<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA new-model in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-new-model/m-p/2639107#M74628</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;While trying to change the TACACS server I entered&lt;/P&gt;&lt;P&gt;no aaa-new model&amp;nbsp; before removing aaa authorization exec default group tacacs+ local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I saved the config so now I can not enter&lt;STRONG&gt; aaa-new model&lt;/STRONG&gt; because the router output is &lt;STRONG&gt;Authorization failed&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is if there is anyway to configure again the TACACS remotely. I have access through a login local with priviledge 15&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The router is a cisco 2801 ver 12.4&lt;/P&gt;&lt;P&gt;I entered no service config because I thought this might have to do with the above issue.&lt;/P&gt;&lt;P&gt;%SYS-4-CONFIG_RESOLVE_FAILURE: System config parse from (tftp://255.255.255.255/cisconet.cfg) failed&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 05:26:01 GMT</pubDate>
    <dc:creator>Alejandro Manuel Rodriguez Daumy</dc:creator>
    <dc:date>2019-03-11T05:26:01Z</dc:date>
    <item>
      <title>AAA new-model</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-new-model/m-p/2639107#M74628</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;While trying to change the TACACS server I entered&lt;/P&gt;&lt;P&gt;no aaa-new model&amp;nbsp; before removing aaa authorization exec default group tacacs+ local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I saved the config so now I can not enter&lt;STRONG&gt; aaa-new model&lt;/STRONG&gt; because the router output is &lt;STRONG&gt;Authorization failed&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is if there is anyway to configure again the TACACS remotely. I have access through a login local with priviledge 15&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The router is a cisco 2801 ver 12.4&lt;/P&gt;&lt;P&gt;I entered no service config because I thought this might have to do with the above issue.&lt;/P&gt;&lt;P&gt;%SYS-4-CONFIG_RESOLVE_FAILURE: System config parse from (tftp://255.255.255.255/cisconet.cfg) failed&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:26:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-new-model/m-p/2639107#M74628</guid>
      <dc:creator>Alejandro Manuel Rodriguez Daumy</dc:creator>
      <dc:date>2019-03-11T05:26:01Z</dc:date>
    </item>
    <item>
      <title>Hello Alejandro-I am a bit</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-new-model/m-p/2639108#M74629</link>
      <description>&lt;P&gt;Hello Alejandro-&lt;/P&gt;&lt;P&gt;I am a bit confused on the issue that you are having and the question that you are asking:&lt;/P&gt;&lt;P&gt;1. If you issue "no aaa new-model" then any aaa related commands should be removed from the switch. Thus, the "aaa authorization exec..." command should no longer be part of your running config&lt;/P&gt;&lt;P&gt;2. If for some reason the authorization command is still in place then you should be able to configure the device once you are re-logged in via the local user. This should be possible because you have "local" at the end of your command which will instruct the router to check the local database if the AAA server is unavailable.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank &amp;nbsp;you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2015 04:45:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-new-model/m-p/2639108#M74629</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-02-10T04:45:50Z</dc:date>
    </item>
    <item>
      <title>Hello Neno The problem is</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-new-model/m-p/2639109#M74630</link>
      <description>&lt;P&gt;Hello Neno&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is that when I reenter aaa new-model for the new TACACS configuration the command&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local of the previous configuration becomes active&lt;/P&gt;&lt;P&gt;and the router wont let me enter any configuration with an&lt;STRONG&gt; Authorization failed&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2015 15:36:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-new-model/m-p/2639109#M74630</guid>
      <dc:creator>Alejandro Manuel Rodriguez Daumy</dc:creator>
      <dc:date>2015-02-10T15:36:21Z</dc:date>
    </item>
    <item>
      <title>Are you getting the</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-new-model/m-p/2639110#M74631</link>
      <description>&lt;P&gt;Are you getting the authorization failure due to the TACACS server response? Then you should block TACACS+ traffic with an ACL temporarily.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Feb 2015 19:18:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-new-model/m-p/2639110#M74631</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2015-02-15T19:18:24Z</dc:date>
    </item>
  </channel>
</rss>

