<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX authentication using Tacacs ( ACS) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/pix-authentication-using-tacacs-acs/m-p/416800#M5853</link>
    <description>&lt;P&gt;I have configured my pix to authentication using tacacs first; if tacacs is not available it must fall back to LOCAL authentication. The TACACS authentication works fine, when I take out the ACS from the network, the local authentication works as well. The problem is when the ACS comes back online, the PIX do not want to authenticate to TACACS anymore, and it only accept the LOCAL username and password. If I reboot the PIX the tacacs username and Password works again. Can someone help me with this problem? I don't want to reboot my PIX now and then. Please find my configuration for the PIX.&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ (inside) host 1.1.1.1 xxxxx timeout 10&lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local&lt;/P&gt;&lt;P&gt;aaa authentication telnet console TACACS+ LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication enable console TACACS+ LOCAL&lt;/P&gt;&lt;P&gt;username xxxxx password xxxxxx encrypted privilege 15&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:13:04 GMT</pubDate>
    <dc:creator>amashau</dc:creator>
    <dc:date>2020-02-21T18:13:04Z</dc:date>
    <item>
      <title>PIX authentication using Tacacs ( ACS)</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-authentication-using-tacacs-acs/m-p/416800#M5853</link>
      <description>&lt;P&gt;I have configured my pix to authentication using tacacs first; if tacacs is not available it must fall back to LOCAL authentication. The TACACS authentication works fine, when I take out the ACS from the network, the local authentication works as well. The problem is when the ACS comes back online, the PIX do not want to authenticate to TACACS anymore, and it only accept the LOCAL username and password. If I reboot the PIX the tacacs username and Password works again. Can someone help me with this problem? I don't want to reboot my PIX now and then. Please find my configuration for the PIX.&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ (inside) host 1.1.1.1 xxxxx timeout 10&lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local&lt;/P&gt;&lt;P&gt;aaa authentication telnet console TACACS+ LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication enable console TACACS+ LOCAL&lt;/P&gt;&lt;P&gt;username xxxxx password xxxxxx encrypted privilege 15&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:13:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-authentication-using-tacacs-acs/m-p/416800#M5853</guid>
      <dc:creator>amashau</dc:creator>
      <dc:date>2020-02-21T18:13:04Z</dc:date>
    </item>
    <item>
      <title>Re: PIX authentication using Tacacs ( ACS)</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-authentication-using-tacacs-acs/m-p/416801#M5854</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;set the deadtime to "0", this way it will always check with the tacacs server before falling back to the local user database.  Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jul 2005 12:07:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-authentication-using-tacacs-acs/m-p/416801#M5854</guid>
      <dc:creator>vasthorvak</dc:creator>
      <dc:date>2005-07-27T12:07:44Z</dc:date>
    </item>
  </channel>
</rss>

