<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problems with AAA Authorization on console in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/problems-with-aaa-authorization-on-console/m-p/4183422#M563805</link>
    <description>&lt;P&gt;When you say "&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt; console is cut-off. &lt;/FONT&gt;&lt;/FONT&gt;" is that mean you conjfiguring this config using Console ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;after you add that config, what username and password you using to Loging, first ACACS_GROUP if that fail Local&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;aaa authentication login CON group tacacs+&lt;FONT color="#FF0000"&gt; local &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;here is soem diag tips :&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security-vpn/terminal-access-controller-access-control-system-tacacs-/10384-security.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security-vpn/terminal-access-controller-access-control-system-tacacs-/10384-security.html&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Nov 2020 13:32:56 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2020-11-13T13:32:56Z</dc:date>
    <item>
      <title>Problems with AAA Authorization on console</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-aaa-authorization-on-console/m-p/4183389#M563803</link>
      <description>&lt;P&gt;I have read a number of posts and tested a number of them. Due to Cisco deprecating the legacy tacacs-server host command&lt;/P&gt;&lt;P&gt;I have come up with a new config. However, when I add the line in &lt;FONT color="#FF0000"&gt;red &lt;FONT color="#000000"&gt;access via the console is cut-off.&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt;This is on a 9200L switch running 16.12.4&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;aaa new-model&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;aaa group server tacacs+ TACACS_GROUP&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;server name TACACS_SERVER_1&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;ip tacacs source-interface Vlan3&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;aaa authentication login default group TACACS_GROUP local&lt;/DIV&gt;&lt;DIV&gt;aaa authentication login CON group tacacs+ line&lt;/DIV&gt;&lt;DIV&gt;aaa authentication enable default group TACACS_GROUP enable&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;FONT color="#FF0000"&gt;&lt;EM&gt;aaa authorization console&lt;/EM&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;DIV&gt;aaa authorization exec default group TACACS_GROUP if-authenticated&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;P&gt;&lt;SPAN&gt;aaa&amp;nbsp;authorization commands 1 default group TACACS_GROUP local&amp;nbsp;&lt;I&gt;&lt;STRONG&gt;if-authenticated&lt;/STRONG&gt;&lt;/I&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;P&gt;&lt;SPAN&gt;aaa&amp;nbsp;authorization commands 15 default group TACACS_GROUP local&amp;nbsp;&lt;STRONG&gt;&lt;I&gt;if authenticated&lt;/I&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;aaa accounting exec default start-stop group TACACS_GROUP&lt;/DIV&gt;&lt;DIV&gt;aaa accounting commands 1 default start-stop group TACACS_GROUP&lt;/DIV&gt;&lt;DIV&gt;aaa accounting commands 15 default start-stop group TACACS_GROUP&lt;/DIV&gt;aaa accounting connection default start-stop group TACACS_GROUP&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;aaa session-id common&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;!&lt;/DIV&gt;&lt;DIV&gt;tacacs server TACACS_SERVER_1&lt;DIV&gt;&amp;nbsp;address ipv4 x.x.x.x&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;key 7 ****************************&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;timeout 2&lt;/DIV&gt;&amp;nbsp;single-connection&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;line con 0&lt;DIV&gt;&amp;nbsp;exec-timeout 15 0&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;password 7 **************************&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;authorization exec CON&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;login authentication CON&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;transport output none&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;escape-character 3&lt;/DIV&gt;&amp;nbsp;stopbits 1&lt;/DIV&gt;</description>
      <pubDate>Fri, 13 Nov 2020 12:24:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-aaa-authorization-on-console/m-p/4183389#M563803</guid>
      <dc:creator>russell.sage</dc:creator>
      <dc:date>2020-11-13T12:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with AAA Authorization on console</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-aaa-authorization-on-console/m-p/4183422#M563805</link>
      <description>&lt;P&gt;When you say "&lt;FONT color="#FF0000"&gt;&lt;FONT color="#000000"&gt; console is cut-off. &lt;/FONT&gt;&lt;/FONT&gt;" is that mean you conjfiguring this config using Console ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;after you add that config, what username and password you using to Loging, first ACACS_GROUP if that fail Local&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;aaa authentication login CON group tacacs+&lt;FONT color="#FF0000"&gt; local &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;here is soem diag tips :&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security-vpn/terminal-access-controller-access-control-system-tacacs-/10384-security.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security-vpn/terminal-access-controller-access-control-system-tacacs-/10384-security.html&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2020 13:32:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-aaa-authorization-on-console/m-p/4183422#M563805</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-11-13T13:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with AAA Authorization on console</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-aaa-authorization-on-console/m-p/4183427#M563806</link>
      <description>&lt;P&gt;Yes I mean I am testing from the console port on the switch and when I add the authorization config in red any further commands fail authorization as the switch doesn't have connectivity to the TACACs server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Historically we haven't used a username and password for console access just a password under the line con 0 configuration.&lt;/P&gt;&lt;P&gt;I have added a username and password and will try adding the local word to the CON profile&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2020 13:42:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-aaa-authorization-on-console/m-p/4183427#M563806</guid>
      <dc:creator>russell.sage</dc:creator>
      <dc:date>2020-11-13T13:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with AAA Authorization on console</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-aaa-authorization-on-console/m-p/4183448#M563807</link>
      <description>&lt;P&gt;Good you processing, let us know what was the outcome after changing.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2020 14:14:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-aaa-authorization-on-console/m-p/4183448#M563807</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-11-13T14:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with AAA Authorization on console</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-aaa-authorization-on-console/m-p/4183898#M563841</link>
      <description>&lt;P&gt;I think that is expected in your case as you seem to have applied the wrong authorization method list to the console line. Based on the configs you shared, you used the default method list for authorization exec, so you should use that method list on the console line. Also, I would add the &lt;STRONG&gt;if-authenticated&lt;/STRONG&gt; keyword to the authorization exec line to allow the already authenticated users to interact with the device in case the TACACS server is not reachable.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;line con 0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;no authorization exec CON&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;authorization exec default&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 14 Nov 2020 17:29:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-aaa-authorization-on-console/m-p/4183898#M563841</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2020-11-14T17:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with AAA Authorization on console</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-aaa-authorization-on-console/m-p/4184277#M563849</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;I tried what you suggested but as soon as I added the aaa authorization console I am locked out&lt;BR /&gt;</description>
      <pubDate>Mon, 16 Nov 2020 07:48:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-aaa-authorization-on-console/m-p/4184277#M563849</guid>
      <dc:creator>russell.sage</dc:creator>
      <dc:date>2020-11-16T07:48:55Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with AAA Authorization on console</title>
      <link>https://community.cisco.com/t5/network-access-control/problems-with-aaa-authorization-on-console/m-p/4188261#M563963</link>
      <description>&lt;P&gt;Do you mean you could not issue any commands post applying those commands? if so, you would need to log out and log back into the device. Try that please and let us know if it works.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 18:04:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problems-with-aaa-authorization-on-console/m-p/4188261#M563963</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2020-11-24T18:04:43Z</dc:date>
    </item>
  </channel>
</rss>

