<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Mohammad,I replicated your in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618146#M74068</link>
    <description>&lt;P&gt;Hi Mohammad,&lt;/P&gt;&lt;P&gt;I replicated your configuration in a lab environment and I was able to ping all IP addresses, both active and standby.&lt;/P&gt;&lt;P&gt;Perhaps you should troubleshoot why you can't ping those addresses.&lt;/P&gt;</description>
    <pubDate>Fri, 13 Mar 2015 21:09:19 GMT</pubDate>
    <dc:creator>Adeolu Owokade</dc:creator>
    <dc:date>2015-03-13T21:09:19Z</dc:date>
    <item>
      <title>AAA and ASA issue</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618138#M74060</link>
      <description>&lt;P&gt;Hi Team&lt;/P&gt;&lt;P&gt;Once I configured the ASA AAA commands , hence I am not able to do any command including the show commands , And following message came once I accessed through serial through SSH..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;BR /&gt;Fallback authorization. Username 'enable_15' not in LOCAL database&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For more information Following are&amp;nbsp;AAA configuration in the ASA.&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;aaa authentication enable console TACACS-SERVER LOCAL&lt;BR /&gt;aaa authentication http console TACACS-SERVER LOCAL&lt;BR /&gt;aaa authentication ssh console TACACS-SERVER LOCAL&lt;BR /&gt;aaa authorization command TACACS-SERVER LOCAL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:32:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618138#M74060</guid>
      <dc:creator>MOHAMMAD ALHAJ EID</dc:creator>
      <dc:date>2019-03-11T05:32:28Z</dc:date>
    </item>
    <item>
      <title>Hi Mohammad,It has to do with</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618139#M74061</link>
      <description>&lt;P&gt;Hi Mohammad,&lt;/P&gt;&lt;P&gt;It has to do with the command authorization you enabled.&lt;/P&gt;&lt;P&gt;Do you have any AAA server configured under the TACACS-SERVER server-group? It seems the ASA tries to contact the TACACS-SERVER for command authorization and it fails so it falls back to the LOCAL database.&lt;/P&gt;&lt;P&gt;Since you configured these commands after logging in via SSH, the ASA tries to perform command authorization for the&amp;nbsp;"enable_15" username and it fails because there is no username like that in the LOCAL database.&lt;/P&gt;&lt;P&gt;Do you have access to the ASA via some other means? What kind of TACACS+ server are you using?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2015 04:01:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618139#M74061</guid>
      <dc:creator>Adeolu Owokade</dc:creator>
      <dc:date>2015-03-13T04:01:18Z</dc:date>
    </item>
    <item>
      <title>Do you have multiple context</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618140#M74062</link>
      <description>&lt;P&gt;Do you have multiple context configured with command authorization?&lt;/P&gt;&lt;P&gt;It seems that authentication request is failing over to local database and unable to find "enable_15" user in it. &amp;nbsp;&lt;/P&gt;&lt;P&gt;The solution is to create a username called "enable_15" or use "login".&lt;/P&gt;&lt;P&gt;It's explained &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/mode_contexts.html#wp1133258"&gt;here&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jatin&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2015 04:20:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618140#M74062</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2015-03-13T04:20:48Z</dc:date>
    </item>
    <item>
      <title>Dear Adeolu/JatinI have</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618141#M74063</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Dear Adeolu/Jatin&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I have created the username enable_15 with privilege 15 in both contexts with no luck; I would thank you for your prompt response.&lt;/P&gt;&lt;P&gt;Since I&amp;nbsp; configured a couple of boxes in A/A mode ( CTX-1&amp;nbsp;active in the first ASA and standby in the second ASA, Then CTX-2 is Active in&amp;nbsp;second ASA and standby in the first ASA) &amp;nbsp;I did following as troubleshooting and have doubt why IPs ( 10.32.0.1 and 10.32.0.12) are reachable but IPs( 10.32.0.2 and 10.32.0.11) are not reachable at all, even 10.32.0.11 is in active mode and this may occurring this issue.. For more information first box have no errors once I access the box through serial but the second box have the message of&amp;nbsp; once I accessed through serial...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;(Fallback authorization. Username 'enable_15' not in LOCAL database)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Following are the troubleshooting done.