<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco 5525 ASA TACACS Authentication Problem. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-5525-asa-tacacs-authentication-problem/m-p/2829198#M56695</link>
    <description>&lt;P&gt;Hi Experts,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Due to some suspected recent policy implementation/changes on&amp;nbsp;5525 ASA , same is not getting&amp;nbsp;autheticate on TACACs (ACS) However we are getting prompt for username/password.&lt;/P&gt;
&lt;P&gt;We also&amp;nbsp;have local username/password, through which we are able to logged into ASA but not able to execute any command , it's showing "command authorization failed". Like.&lt;/P&gt;
&lt;P&gt;Cisco-asa&amp;gt; en&lt;BR /&gt;Password: ***********&lt;BR /&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;Cisco-asa# conf t&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;Command authorization failed&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;Cisco-asa#&lt;/P&gt;
&lt;P&gt;Due to this issue, we are also not getting authenticate&amp;nbsp;on upper devices (above ASA).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Below is Configuration for ACS(TACACS) for reference (taken from old configuration backup)&lt;/P&gt;
&lt;P&gt;aaa-server ACS protocol tacacs+&lt;BR /&gt;&amp;nbsp;accounting-mode simultaneous&lt;BR /&gt;aaa-server ACS (Inside) host 10.50.10.100&lt;BR /&gt;&amp;nbsp;key Cisco@123&lt;BR /&gt;aaa-server ACS (Inside) host 10.50.10.101&lt;BR /&gt;&amp;nbsp;key Cisco@123&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication enable console ACS LOCAL&lt;BR /&gt;aaa authentication http console ACS LOCAL&lt;BR /&gt;aaa authentication ssh console ACS LOCAL&lt;BR /&gt;aaa authorization command ACS &lt;BR /&gt;aaa accounting enable console ACS&lt;BR /&gt;aaa accounting ssh console ACS&lt;BR /&gt;aaa accounting command ACS&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Requesting to&amp;nbsp;pls guide&amp;nbsp;for resolving the problem.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rgds&lt;/P&gt;
&lt;P&gt;***&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 06:14:14 GMT</pubDate>
    <dc:creator>netbeginner</dc:creator>
    <dc:date>2019-03-11T06:14:14Z</dc:date>
    <item>
      <title>Cisco 5525 ASA TACACS Authentication Problem.</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-5525-asa-tacacs-authentication-problem/m-p/2829198#M56695</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Due to some suspected recent policy implementation/changes on&amp;nbsp;5525 ASA , same is not getting&amp;nbsp;autheticate on TACACs (ACS) However we are getting prompt for username/password.&lt;/P&gt;
&lt;P&gt;We also&amp;nbsp;have local username/password, through which we are able to logged into ASA but not able to execute any command , it's showing "command authorization failed". Like.&lt;/P&gt;
&lt;P&gt;Cisco-asa&amp;gt; en&lt;BR /&gt;Password: ***********&lt;BR /&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;Cisco-asa# conf t&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;Command authorization failed&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;Cisco-asa#&lt;/P&gt;
&lt;P&gt;Due to this issue, we are also not getting authenticate&amp;nbsp;on upper devices (above ASA).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Below is Configuration for ACS(TACACS) for reference (taken from old configuration backup)&lt;/P&gt;
&lt;P&gt;aaa-server ACS protocol tacacs+&lt;BR /&gt;&amp;nbsp;accounting-mode simultaneous&lt;BR /&gt;aaa-server ACS (Inside) host 10.50.10.100&lt;BR /&gt;&amp;nbsp;key Cisco@123&lt;BR /&gt;aaa-server ACS (Inside) host 10.50.10.101&lt;BR /&gt;&amp;nbsp;key Cisco@123&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication enable console ACS LOCAL&lt;BR /&gt;aaa authentication http console ACS LOCAL&lt;BR /&gt;aaa authentication ssh console ACS LOCAL&lt;BR /&gt;aaa authorization command ACS &lt;BR /&gt;aaa accounting enable console ACS&lt;BR /&gt;aaa accounting ssh console ACS&lt;BR /&gt;aaa accounting command ACS&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Requesting to&amp;nbsp;pls guide&amp;nbsp;for resolving the problem.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rgds&lt;/P&gt;
&lt;P&gt;***&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:14:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-5525-asa-tacacs-authentication-problem/m-p/2829198#M56695</guid>
      <dc:creator>netbeginner</dc:creator>
      <dc:date>2019-03-11T06:14:14Z</dc:date>
    </item>
    <item>
      <title>I think you could just delete</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-5525-asa-tacacs-authentication-problem/m-p/2829199#M56699</link>
      <description>&lt;P&gt;I think you could just delete the Authorization command, in my experience if you are allowed to login then you want to be authorised automatically,authentication is usually enough.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2015 06:49:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-5525-asa-tacacs-authentication-problem/m-p/2829199#M56699</guid>
      <dc:creator>Richard Bradfield</dc:creator>
      <dc:date>2015-11-16T06:49:12Z</dc:date>
    </item>
  </channel>
</rss>

