<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TACACS+ (ISE) configuration on a catalyst 9500 with Multiple-vrfs in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-ise-configuration-on-a-catalyst-9500-with-multiple-vrfs/m-p/5216541#M592759</link>
    <description>&lt;P&gt;As I see you don't use server-private command under group?&lt;/P&gt;
&lt;P&gt;Check config I share above&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Tue, 29 Oct 2024 04:52:02 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2024-10-29T04:52:02Z</dc:date>
    <item>
      <title>TACACS+ (ISE) configuration on a catalyst 9500 with Multiple-vrfs</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-ise-configuration-on-a-catalyst-9500-with-multiple-vrfs/m-p/5216452#M592749</link>
      <description>&lt;P&gt;Hello All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Kindly I need to help to configure TACACS+ (ISE) on a catalyst switch&amp;nbsp; 9500. The 9500 has 2 vrfs and in the aaa group I specified the vrf and the source-interface.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; I could successfully login to the switch but can not run any command. it gives me "Authorization Failed" and in ISE the logs show that the command was authorized successfully.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions would be helpful.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 20:51:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-ise-configuration-on-a-catalyst-9500-with-multiple-vrfs/m-p/5216452#M592749</guid>
      <dc:creator>hadeelOth81</dc:creator>
      <dc:date>2024-10-28T20:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+ (ISE) configuration on a catalyst 9500 with Multiple-vrfs</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-ise-configuration-on-a-catalyst-9500-with-multiple-vrfs/m-p/5216454#M592750</link>
      <description>&lt;P class="summary_indent"&gt;&lt;SPAN&gt;&lt;SPAN class="synph"&gt;&lt;SPAN class="kwd"&gt;aaa&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="kwd"&gt;group&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="kwd"&gt;server&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="kwd"&gt;tacacs+&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;group-name&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="summary_indent"&gt;&lt;SPAN&gt;&lt;SPAN class="synph"&gt;&lt;SPAN class="kwd"&gt;server-private&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;{&lt;SPAN class="synph"&gt;&lt;SPAN class="var"&gt;ip-address&lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;|&amp;nbsp;&lt;SPAN class="synph"&gt;&lt;SPAN class="var"&gt;name&lt;/SPAN&gt;&lt;/SPAN&gt;} [&lt;SPAN class="synph"&gt;&lt;SPAN class="kwd"&gt;nat&lt;/SPAN&gt;&lt;/SPAN&gt;] [&lt;SPAN class="synph"&gt;&lt;SPAN class="kwd"&gt;single-connection&lt;/SPAN&gt;&lt;/SPAN&gt;] [&lt;SPAN class="synph"&gt;&lt;SPAN class="kwd"&gt;port&lt;/SPAN&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="synph"&gt;&lt;SPAN class="var"&gt;port-number&lt;/SPAN&gt;] [&lt;SPAN class="kwd"&gt;timeout&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="var"&gt;seconds&lt;/SPAN&gt;] [&lt;SPAN class="kwd"&gt;key&lt;/SPAN&gt;&amp;nbsp;[&lt;SPAN class="kwd"&gt;0&lt;/SPAN&gt;&amp;nbsp;|&amp;nbsp;&lt;SPAN class="kwd"&gt;7&lt;/SPAN&gt;]&lt;SPAN class="var"&gt;&amp;nbsp;string&lt;/SPAN&gt;]&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="summary_indent"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="synph"&gt;&lt;SPAN class="kwd"&gt;ip&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="kwd"&gt;vrf&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="kwd"&gt;forwarding&lt;/SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="synph"&gt;&lt;SPAN class="var"&gt;vrf-name&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="summary_indent"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="synph"&gt;&lt;SPAN class="kwd"&gt;ip&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="kwd"&gt;tacacs&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN class="kwd"&gt;source-interface&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="summary_indent"&gt;&lt;SPAN&gt;&lt;SPAN class="synph"&gt;&lt;SPAN class="kwd"&gt;Do config as above&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="summary_indent"&gt;&lt;SPAN&gt;&lt;SPAN class="synph"&gt;&lt;SPAN class="kwd"&gt;MHM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 20:54:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-ise-configuration-on-a-catalyst-9500-with-multiple-vrfs/m-p/5216454#M592750</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-10-28T20:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+ (ISE) configuration on a catalyst 9500 with Multiple-vrfs</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-ise-configuration-on-a-catalyst-9500-with-multiple-vrfs/m-p/5216459#M592751</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;Unfortunately, it did not work. Still facing authorization failed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 21:07:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-ise-configuration-on-a-catalyst-9500-with-multiple-vrfs/m-p/5216459#M592751</guid>
      <dc:creator>hadeelOth81</dc:creator>
      <dc:date>2024-10-28T21:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+ (ISE) configuration on a catalyst 9500 with Multiple-vrfs</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-ise-configuration-on-a-catalyst-9500-with-multiple-vrfs/m-p/5216461#M592752</link>
