<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE 3.0 - TACACS+ is not working, Tacacs logs: No data found in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-tacacs-is-not-working-tacacs-logs-no-data-found/m-p/4518273#M571641</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1049013"&gt;@pozodionisio62774&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;please try first to install the latest Patch: &lt;A href="https://software.cisco.com/download/home/283801620/type/283802505/release/3.0.0" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;3.0 P4&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;and if the issue continues, then open a &lt;STRONG&gt;TAC Case&lt;/STRONG&gt; (as&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/26555"&gt;@thomas&lt;/a&gt;&amp;nbsp;said).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
    <pubDate>Tue, 14 Dec 2021 00:46:05 GMT</pubDate>
    <dc:creator>Marcelo Morais</dc:creator>
    <dc:date>2021-12-14T00:46:05Z</dc:date>
    <item>
      <title>Cisco ISE 3.0 - TACACS+ is not working, Tacacs logs: No data found</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-tacacs-is-not-working-tacacs-logs-no-data-found/m-p/4510465#M571301</link>
      <description>&lt;P&gt;Hello everyone;&lt;/P&gt;&lt;P&gt;I am doing a deployment to create a new tacacs server through cisco ISE (authenticating to an AD).&lt;/P&gt;&lt;P&gt;The thing is that I am not receiving any TACACS log on the Cisco ISE, and on the firewall, I can observe that the requests from the test SW are arriving to my Cisco ISE.&lt;/P&gt;&lt;P&gt;On the other hand, on the AD I can't see any request either.&lt;/P&gt;&lt;P&gt;The thing is that in the switch I get the message "access denied".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I go to show you guys some additional information:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SW-TEST#test aaa group tacacs+ MYUSER PASSWORD legacy&lt;BR /&gt;Attempting authentication test to server-group tacacs+ using tacacs+&lt;BR /&gt;No authoritative response from any server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Cisco Switch configuration:&lt;/P&gt;&lt;P&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa group server tacacs+ GROUP1&lt;BR /&gt;server name ISE01&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default group GROUP1 local&lt;BR /&gt;aaa authorization config-commands&lt;BR /&gt;aaa authorization exec default group GROUP1 local&lt;BR /&gt;aaa authorization commands 0 default group GROUP1 local&lt;BR /&gt;aaa authorization commands 7 default group GROUP1 local&lt;BR /&gt;aaa authorization commands 15 default group GROUP1 local&lt;BR /&gt;aaa accounting system default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tacacs server ISE01&lt;BR /&gt;address ipv4 10.239.254.243 (this is the IP of Cisco ISE)&lt;BR /&gt;key 7 03215F1B145D711E1C&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PD: Debubbing additional info:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Log Buffer (4096 bytes):&lt;BR /&gt;0: state was SYNSENT -&amp;gt; ESTAB [17344 -&amp;gt; 10.239.254.243(49)]&lt;BR /&gt;.Nov 30 11:43:35.151: TCP0: tcb 76AD1CC connection to 10.239.254.243:49, received MSS 1460, MSS is 536&lt;BR /&gt;.Nov 30 11:43:35.151: TCP0: tcb 76AD1CC connection to 10.239.254.243:49, received MSS 1460, MSS is 536&lt;BR /&gt;.Nov 30 11:43:35.151: TPLUS(0000087D)/0/NB_WAIT: socket event 2&lt;BR /&gt;.Nov 30 11:43:35.151: TPLUS(0000087D)/0/NB_WAIT: wrote entire 47 bytes request&lt;BR /&gt;.Nov 30 11:43:35.159: TPLUS(0000087D)/0/READ: socket event 1&lt;BR /&gt;.Nov 30 11:43:35.159: TPLUS(0000087D)/0/READ: Would block while reading&lt;BR /&gt;.Nov 30 11:43:35.159: TCP0: FIN processed&lt;BR /&gt;.Nov 30 11:43:35.159: TCP0: state was ESTAB -&amp;gt; CLOSEWAIT [17344 -&amp;gt; 10.239.254.243(49)]&lt;BR /&gt;.Nov 30 11:43:35.159: TCP0: bad seg from 10.239.254.243 -- ACK sent to validate RST: port 17344 seq 1532879747 ack 0 rcvnxt 1532879748 rcvwnd 4128 len 0&lt;BR /&gt;.Nov 30 11:43:35.159: TCP0: RST received, ACK sent to validate RST&lt;BR /&gt;.Nov 30 11:43:35.159: TPLUS(0000087D)/0/READ: socket event 1&lt;BR /&gt;.Nov 30 11:43:35.159: TPLUS(0000087D)/0/READ: read 0 bytes&lt;BR /&gt;.Nov 30 11:43:35.159: TCP0: RST received, Closing connection&lt;BR /&gt;.Nov 30 11:43:35.159: TCP0: state was CLOSEWAIT -&amp;gt; CLOSED [17344 -&amp;gt; 10.239.254.243(49)]&lt;BR /&gt;.Nov 30 11:43:35.159: TPLUS(0000087D)/0/READ: socket event 1&lt;BR /&gt;.Nov 30 11:43:35.159: TPLUS(0000087D)/0/READ: errno 32&lt;BR /&gt;.Nov 30 11:43:35.159: TPLUS(0000087D)/0/739F9B8: Processing the reply packet&lt;BR /&gt;.Nov 30 11:43:35.159: TPA: Released port 17344 in Transport Port Agent for TCP IP type 1 delay 240000&lt;BR /&gt;.Nov 30 11:43:35.159: TCB 0x76AD1CC destroyed&lt;BR /&gt;.Nov 30 11:43:49.922: AAA/AUTHOR: auth_need : user= 'edpr_tr' ruser= 'EUPTNSWERMESINDE194'rem_addr= '172.17.86.253' priv= 15 list= '' AUTHOR-TYPE= 'command'&lt;BR /&gt;.Nov 30 11:43:49.922: AAA: parse name=tty4 idb type=-1 tty=-1&lt;BR /&gt;.Nov 30 11:43:49.922: AAA: name=tty4 flags=0x11 type=5 shelf=0 slot=0 adapter=0 port=4 channel=0&lt;BR /&gt;.Nov 30 11:43:49.922: AAA/MEMORY: create_user (0x74F81B0) user='edpr_tr' ruser='EUPTNSWERMESINDE194' ds0=0 port='tty4' rem_addr='172.17.86.253' authen_type=ASCII service=NONE priv=15 initial_task_id='0', vrf= (id=0)&lt;BR /&gt;.Nov 30 11:43:49.922: tty4 AAA/AUTHOR/CMD (621972277): Port='tty4' list='' service=CMD&lt;BR /&gt;.Nov 30 11:43:49.922: AAA/AUTHOR/CMD: tty4 (621972277) user='edpr_tr'&lt;BR /&gt;.Nov 30 11:43:49.922: tty4 AAA/AUTHOR/CMD (621972277): send AV service=shell&lt;BR /&gt;.Nov 30 11:43:49.922: tty4 AAA/AUTHOR/CMD (621972277): send AV cmd=show&lt;BR /&gt;.Nov 30 11:43:49.922: tty4 AAA/AUTHOR/CMD (621972277): send AV cmd-arg=logging&lt;BR /&gt;.Nov 30 11:43:49.922: tty4 AAA/AUTHOR/CMD (621972277): send AV cmd-arg=&amp;lt;cr&amp;gt;&lt;BR /&gt;.Nov 30 11:43:49.931: tty4 AAA/AUTHOR/CMD(621972277): found list "default"&lt;BR /&gt;.Nov 30 11:43:49.931: tty4 AAA/AUTHOR/CMD (621972277): Method=GROUP1 (tacacs+)&lt;BR /&gt;.Nov 30 11:43:49.931: AAA/AUTHOR/TAC+: (621972277): user=edpr_tr&lt;BR /&gt;.Nov 30 11:43:49.931: AAA/AUTHOR/TAC+: (621972277): send AV service=shell&lt;BR /&gt;.Nov 30 11:43:49.931: AAA/AUTHOR/TAC+: (621972277): send AV cmd=show&lt;BR /&gt;.Nov 30 11:43:49.931: AAA/AUTHOR/TAC+: (621972277): send AV cmd-arg=logging&lt;BR /&gt;.Nov 30 11:43:49.931: AAA/AUTHOR/TAC+: (621972277): send AV cmd-arg=&amp;lt;cr&amp;gt;&lt;BR /&gt;.Nov 30 11:43:49.931: TAC+: Using default tacacs server-group "GROUP1" list.&lt;BR /&gt;.Nov 30 11:43:49.931: TAC+: Opening TCP/IP to 10.239.254.243/49 timeout=5&lt;BR /&gt;.Nov 30 11:43:49.931: TCB07697018 created&lt;BR /&gt;.Nov 30 11:43:49.931: TCB07697018 setting property TCP_GIVEUP (12) 762FBA0&lt;BR /&gt;.Nov 30 11:43:49.931: TCP: Random local port generated 25269, network 1&lt;BR /&gt;.Nov 30 11:43:49.931: TPA: Reserved port 25269 in Transport Port Agent for TCP IP type 1&lt;BR /&gt;.Nov 30 11:43:49.931: TCP: sending SYN, seq 19705197, ack 0&lt;BR /&gt;.Nov 30 11:43:49.931: TCP0: Connection to 10.239.254.243:49, advertising MSS 536&lt;BR /&gt;.Nov 30 11:43:49.931: TCP0: state was CLOSED -&amp;gt; SYNSENT [25269 -&amp;gt; 10.239.254.243(49)]&lt;BR /&gt;.Nov 30 11:43:49.939: TCP0: state was SYNSENT -&amp;gt; ESTAB [25269 -&amp;gt; 10.239.254.243(49)]&lt;BR /&gt;.Nov 30 11:43:49.939: TCP0: tcb 7697018 connection to 10.239.254.243:49, received MSS 1460, MSS is 536&lt;BR /&gt;.Nov 30 11:43:49.939: TCP0: tcb 7697018 connection to 10.239.254.243:49, received MSS 1460, MSS is 536&lt;BR /&gt;.Nov 30 11:43:49.939: TCB07697018 connected to 10.239.254.243.49&lt;BR /&gt;.Nov 30 11:43:49.939: TAC+: Opened TCP/IP handle 0x7697018 to 10.239.254.243/49&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TCPDUMP in Cisco ISE in attached files.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could someone help me, please?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 13:37:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-tacacs-is-not-working-tacacs-logs-no-data-found/m-p/4510465#M571301</guid>
      <dc:creator>pozodionisio62774</dc:creator>
      <dc:date>2021-11-30T13:37:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.0 - TACACS+ is not working, Tacacs logs: No data found</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-tacacs-is-not-working-tacacs-logs-no-data-found/m-p/4510489#M571302</link>
