<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: lin con 0 authorization failed in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/lin-con-0-authorization-failed/m-p/4925523#M584119</link>
    <description>&lt;P&gt;Sorry, that was missing in my post&lt;/P&gt;
&lt;P&gt;aaa authentication login default group tacacs+ local&lt;BR /&gt;aaa authentication login CONSOLE group tacacs+ local&lt;BR /&gt;aaa authentication enable default group tacacs+ enable&lt;BR /&gt;aaa authorization console&lt;BR /&gt;aaa authorization config-commands&lt;BR /&gt;aaa authorization exec default group tacacs+ local &lt;BR /&gt;aaa authorization exec CONSOLE group tacacs+ local &lt;BR /&gt;aaa authorization commands 1 default group tacacs+ local &lt;BR /&gt;aaa authorization commands 15 default group tacacs+ local&lt;/P&gt;</description>
    <pubDate>Tue, 19 Sep 2023 06:55:49 GMT</pubDate>
    <dc:creator>Conucci</dc:creator>
    <dc:date>2023-09-19T06:55:49Z</dc:date>
    <item>
      <title>lin con 0 authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/lin-con-0-authorization-failed/m-p/4925522#M584118</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I can't configure the line con 0 with the command&amp;nbsp;login authentication CONSOLE. I get the following error:&lt;/P&gt;
&lt;P&gt;sy-xxxx-ch-xxx-s-0xx(config-line)#login authentication CONSOLE &lt;BR /&gt;Command authorization failed.&lt;/P&gt;
&lt;P&gt;The tacacs is up and running because I'm already connected to the device with ssh over tacacs+ and I have done several commends like on the console 0 too:&lt;BR /&gt;***&lt;BR /&gt;line con 0&lt;BR /&gt;authorization exec CONSOLE&lt;BR /&gt;***&lt;BR /&gt;&lt;BR /&gt;What I'm doing wrong? Is it not possible to do this command on a running system?&amp;nbsp;&lt;BR /&gt;It's a new C9200CX&lt;BR /&gt;&lt;BR /&gt;Thank you for your advice&lt;BR /&gt;&lt;BR /&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Marco&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 06:55:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/lin-con-0-authorization-failed/m-p/4925522#M584118</guid>
      <dc:creator>Conucci</dc:creator>
      <dc:date>2023-09-19T06:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: lin con 0 authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/lin-con-0-authorization-failed/m-p/4925523#M584119</link>
      <description>&lt;P&gt;Sorry, that was missing in my post&lt;/P&gt;
&lt;P&gt;aaa authentication login default group tacacs+ local&lt;BR /&gt;aaa authentication login CONSOLE group tacacs+ local&lt;BR /&gt;aaa authentication enable default group tacacs+ enable&lt;BR /&gt;aaa authorization console&lt;BR /&gt;aaa authorization config-commands&lt;BR /&gt;aaa authorization exec default group tacacs+ local &lt;BR /&gt;aaa authorization exec CONSOLE group tacacs+ local &lt;BR /&gt;aaa authorization commands 1 default group tacacs+ local &lt;BR /&gt;aaa authorization commands 15 default group tacacs+ local&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 06:55:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/lin-con-0-authorization-failed/m-p/4925523#M584119</guid>
      <dc:creator>Conucci</dc:creator>
      <dc:date>2023-09-19T06:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: lin con 0 authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/lin-con-0-authorization-failed/m-p/4925551#M584120</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1595760"&gt;@Conucci&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;add&amp;nbsp;&lt;STRONG&gt;aaa authorization exec CONSOLE if-authenticated&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 07:31:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/lin-con-0-authorization-failed/m-p/4925551#M584120</guid>
      <dc:creator>M02@rt37</dc:creator>
      <dc:date>2023-09-19T07:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: lin con 0 authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/lin-con-0-authorization-failed/m-p/4925581#M584122</link>
      <description>&lt;P&gt;Dear &lt;A href="mailto:M02@rt37" target="_blank"&gt;M02@rt37&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Thank you, it's working. Strange is, that I didn't configure on C9200L and it's working. I have never seen before&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 08:18:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/lin-con-0-authorization-failed/m-p/4925581#M584122</guid>
      <dc:creator>Conucci</dc:creator>
      <dc:date>2023-09-19T08:18:44Z</dc:date>
    </item>
    <item>
      <title>Re: lin con 0 authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/lin-con-0-authorization-failed/m-p/4925589#M584123</link>
      <description>&lt;P&gt;You're very welcome&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1595760"&gt;@Conucci&lt;/a&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 08:24:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/lin-con-0-authorization-failed/m-p/4925589#M584123</guid>
      <dc:creator>M02@rt37</dc:creator>
      <dc:date>2023-09-19T08:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: lin con 0 authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/lin-con-0-authorization-failed/m-p/4925603#M584125</link>
      <description>&lt;P&gt;I think it should've worked with the commands you already applied. The only thing that comes to my mind that could potentially have caused this issue is that on the TACACS server you don't have the right authorization rules so potentially it was hitting a default deny rule. I think with the command suggested by&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/237724"&gt;M02@rt37&lt;/a&gt;&amp;nbsp;it wouldn't check against the TACACS policies configured on the TACACS server, and it would only look if the session has passed the authentication.&lt;/P&gt;
&lt;P&gt;Usually we add the "if-authenticated" keyword at the end of the aaa authorization command, something like this "&lt;SPAN&gt;aaa authorization exec CONSOLE group tacacs+ local if-authenticated". The "if-authenticated" keyword would allow the authorization to be allowed when the TACACS server is not available at the time the network device relays the authorization requests, and in that case, the network device would only verify if the session has been successfully authenticated. This is a security measure that would avoid being locked-out in case right after the authetnication the communication with the TACACS server goes down for any reason.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2023 08:47:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/lin-con-0-authorization-failed/m-p/4925603#M584125</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-09-19T08:47:22Z</dc:date>
    </item>
  </channel>
</rss>