      <description>&lt;P&gt;Can I see the full config&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 21:12:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-ise-configuration-on-a-catalyst-9500-with-multiple-vrfs/m-p/5216461#M592752</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-10-28T21:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+ (ISE) configuration on a catalyst 9500 with Multiple-vrfs</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-ise-configuration-on-a-catalyst-9500-with-multiple-vrfs/m-p/5216466#M592753</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;Please share complete AAA config, as well as VTY lines and console config, as well as print-screen with ISE TACACS log message.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Cristian.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Oct 2024 21:26:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-ise-configuration-on-a-catalyst-9500-with-multiple-vrfs/m-p/5216466#M592753</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2024-10-28T21:26:00Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+ (ISE) configuration on a catalyst 9500 with Multiple-vrfs</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-ise-configuration-on-a-catalyst-9500-with-multiple-vrfs/m-p/5216514#M592756</link>
      <description>&lt;P&gt;Here is the configuration&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;switch1#sh run | sec aaa&lt;BR /&gt;aaa new-model&lt;BR /&gt;aaa local authentication attempts max-fail 10&lt;BR /&gt;aaa group server tacacs+ (Group-Name)&lt;BR /&gt;server name ise-name1&lt;BR /&gt;server name ise-name2&lt;BR /&gt;ip vrf forwarding vrf-name&lt;BR /&gt;ip tacacs source-interface Loopback0&lt;BR /&gt;aaa authentication login default group Group_Name local&lt;BR /&gt;aaa authentication login synchronization none&lt;BR /&gt;aaa authorization config-commands&lt;BR /&gt;aaa authorization exec default group Group_Name if-authenticated&lt;BR /&gt;aaa authorization commands 0 default group tacacs+ local&lt;BR /&gt;aaa authorization commands 1 default group tacacs+ local&lt;BR /&gt;aaa authorization commands 15 default group tacacs+ local&lt;BR /&gt;aaa accounting update newinfo&lt;BR /&gt;aaa accounting exec default start-stop broadcast group Group-Name&lt;BR /&gt;aaa accounting commands 1 default start-stop broadcast group Group-Name&lt;BR /&gt;aaa accounting commands 15 default start-stop broadcast group Group-Name&lt;BR /&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;tacacs server ise-name1&lt;BR /&gt;address ipv4 IP&lt;BR /&gt;key 7 Key&lt;/P&gt;&lt;P&gt;tacacs server ise-name2&lt;BR /&gt;address ipv4 IP&lt;BR /&gt;key 7 Key&lt;/P&gt;&lt;P&gt;Thank you,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2024 02:50:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-ise-configuration-on-a-catalyst-9500-with-multiple-vrfs/m-p/5216514#M592756</guid>
      <dc:creator>hadeelOth81</dc:creator>
      <dc:date>2024-10-29T02:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+ (ISE) configuration on a catalyst 9500 with Multiple-vrfs</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-ise-configuration-on-a-catalyst-9500-with-multiple-vrfs/m-p/5216541#M592759</link>
      <description>&lt;P&gt;As I see you don't use server-private command under group?&lt;/P&gt;
&lt;P&gt;Check config I share above&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2024 04:52:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-ise-configuration-on-a-catalyst-9500-with-multiple-vrfs/m-p/5216541#M592759</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-10-29T04:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+ (ISE) configuration on a catalyst 9500 with Multiple-vrfs</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-ise-configuration-on-a-catalyst-9500-with-multiple-vrfs/m-p/5216695#M592770</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;Command authorization fails as within your config you're referencing globally configured TACACS servers which don't exist, your configuration uses aaa group settings. Perform following changes and it will work:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;no aaa authorization commands 0 default group tacacs+ local
no aaa authorization commands 1 default group tacacs+ local
no aaa authorization commands 15 default group tacacs+ local
!
aaa authorization commands 0 default group Group_Name local
aaa authorization commands 1 default group Group_Name local
aaa authorization commands 15 default group Group_Name local&lt;/LI-CODE&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Cristian.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2024 10:43:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-ise-configuration-on-a-catalyst-9500-with-multiple-vrfs/m-p/5216695#M592770</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2024-10-29T10:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS+ (ISE) configuration on a catalyst 9500 with Multiple-vrfs</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-ise-configuration-on-a-catalyst-9500-with-multiple-vrfs/m-p/5216865#M592781</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/295226"&gt;@Cristian Matei&lt;/a&gt;&amp;nbsp;. It solved the issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Oct 2024 14:53:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-ise-configuration-on-a-catalyst-9500-with-multiple-vrfs/m-p/5216865#M592781</guid>
      <dc:creator>hadeelOth81</dc:creator>
      <dc:date>2024-10-29T14:53:00Z</dc:date>
    </item>
  </channel>
</rss>

