<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi the command aaa in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501740#M72762</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the command&amp;nbsp;&lt;SPAN style="font-size: 14px;"&gt;aaa authorization network default group ISE-PSN-DOT1X&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;points to radius it should been pointed to tacacs or removed if authorization is not required.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it is not a bug issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 06 Oct 2014 06:44:45 GMT</pubDate>
    <dc:creator>saxenanitesh8522</dc:creator>
    <dc:date>2014-10-06T06:44:45Z</dc:date>
    <item>
      <title>I am unable to login to the switch using TACACS+ login after adding aaa authorization network command</title>
      <link>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501729#M72746</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I am testing a switch for aaa authentication when it is not communicating to ISE, and i found a strange behavior. After i added the aaa authentication accounting and authorization commands and reloaded the switch i was not able to login to the switch with the TACACS login&lt;/P&gt;&lt;P&gt;The switch kept going in cycles showing the banner and then giving the authentication failed message 3 times and the cycle starts with the banner and authentication failed message&lt;/P&gt;&lt;P&gt;i removed the command aaa authorization network command and i was reloaded the switch and i was able to login successfully.&lt;/P&gt;&lt;P&gt;could someone help me with this problem.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:04:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501729#M72746</guid>
      <dc:creator>Nisha Prabath</dc:creator>
      <dc:date>2019-03-11T05:04:42Z</dc:date>
    </item>
    <item>
      <title>Please attach your switch</title>
      <link>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501730#M72747</link>
      <description>&lt;P&gt;Please attach your switch config. If you cannot attach the whole config then please post your:&lt;/P&gt;&lt;P&gt;1. AAA configurations&lt;/P&gt;&lt;P&gt;2. Line (AUX, Console) configurations&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2014 00:05:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501730#M72747</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-10-02T00:05:53Z</dc:date>
    </item>
    <item>
      <title>I have pasted the AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501731#M72749</link>
      <description>&lt;P&gt;I have pasted the AAA configuration and the line configuation for your reference.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa group server radius ISE-PSN-DOT1X&lt;BR /&gt;&amp;nbsp;server name TCI-ISE01&lt;BR /&gt;&amp;nbsp;server name TCI-ISE02&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default group tacacs+ local&lt;BR /&gt;aaa authentication dot1x default group ISE-PSN-DOT1X&lt;BR /&gt;aaa authorization network default group ISE-PSN-DOT1X&lt;BR /&gt;aaa authorization network auth-list group ISE-PSN-DOT1X&lt;BR /&gt;aaa authorization auth-proxy default group ISE-PSN-DOT1X&lt;BR /&gt;aaa accounting update periodic 5&lt;BR /&gt;aaa accounting auth-proxy default start-stop group ISE-PSN-DOT1X&lt;BR /&gt;aaa accounting dot1x default start-stop group ISE-PSN-DOT1X&lt;BR /&gt;aaa accounting system default start-stop group ISE-PSN-DOT1X&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;line con 0&lt;BR /&gt;line vty 0 4&lt;BR /&gt;&amp;nbsp;password 7&lt;BR /&gt;&amp;nbsp;length 0&lt;BR /&gt;&amp;nbsp;transport input telnet&lt;BR /&gt;line vty 5 15&lt;BR /&gt;&amp;nbsp;transport input telnet&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2014 13:30:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501731#M72749</guid>
      <dc:creator>Nisha Prabath</dc:creator>
      <dc:date>2014-10-02T13:30:38Z</dc:date>
    </item>
    <item>
      <title>Thanks! Also, can you post</title>
      <link>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501732#M72752</link>
      <description>&lt;P&gt;Thanks! Also, can you post the "aaa authorization" command that breaks the process? The "aaa authentication" commands look ok.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2014 16:20:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501732#M72752</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-10-02T16:20:21Z</dc:date>
    </item>
    <item>
      <title>AAA authorization commands</title>
      <link>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501733#M72754</link>
      <description>&lt;P&gt;AAA authorization commands:&lt;/P&gt;&lt;P&gt;aaa authorization network default group ISE-PSN-DOT1X&lt;BR /&gt;aaa authorization network auth-list group ISE-PSN-DOT1X&lt;/P&gt;&lt;P&gt;After i removed the command 'aaa authorization network auth-list group ISE-PSN-DOT1X' from the switch and reloaded it, i was able to login successfully.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2014 17:15:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501733#M72754</guid>
      <dc:creator>Nisha Prabath</dc:creator>
      <dc:date>2014-10-02T17:15:32Z</dc:date>
    </item>
    <item>
      <title>Hmm, those commands are</title>
      <link>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501734#M72756</link>
      <description>&lt;P&gt;Hmm, those commands are related to network access and not associated with the authorization of your local device. I just tested the syntax in my lab and had no issues with it. So:&lt;/P&gt;&lt;P&gt;1. What version of code are you running on the network device?&lt;/P&gt;&lt;P&gt;2. What are you returning in the authorization profile in ISE?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2014 17:46:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501734#M72756</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-10-02T17:46:19Z</dc:date>
