<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authorization Issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5008998#M586880</link>
    <description>&lt;P&gt;Unfortunately, it is in prod. I am desperately trying to get to it.&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jan 2024 12:53:16 GMT</pubDate>
    <dc:creator>JAISONTHOMAS</dc:creator>
    <dc:date>2024-01-30T12:53:16Z</dc:date>
    <item>
      <title>Authorization Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5008993#M586878</link>
      <description>&lt;P&gt;I have a catalyst&amp;nbsp;&lt;SPAN&gt;WS-C3850-48U-S that has some problem with getting it to enable mode. I am getting the below error,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;XXX-XXX-XXX-X&amp;gt;en&lt;BR /&gt;% Authorization failed.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I tried to console the switch and it is the same. Is there a way I can get into the switch and check its config.?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 12:45:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5008993#M586878</guid>
      <dc:creator>JAISONTHOMAS</dc:creator>
      <dc:date>2024-01-30T12:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5008995#M586879</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1673975"&gt;@JAISONTHOMAS&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The C3850 is in production environment ?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 12:49:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5008995#M586879</guid>
      <dc:creator>M02@rt37</dc:creator>
      <dc:date>2024-01-30T12:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5008998#M586880</link>
      <description>&lt;P&gt;Unfortunately, it is in prod. I am desperately trying to get to it.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 12:53:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5008998#M586880</guid>
      <dc:creator>JAISONTHOMAS</dc:creator>
      <dc:date>2024-01-30T12:53:16Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5008999#M586881</link>
      <description>&lt;P&gt;share&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show run | i aaa&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 12:53:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5008999#M586881</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-30T12:53:17Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009000#M586882</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1673975"&gt;@JAISONTHOMAS&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Auth relies on RADIUS or TACACS server ?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 12:54:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009000#M586882</guid>
      <dc:creator>M02@rt37</dc:creator>
      <dc:date>2024-01-30T12:54:39Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009002#M586883</link>
      <description>&lt;P&gt;xxxx-xxx-xxx&amp;gt;sh run | i aaa&lt;BR /&gt;^&lt;BR /&gt;% Invalid input detected at '^' marker.&lt;/P&gt;&lt;P&gt;xxxx-xxx-xxx&amp;gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 12:54:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009002#M586883</guid>
      <dc:creator>JAISONTHOMAS</dc:creator>
      <dc:date>2024-01-30T12:54:37Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009004#M586884</link>
      <description>&lt;P&gt;&lt;SPAN&gt;TACACS server&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 12:55:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009004#M586884</guid>
      <dc:creator>JAISONTHOMAS</dc:creator>
      <dc:date>2024-01-30T12:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009007#M586885</link>
      <description>&lt;P&gt;OK, I forget you cant access by console also&amp;nbsp;&lt;BR /&gt;do&amp;nbsp;&lt;/P&gt;
&lt;P&gt;enable &lt;STRONG&gt;5&lt;/STRONG&gt; or enable &lt;STRONG&gt;1&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;the try show&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;hope it work&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 13:15:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009007#M586885</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-30T13:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009022#M586886</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1673975"&gt;@JAISONTHOMAS&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"Authorization failed" message at the console is because in the config AAA authentication must be configured and no fallback option of enable or local username is there.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 13:10:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009022#M586886</guid>
      <dc:creator>M02@rt37</dc:creator>
      <dc:date>2024-01-30T13:10:17Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009029#M586887</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1673975"&gt;@JAISONTHOMAS&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you are unable to access enable mode due to authorization issues, you might need to perform a password recovery procedure. This involves restarting the switch and interrupting the boot sequence to access a recovery mode where you can add a AAA fallback with local credentials.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Maintenance window...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 13:16:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009029#M586887</guid>
      <dc:creator>M02@rt37</dc:creator>
      <dc:date>2024-01-30T13:16:47Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009032#M586888</link>
      <description>&lt;P&gt;It seems that the account you used to log into the switch doesn't have permissions to higher its privilege level. If you are using ISE as the TACACS server then I think you can workaround this by creating a new network access user in ISE with enable password configured, and then you create an authentication rule on ISE with TACACS service equals to enable, and finally you point that authentication rule to ISE internal users database.&lt;/P&gt;
&lt;P&gt;When you log into the switch with these new user credentials, and you type "en" you should then use the new enable password you configured in ISE, that should work.&lt;/P&gt;
&lt;P&gt;Alternatively, but depending on your TACACS configs on the switch, you simulate a link failure between the switch and ISE, maybe by placing a deny all firewall rule between the switch and ISE if the firewall happens to be in the path, and if your TACACS configs applied to the switch are configured to fall back to local or if "if-authenticated" keyword is configured, then authorizing the enable command would be skipped.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 13:21:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009032#M586888</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-01-30T13:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009033#M586889</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/237724"&gt;M02@rt37&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/284594"&gt;@Aref Alsouqi&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;the issue seem from AAA and he have two solution (depend on his config)&lt;BR /&gt;either password recovery (sorry&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1673975"&gt;@JAISONTHOMAS&lt;/a&gt;&amp;nbsp;)&lt;BR /&gt;or make TACACS push priv 15 via authz &amp;lt;&amp;lt;- this done by ISE or AAA server and it make you directly enter priv 15 no need enable&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;so let wait his reply can he access priv1 or priv5 or not&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 13:27:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009033#M586889</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-30T13:27:06Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009040#M586890</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;enable 1 and 5 didn't work.&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/284594"&gt;@Aref Alsouqi&lt;/a&gt;&amp;nbsp; yes we are using ISE as our tacacs server. I will try the ISE option you mentioned. if that fails, will put a FW rule to deny the connectivity to ISE and see if it failover to local authentication. Thank you guys, appreciated&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 13:32:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009040#M586890</guid>
      <dc:creator>JAISONTHOMAS</dc:creator>
      <dc:date>2024-01-30T13:32:27Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009046#M586891</link>
      <description>&lt;P&gt;if you use ISE push priv 15 to SW&amp;nbsp;&lt;BR /&gt;cisco-av-pair = priv-lev=15&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;&amp;lt;- this need to add in ISE&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;if you can not enter enable priv 15 then adjust the authz in SW is impossible, try solution from ISE&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 13:39:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009046#M586891</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-30T13:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009049#M586892</link>
      <description>&lt;P&gt;Yes that's right, changing the TACACS profile privilege level would be another option.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 13:39:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009049#M586892</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-01-30T13:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009052#M586893</link>
      <description>&lt;P&gt;thanks for confirm&amp;nbsp;&lt;BR /&gt;have a nice day&amp;nbsp;&lt;BR /&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 13:41:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009052#M586893</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-01-30T13:41:33Z</dc:date>
    </item>
    <item>
      <title>Re: Authorization Issue</title>
      <link>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009056#M586894</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;mentioned another option would be to change TACACS profile in ISE to push privilege 15 for example down to the switch. If you check your authorization rule in ISE you should see a profile associated next the rule to the right. You can check what privilege level is configured as the default in that profile, it would be something different than 15. If you don't want to change the settings of this original profile, then you can clone it and set the default privilege and the maximum to be level 15. And then you associate this profile to the authorization rule, this should place you in privilege level 15 when you log into the switch.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2024 13:43:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/authorization-issue/m-p/5009056#M586894</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-01-30T13:43:34Z</dc:date>
    </item>
  </channel>
</rss>