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;First box ( CTX-1) : &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;First-ASA-CONTEXT-1# show failover&lt;BR /&gt;Failover On&lt;BR /&gt;Last Failover at: 01:05:08 UTC Mar 12 2015&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; This context: &lt;STRONG&gt;Active&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Active time: 9701 (sec)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface VLAN812-IN (&lt;STRONG&gt;10.32.0.1&lt;/STRONG&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; Normal (Not-Monitored)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Peer context: &lt;STRONG&gt;Standby Ready&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Active time: 0 (sec)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface VLAN812-IN (&lt;STRONG&gt;10.32.0.2&lt;/STRONG&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; Normal (Not-Monitored)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First-ASA-CONTEXT-1#sh run int po8.812&lt;/P&gt;&lt;P&gt;interface Port-channel8.812&lt;BR /&gt;&amp;nbsp;nameif VLAN812-IN&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address &lt;STRONG&gt;10.32.100.1 255.255.255.0 standby 10.32.100.2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First-ASA-CONTEXT-1&amp;nbsp;# sh ip add&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;System IP Addresses:&lt;/STRONG&gt;&lt;BR /&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Subnet mask&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&lt;BR /&gt;Port-channel8.812&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VLAN812-IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;10.32.0.1&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; CONFIG&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Current IP Addresses:&lt;/STRONG&gt;&lt;BR /&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Subnet mask&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&lt;BR /&gt;Port-channel8.812&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VLAN812-IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;10.32.0.1&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; CONFIG&lt;/P&gt;&lt;P&gt;________________________________________________________________&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Second box, &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second- ASA( CTX-2)# show failover&lt;BR /&gt;Failover On&lt;BR /&gt;Last Failover at: 01:07:26 UTC Mar 12 2015&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; This context: &lt;STRONG&gt;Standby Ready&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Active time: 137 (sec)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface VLAN812-IN (&lt;STRONG&gt;10.32.0.12&lt;/STRONG&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; Normal (Not-Monitored)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Peer context: &lt;STRONG&gt;Active&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Active time: 9657 (sec)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface VLAN812-IN (&lt;STRONG&gt;10.32.0.11&lt;/STRONG&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; Normal (Not-Monitored)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second- ASA( CTX-2)# sh run int po8.812&lt;/P&gt;&lt;P&gt;interface Port-channel8.812&lt;BR /&gt;&amp;nbsp;nameif VLAN812-IN&lt;BR /&gt;&amp;nbsp;security-level 100&lt;BR /&gt;&amp;nbsp;ip address &lt;STRONG&gt;10.32.100.11 255.255.255.0 standby 10.32.100.12&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second- ASA( CTX-2)# &lt;STRONG&gt;sh ip add&amp;nbsp;&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;System IP Addresses:&lt;/STRONG&gt;&lt;BR /&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Subnet mask&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&lt;BR /&gt;Port-channel8.812&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VLAN812-IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;10.32.0.11&amp;nbsp;&lt;/STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.255.0&amp;nbsp;&amp;nbsp; CONFIG&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Current IP Addresses:&lt;/STRONG&gt;&lt;BR /&gt;Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; IP address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Subnet mask&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Method&lt;BR /&gt;Port-channel8.812&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VLAN812-IN&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;10.32.0.12&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;255.255.255.0&amp;nbsp;&amp;nbsp; CONFIG&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Following are TACACS-SERVER&amp;nbsp; configuration in both boxes : &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;aaa-server 10.32.0.100 protocol tacacs+&lt;BR /&gt;&lt;STRONG&gt;aaa-server TACACS-SERVER protocol tacacs+&lt;BR /&gt;aaa-server TACACS-SERVER (VLAN812-IN) host 10.32.0.100&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;key *****&lt;BR /&gt;user-identity default-domain LOCAL&lt;BR /&gt;aaa authentication enable console TACACS-SERVER LOCAL&lt;BR /&gt;aaa authentication http console TACACS-SERVER LOCAL&lt;BR /&gt;aaa authentication ssh console TACACS-SERVER LOCAL&lt;BR /&gt;aaa authorization command TACACS-SERVER LOCAL&lt;BR /&gt;aaa accounting command privilege 15 TACACS-SERVER&lt;BR /&gt;aaa accounting enable console TACACS-SERVER&lt;BR /&gt;aaa accounting ssh console TACACS-SERVER&lt;BR /&gt;aaa authorization exec authentication-server&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2015 09:09:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618141#M74063</guid>
      <dc:creator>MOHAMMAD ALHAJ EID</dc:creator>
      <dc:date>2015-03-13T09:09:23Z</dc:date>
    </item>
    <item>
      <title>Hi Mohammad,Before dealing</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618142#M74064</link>