    </item>
    <item>
      <title>This switch is not talking to</title>
      <link>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501735#M72757</link>
      <description>&lt;P&gt;This switch is not talking to the ISE. this is more of a fail-over test environment where ISE is not available&lt;/P&gt;&lt;P&gt;SW Version&lt;BR /&gt;------ ----- -----&lt;BR /&gt;15.0(2)SE4&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2014 18:14:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501735#M72757</guid>
      <dc:creator>Nisha Prabath</dc:creator>
      <dc:date>2014-10-02T18:14:57Z</dc:date>
    </item>
    <item>
      <title>I am guessing that it is a</title>
      <link>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501736#M72758</link>
      <description>&lt;P&gt;I am guessing that it is a bug with that version of code...In my lab I am running 15.1.x code and have no issues.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2014 19:00:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501736#M72758</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-10-02T19:00:23Z</dc:date>
    </item>
    <item>
      <title>Oh ok.thank you for the help</title>
      <link>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501737#M72759</link>
      <description>&lt;P&gt;Oh ok.&lt;/P&gt;&lt;P&gt;thank you for the help and support.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2014 19:53:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501737#M72759</guid>
      <dc:creator>Nisha Prabath</dc:creator>
      <dc:date>2014-10-02T19:53:15Z</dc:date>
    </item>
    <item>
      <title>No problem! Please come back</title>
      <link>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501738#M72760</link>
      <description>&lt;P&gt;No problem! Please come back and let us know if a code upgrade resolves your issue!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 14px;"&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2014 20:43:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501738#M72760</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-10-02T20:43:36Z</dc:date>
    </item>
    <item>
      <title>Sure, will let you know once</title>
      <link>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501739#M72761</link>
      <description>&lt;P&gt;Sure, will let you know once my issue gets resolved.&lt;/P&gt;&lt;P&gt;Thank you so much for the support!&lt;/P&gt;</description>
      <pubDate>Thu, 02 Oct 2014 21:22:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501739#M72761</guid>
      <dc:creator>Nisha Prabath</dc:creator>
      <dc:date>2014-10-02T21:22:58Z</dc:date>
    </item>
    <item>
      <title>Hi the command aaa</title>
      <link>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501740#M72762</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the command&amp;nbsp;&lt;SPAN style="font-size: 14px;"&gt;aaa authorization network default group ISE-PSN-DOT1X&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;points to radius it should been pointed to tacacs or removed if authorization is not required.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it is not a bug issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 06 Oct 2014 06:44:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501740#M72762</guid>
      <dc:creator>saxenanitesh8522</dc:creator>
      <dc:date>2014-10-06T06:44:45Z</dc:date>
    </item>
    <item>
      <title>Hi Nitesh-That command (aaa</title>
      <link>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501741#M72763</link>
      <description>&lt;P&gt;Hi Nitesh-&lt;/P&gt;&lt;P&gt;That command (aaa authorization network...) has nothing to do with admin based authorization on the NAD (in this situation the switch). That command applies to network connections such as PPP, SLIP,, etc.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In addition, aaa authorization can be performed by Radius and not only TACACS+. Radius is not as powerful and you cannot provide authorization command sets but you can still return different privilege levels and roles.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you test the above configuration syntax? I did and it is working as expected!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM style="font-size: 14px;"&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Oct 2014 06:53:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501741#M72763</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-10-06T06:53:21Z</dc:date>
    </item>
    <item>
      <title>Hi Neno,Yes you are correct.</title>
      <link>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501742#M72764</link>
      <description>&lt;P&gt;Hi Neno,&lt;/P&gt;&lt;P&gt;Yes you are correct. i was able to login to switch but it took a while to show the username and password prompt.&lt;/P&gt;&lt;P&gt;Thank you for the support.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Oct 2014 13:55:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501742#M72764</guid>
      <dc:creator>Nisha Prabath</dc:creator>
      <dc:date>2014-10-06T13:55:07Z</dc:date>
    </item>
    <item>
      <title>Thank you for confirming this</title>
      <link>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501743#M72765</link>
      <description>&lt;P&gt;Thank you for confirming this Nisha and also thank you for the rating! I think the delay with the username/password showing is due to the switch trying to connect to your TACACS+ server. After that fails/timeouts then the username password shows up.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Oct 2014 16:11:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/i-am-unable-to-login-to-the-switch-using-tacacs-login-after/m-p/2501743#M72765</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-10-06T16:11:22Z</dc:date>
    </item>
  </channel>
</rss>

