<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS Failing Local User in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-failing-local-user/m-p/4496606#M570793</link>
    <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;We've Cisco ASA firewalls being authenticated and authorized by the Cisco ACS (5.8 Patch 10) for the TACACS users. We've Local/Internal users to ACS configured and I'm noticing an issue when the Internal user is unable to authenticate using the secondary ACS. Both the ACS is in cluster and this is specific to a user.&lt;/P&gt;&lt;P&gt;Other Local users and AD users are able to authenticate with the firewall successfully. This is working perfectly working when authenticating with the primary ACS using the same username/password. I've tested this behavior with the test aaa-server command and I enter the correct username/password.&lt;/P&gt;&lt;P&gt;Below debug logs for that specific user from the firewall when connecting with the secondary ACS.&lt;/P&gt;&lt;P&gt;Please assist?&lt;/P&gt;&lt;P&gt;INFO: Attempting Authentication test to IP address (10.0.0.10) (timeout: 10 seconds)&lt;BR /&gt;mk_pkt - type: 0x1, session_id: 2147483655&lt;BR /&gt;user: username&lt;BR /&gt;Tacacs packet sent&lt;BR /&gt;Sending TACACS Start message. Session id: 2147483655, seq no:1&lt;BR /&gt;Received TACACS packet. Session id:379906433 seq no:2&lt;BR /&gt;tacp_procpkt_authen: GETPASS&lt;BR /&gt;mk_pkt - type: 0x1, session_id: 2147483655&lt;BR /&gt;mkpkt_continue - response: ***&lt;BR /&gt;Tacacs packet sent&lt;BR /&gt;Sending TACACS Continue message. Session id: 2147483655, seq no:3&lt;BR /&gt;Received TACACS packet. Session id:379906433 seq no:4&lt;BR /&gt;&lt;STRONG&gt;tacp_procpkt_authen: FAIL&lt;/STRONG&gt;&lt;BR /&gt;TACACS Session finished. Session id: 2147483655, seq no: 3&lt;/P&gt;&lt;P&gt;++++++&lt;/P&gt;&lt;P&gt;INFO: Attempting Authentication test to IP address (10.0.0.10) (timeout: 10 seconds)&lt;BR /&gt;&lt;STRONG&gt;ERROR: Authentication Rejected: Unspecified&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Nov 2021 15:15:37 GMT</pubDate>
    <dc:creator>Srinivasan Nagarajan</dc:creator>
    <dc:date>2021-11-02T15:15:37Z</dc:date>
    <item>
      <title>ACS Failing Local User</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-failing-local-user/m-p/4496606#M570793</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;We've Cisco ASA firewalls being authenticated and authorized by the Cisco ACS (5.8 Patch 10) for the TACACS users. We've Local/Internal users to ACS configured and I'm noticing an issue when the Internal user is unable to authenticate using the secondary ACS. Both the ACS is in cluster and this is specific to a user.&lt;/P&gt;&lt;P&gt;Other Local users and AD users are able to authenticate with the firewall successfully. This is working perfectly working when authenticating with the primary ACS using the same username/password. I've tested this behavior with the test aaa-server command and I enter the correct username/password.&lt;/P&gt;&lt;P&gt;Below debug logs for that specific user from the firewall when connecting with the secondary ACS.&lt;/P&gt;&lt;P&gt;Please assist?&lt;/P&gt;&lt;P&gt;INFO: Attempting Authentication test to IP address (10.0.0.10) (timeout: 10 seconds)&lt;BR /&gt;mk_pkt - type: 0x1, session_id: 2147483655&lt;BR /&gt;user: username&lt;BR /&gt;Tacacs packet sent&lt;BR /&gt;Sending TACACS Start message. Session id: 2147483655, seq no:1&lt;BR /&gt;Received TACACS packet. Session id:379906433 seq no:2&lt;BR /&gt;tacp_procpkt_authen: GETPASS&lt;BR /&gt;mk_pkt - type: 0x1, session_id: 2147483655&lt;BR /&gt;mkpkt_continue - response: ***&lt;BR /&gt;Tacacs packet sent&lt;BR /&gt;Sending TACACS Continue message. Session id: 2147483655, seq no:3&lt;BR /&gt;Received TACACS packet. Session id:379906433 seq no:4&lt;BR /&gt;&lt;STRONG&gt;tacp_procpkt_authen: FAIL&lt;/STRONG&gt;&lt;BR /&gt;TACACS Session finished. Session id: 2147483655, seq no: 3&lt;/P&gt;&lt;P&gt;++++++&lt;/P&gt;&lt;P&gt;INFO: Attempting Authentication test to IP address (10.0.0.10) (timeout: 10 seconds)&lt;BR /&gt;&lt;STRONG&gt;ERROR: Authentication Rejected: Unspecified&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 15:15:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-failing-local-user/m-p/4496606#M570793</guid>
      <dc:creator>Srinivasan Nagarajan</dc:creator>
      <dc:date>2021-11-02T15:15:37Z</dc:date>
    </item>
    <item>
      <title>Re: ACS Failing Local User</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-failing-local-user/m-p/4496619#M570794</link>
      <description>&lt;PRE&gt; this is specific to a user.&lt;/PRE&gt;
&lt;P&gt;if this is specific to the only 1 user, i would suggest to delete the user and create back, make sure ACS synched 100%&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 15:17:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-failing-local-user/m-p/4496619#M570794</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-11-02T15:17:13Z</dc:date>
    </item>
  </channel>
</rss>

