BR /&gt;aaa accounting default group&amp;nbsp;ACS-SERVERS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is something new to me and I feel lucky that I was able to move the other switches and routers with little issues but I am stumped with these devices.&amp;nbsp; Could there be a bug on the current version of ISE that we have installed or do I have something misconfigured somewhere else?&lt;/P&gt;</description>
    <pubDate>Sat, 29 Aug 2020 00:16:06 GMT</pubDate>
    <dc:creator>GlennF</dc:creator>
    <dc:date>2020-08-29T00:16:06Z</dc:date>
    <item>
      <title>ISE 2.6.0.156 Patch 7, Error: 13078</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4143326#M562587</link>
      <description>&lt;P&gt;I have been tasked to manually move all devices using TACACS+ authentication on an ACS 5.3.0.40 to ISE 2.6 (Patch 7).&amp;nbsp; I have moved a majority of our switches and routers to ISE successfully and I am currently attempting to move two Nexus 5548 switches.&amp;nbsp; When I change the config on the Nexus 5548 to add the new TACACS server host (ISE) and remove the old ACS hosts, an error pops up in the TACACS+ logs on ISE:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;13078 Invalid TACACS+ authorization request packet - possibly malformed packet&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The following is the old config on the 5548:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tacacs-server host &amp;lt;ip of ACS host 1&amp;gt; key 7 "shared secret"&lt;BR /&gt;tacacs-server host &amp;lt;ip of ACS host 2&amp;gt; key 7 "shared secret"&lt;BR /&gt;aaa group server tacacs+ ACS-SERVERS&lt;BR /&gt;&amp;nbsp; server&amp;nbsp;&amp;lt;ip of ACS host 1&amp;gt;&lt;BR /&gt;&amp;nbsp; server&amp;nbsp;&amp;lt;ip of ACS host 2&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The following is the new config I inputted:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tacacs-server host &amp;lt;ip of ACS host 3&amp;gt; key 7 "shared secret"&lt;BR /&gt;aaa group server tacacs+ ACS-SERVERS&lt;BR /&gt;&amp;nbsp; server&amp;nbsp;&amp;lt;ip of ACS host 3&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And the aaa section remained untouched:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa authentication login default group&amp;nbsp;ACS-SERVERS local&lt;BR /&gt;aaa authentication login console group&amp;nbsp;ACS-SERVERS local&lt;BR /&gt;aaa authorization config-commands default group&amp;nbsp;ACS-SERVERS local&lt;BR /&gt;aaa authorization commands default group&amp;nbsp;ACS-SERVERS local&lt;BR /&gt;aaa accounting default group&amp;nbsp;ACS-SERVERS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is something new to me and I feel lucky that I was able to move the other switches and routers with little issues but I am stumped with these devices.&amp;nbsp; Could there be a bug on the current version of ISE that we have installed or do I have something misconfigured somewhere else?&lt;/P&gt;</description>
      <pubDate>Sat, 29 Aug 2020 00:16:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4143326#M562587</guid>
      <dc:creator>GlennF</dc:creator>
      <dc:date>2020-08-29T00:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6.0.156 Patch 7, Error: 13078</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4143516#M562589</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1093648"&gt;@GlennF&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;did you take a look at&amp;nbsp;&lt;STRONG&gt;Nexus 5548&lt;/STRONG&gt;&amp;nbsp;logs? For example:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;debug tacacs all&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Aug 2020 01:30:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4143516#M562589</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2020-08-30T01:30:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6.0.156 Patch 7, Error: 13078</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4143695#M562598</link>
      <description>&lt;P&gt;Have a look at the Nexus Platform section of the &lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-device-administration-prescriptive-deployment-guide/ta-p/3738365#toc-hId-1977002717" target="_blank" rel="noopener"&gt;Cisco ISE Device Administration Prescriptive Deployment Guide&lt;/A&gt; and compare it to your Nexus and ISE configuration. You may be missing the following option or some other configuration.&lt;/P&gt;
&lt;PRE&gt;aaa authentication login ascii-authentication&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2020 00:11:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4143695#M562598</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-08-31T00:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6.0.156 Patch 7, Error: 13078</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4143722#M562599</link>
      <description>&lt;P&gt;Check if you have configured tacacs global shared secret key using below command:&lt;/P&gt;
&lt;P&gt;tacacs-server key 7 "xxxxxx"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If it is there then remove it and test again.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2020 03:37:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4143722#M562599</guid>
      <dc:creator>poongarg</dc:creator>
      <dc:date>2020-08-31T03:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6.0.156 Patch 7, Error: 13078</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4144716#M562618</link>