      <description>&lt;P&gt;Hi Mohammad,&lt;/P&gt;&lt;P&gt;Before dealing with AAA, can you check that your A/A failover configuration is correct? I see something about 10.32.100.X instead of 10.32.0.X in your configuration. Was this a posting error?&lt;/P&gt;&lt;P&gt;Please paste your failover configuration for the system context and the interface configuration for CTX1 and CTX2. You can remove any revealing information.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2015 17:29:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618142#M74064</guid>
      <dc:creator>Adeolu Owokade</dc:creator>
      <dc:date>2015-03-13T17:29:54Z</dc:date>
    </item>
    <item>
      <title>Hi Andrew, Please find brief</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618143#M74065</link>
      <description>&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please find brief &amp;nbsp;attached for the failover configuration for both ASAs.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2015 18:05:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618143#M74065</guid>
      <dc:creator>MOHAMMAD ALHAJ EID</dc:creator>
      <dc:date>2015-03-13T18:05:34Z</dc:date>
    </item>
    <item>
      <title>Hi Mohammad,You are sharing</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618144#M74066</link>
      <description>&lt;P&gt;Hi Mohammad,&lt;/P&gt;&lt;P&gt;You are sharing interfaces between contexts so you should either have unique MAC addresses or a NAT configuration to help the ASA classify packets per contexts correctly. This link explains more:&amp;nbsp;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa80/configuration/guide/conf_gd/contexts.html#wp1124172"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa80/configuration/guide/conf_gd/contexts.html#wp1124172&lt;/A&gt;&lt;/P&gt;&lt;P&gt;What version of the ASA are you using? Starting from version 8.5(1), automatic MAC address generation is enabled. Check the MAC addresses on the interface just to be sure.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2015 19:54:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618144#M74066</guid>
      <dc:creator>Adeolu Owokade</dc:creator>
      <dc:date>2015-03-13T19:54:11Z</dc:date>
    </item>
    <item>
      <title>Hello Anddrew, I am using the</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618145#M74067</link>
      <description>&lt;P&gt;Hello &lt;SPAN style="color: rgb(75, 75, 75); font-family: &amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;A href="https://supportforums.cisco.com/users/adeoluowokade"&gt;&lt;SPAN style="color: rgb(53, 83, 145);"&gt;&lt;U&gt;Adeolu Owokade,&lt;/U&gt;&lt;/SPAN&gt;&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using the version 9.1, Shared interfaces are enabled and I am using the following command :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;MAC-ADDRESS AUTO PREFIX 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since I am configuring this command under the System context , It will replicate to the other ASA but it could be the prefix issue, Is it ?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2015 21:07:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618145#M74067</guid>
      <dc:creator>MOHAMMAD ALHAJ EID</dc:creator>
      <dc:date>2015-03-13T21:07:41Z</dc:date>
    </item>
    <item>
      <title>Hi Mohammad,I replicated your</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618146#M74068</link>
      <description>&lt;P&gt;Hi Mohammad,&lt;/P&gt;&lt;P&gt;I replicated your configuration in a lab environment and I was able to ping all IP addresses, both active and standby.&lt;/P&gt;&lt;P&gt;Perhaps you should troubleshoot why you can't ping those addresses.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2015 21:09:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618146#M74068</guid>
      <dc:creator>Adeolu Owokade</dc:creator>
      <dc:date>2015-03-13T21:09:19Z</dc:date>
    </item>
    <item>
      <title> appreciate your efforts</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618147#M74069</link>
      <description>&lt;P&gt;&amp;nbsp;appreciate your efforts Adelou,&lt;/P&gt;&lt;P&gt;I will do further troubleshooting on this case and keep you updated, But I have doubt may be because I created multiple pairs before this sub interface and this may a limitation, If you created more than two or three pairs other than the po8.812 , With different ips will other active and standby kept in reachable scenarios ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Mar 2015 22:06:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618147#M74069</guid>
      <dc:creator>MOHAMMAD ALHAJ EID</dc:creator>
      <dc:date>2015-03-13T22:06:35Z</dc:date>
    </item>
    <item>
      <title>Jatin, Can you chime in on</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618148#M74070</link>
      <description>&lt;P&gt;Jatin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you chime in on another ticket something similar to this one?&amp;nbsp; Anyconnect Client Certificate from me.&amp;nbsp; I would like to hear your advisement on the subject.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2015 20:47:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-asa-issue/m-p/2618148#M74070</guid>
      <dc:creator>james.king14</dc:creator>
      <dc:date>2015-10-06T20:47:07Z</dc:date>
    </item>
  </channel>
</rss>