      <description>&lt;P&gt;Which Patch version are you running with on ISE 3.0 ?&lt;/P&gt;&lt;P&gt;Hope you have enabled 'Device Admin Service' under Administration &amp;gt; System &amp;gt; Deployment &amp;gt; PSN (or node )&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you enabled it try to disable and enable and then test.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 12:18:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-tacacs-is-not-working-tacacs-logs-no-data-found/m-p/4510489#M571302</guid>
      <dc:creator>PSM</dc:creator>
      <dc:date>2021-11-30T12:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.0 - TACACS+ is not working, Tacacs logs: No data found</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-tacacs-is-not-working-tacacs-logs-no-data-found/m-p/4510491#M571303</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1049013"&gt;@pozodionisio62774&lt;/a&gt; have you enabled Device Adminstration on the PSN(s)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="11.PNG" style="width: 799px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/138242iFB543DC426044C0F/image-size/large?v=v2&amp;amp;px=999" role="button" title="11.PNG" alt="11.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 12:21:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-tacacs-is-not-working-tacacs-logs-no-data-found/m-p/4510491#M571303</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-11-30T12:21:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.0 - TACACS+ is not working, Tacacs logs: No data found</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-tacacs-is-not-working-tacacs-logs-no-data-found/m-p/4510498#M571305</link>
      <description>&lt;P&gt;Hi Rob;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I just enabled as you showed me in the screenshoot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But i am still having the problem&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 12:38:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-tacacs-is-not-working-tacacs-logs-no-data-found/m-p/4510498#M571305</guid>
      <dc:creator>pozodionisio62774</dc:creator>
      <dc:date>2021-11-30T12:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.0 - TACACS+ is not working, Tacacs logs: No data found</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-tacacs-is-not-working-tacacs-logs-no-data-found/m-p/4510499#M571306</link>
      <description>&lt;P&gt;The version is:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN class=""&gt;Standalone&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;SPAN class=""&gt;3.0.0.458&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Active&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Tue, 30 Nov 2021 12:39:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-tacacs-is-not-working-tacacs-logs-no-data-found/m-p/4510499#M571306</guid>
      <dc:creator>pozodionisio62774</dc:creator>
      <dc:date>2021-11-30T12:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.0 - TACACS+ is not working, Tacacs logs: No data found</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-tacacs-is-not-working-tacacs-logs-no-data-found/m-p/4518210#M571637</link>
      <description>&lt;P&gt;Call TAC.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 21:52:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-tacacs-is-not-working-tacacs-logs-no-data-found/m-p/4518210#M571637</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2021-12-13T21:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 3.0 - TACACS+ is not working, Tacacs logs: No data found</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-tacacs-is-not-working-tacacs-logs-no-data-found/m-p/4518273#M571641</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1049013"&gt;@pozodionisio62774&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;please try first to install the latest Patch: &lt;A href="https://software.cisco.com/download/home/283801620/type/283802505/release/3.0.0" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;3.0 P4&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;and if the issue continues, then open a &lt;STRONG&gt;TAC Case&lt;/STRONG&gt; (as&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/26555"&gt;@thomas&lt;/a&gt;&amp;nbsp;said).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 00:46:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-3-0-tacacs-is-not-working-tacacs-logs-no-data-found/m-p/4518273#M571641</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-12-14T00:46:05Z</dc:date>
    </item>
  </channel>
</rss>