      <description>&lt;P&gt;Thank you for your advice.&amp;nbsp; The following command is what we have inputted for the ACS servers:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;tacacs-server host &amp;lt;ip of ACS host 1&amp;gt; key 7 "shared secret"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;tacacs-server host &amp;lt;ip of ACS host 2&amp;gt; key 7 "shared secret"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;aaa group server tacacs+ ACS-SERVERS&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; server&amp;nbsp;&amp;lt;ip of ACS host 1&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; server&amp;nbsp;&amp;lt;ip of ACS host 2&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When I input the new ISE server (and removed the old ACS servers) along with adding it to the aaa TACACS+ group server, it did not&amp;nbsp; work:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;tacacs-server host &amp;lt;ip of ACS host 3&amp;gt; key 7 "shared secret"&lt;BR /&gt;aaa group server tacacs+ ACS-SERVERS&lt;BR /&gt;&amp;nbsp; server&amp;nbsp;&amp;lt;ip of ACS host 3&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 20:54:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4144716#M562618</guid>
      <dc:creator>GlennF</dc:creator>
      <dc:date>2020-09-01T20:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6.0.156 Patch 7, Error: 13078</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4144717#M562619</link>
      <description>&lt;P&gt;Thank you for your advice.&amp;nbsp; I inputted your suggestion in the appropriate section and it still did not work.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 20:56:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4144717#M562619</guid>
      <dc:creator>GlennF</dc:creator>
      <dc:date>2020-09-01T20:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6.0.156 Patch 7, Error: 13078</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4144719#M562620</link>
      <description>&lt;P&gt;Thank you for your advice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran the debug as you suggested when it was pointing to the new ISE host server and took capture of the output.&amp;nbsp; I then did the same when it was pointing to the old ACS servers.&amp;nbsp; I compared the two and there are some differences but not sure what to look for that would be causing the issue.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 21:03:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4144719#M562620</guid>
      <dc:creator>GlennF</dc:creator>
      <dc:date>2020-09-01T21:03:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6.0.156 Patch 7, Error: 13078</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4144795#M562623</link>
      <description>&lt;P&gt;Just to be clear, when you use the 'key &lt;STRONG&gt;7&lt;/STRONG&gt;' option for configuring the shared secret, the switch is expecting the encrypted text for the shared secret. If you are inputting the clear-text shared secret (i.e. 'cisco123) using the 'key 7' option, this will not work.&lt;/P&gt;
&lt;P&gt;If you have not already done so, I would suggest removing the tacacs-server configuration and re-configuring it using the following command syntax.&lt;/P&gt;
&lt;PRE&gt;tacacs-server host &amp;lt;ip of ISE&amp;gt; key &lt;STRONG&gt;0&lt;/STRONG&gt; &amp;lt;clear-text secret&amp;gt;&lt;/PRE&gt;
&lt;P&gt;If that still does not solve your issue, I would suggest opening a TAC case to gather debugs and information necessary to investigate further.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 23:18:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4144795#M562623</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2020-09-01T23:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6.0.156 Patch 7, Error: 13078</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4145491#M562671</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;could you please share the debug output?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2020 02:43:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4145491#M562671</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2020-09-03T02:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6.0.156 Patch 7, Error: 13078</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4183191#M563791</link>
      <description>&lt;P&gt;Hi Glen, did you find your luck? I am facing the same issue with Nexus 9K switches with ISE 2.7, tried all the suggestions provided in this group. ISE logs " 13078 Invalid TACACS+ authorization request packet - possibly malformed packet " error.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2020 05:15:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4183191#M563791</guid>
      <dc:creator>harikish21</dc:creator>
      <dc:date>2020-11-13T05:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6.0.156 Patch 7, Error: 13078</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4183206#M563792</link>
      <description>&lt;P&gt;I was able to resolve this issue with the help of TAC, it was a mismatch secret. The error message in ISE was misleading.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;May be a different issue for you, I pushed the config onto Nexus via DCNM. DCNM expects encrypted key to enter the config, which i copied from a catalyst switch. Looks like the type 7 encryption on Nexus is different than Catalyst switches, when i replaced the key with an encrypted key by Nexus, it worked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FYI, i have not added tacacs key global command and also tacacs source interface global command. All commands were specific to either group or tacacs-server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good luck with your problem.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2020 06:52:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-0-156-patch-7-error-13078/m-p/4183206#M563792</guid>
      <dc:creator>harikish21</dc:creator>
      <dc:date>2020-11-13T06:52:48Z</dc:date>
    </item>
  </channel>
</rss>

