<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Refer the document  : http:/ in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-6-authentication-problem/m-p/2590179#M75341</link>
    <description>&lt;P&gt;Refer the document&amp;nbsp; : &lt;A href="http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_system/5-6/migration/guide/migration_guide/Migration_support.html#pgfId-1014889"&gt;http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_system/5-6/migration/guide/migration_guide/Migration_support.html#pgfId-1014889&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 31 Dec 2014 09:13:46 GMT</pubDate>
    <dc:creator>mohanak</dc:creator>
    <dc:date>2014-12-31T09:13:46Z</dc:date>
    <item>
      <title>ACS 5.6 authentication problem</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-6-authentication-problem/m-p/2590177#M75339</link>
      <description>&lt;P&gt;We are in the process of upgrading our ACS 4.1 to an ACS 5.6 appliance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The appliance is installed on the network, properly licensed etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I joined the ACS server to the AD domain without a problem. I created some local and external (AD) users for testing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created a network device (catalyst switch) as a tacacs+ client, and specified single-connect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I SSH into the switch, I can log in using my AD username and password, but I cannot go into enable mode. It says "Error in authentication"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my aaa settings are&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tacacs-server host 172.25.50.8&lt;BR /&gt;tacacs-server timeout 3&lt;BR /&gt;tacacs-server directed-request&lt;BR /&gt;tacacs-server key &amp;lt;key&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am missing something somewhere, I just don't know where. If I try and download the ACS support bundle, it says downloading, but doesn't say where to get it (or how).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any advice would be great. I am new to this product.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:18:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-6-authentication-problem/m-p/2590177#M75339</guid>
      <dc:creator>Colin Higgins</dc:creator>
      <dc:date>2019-03-11T05:18:43Z</dc:date>
    </item>
    <item>
      <title>also, my aaa settings are:</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-6-authentication-problem/m-p/2590178#M75340</link>
      <description>&lt;P&gt;also, my aaa settings are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;BR /&gt;aaa authentication login listsw2s group tacacs+ local&lt;BR /&gt;aaa authentication enable default group tacacs+ enable&lt;BR /&gt;aaa authorization exec listsw2s group tacacs+ local&lt;/P&gt;</description>
      <pubDate>Tue, 30 Dec 2014 20:52:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-6-authentication-problem/m-p/2590178#M75340</guid>
      <dc:creator>Colin Higgins</dc:creator>
      <dc:date>2014-12-30T20:52:48Z</dc:date>
    </item>
    <item>
      <title>Refer the document  : http:/</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-6-authentication-problem/m-p/2590179#M75341</link>
      <description>&lt;P&gt;Refer the document&amp;nbsp; : &lt;A href="http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_system/5-6/migration/guide/migration_guide/Migration_support.html#pgfId-1014889"&gt;http://www.cisco.com/c/en/us/td/docs/net_mgmt/cisco_secure_access_control_system/5-6/migration/guide/migration_guide/Migration_support.html#pgfId-1014889&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Dec 2014 09:13:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-6-authentication-problem/m-p/2590179#M75341</guid>
      <dc:creator>mohanak</dc:creator>
      <dc:date>2014-12-31T09:13:46Z</dc:date>
    </item>
    <item>
      <title>OK, looks like I have</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-6-authentication-problem/m-p/2590180#M75342</link>
      <description>&lt;P&gt;OK, looks like I have everything working now. I had the wrong shell authorization specified for the group. I was authenticating, but then couldn't do anything.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the other question is, when I download the support pack to view the logs, where does ACS send this download? It doesn't say.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Dec 2014 15:59:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-6-authentication-problem/m-p/2590180#M75342</guid>
      <dc:creator>Colin Higgins</dc:creator>
      <dc:date>2014-12-31T15:59:52Z</dc:date>
    </item>
    <item>
      <title>Actually, I spoke too soon.</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-6-authentication-problem/m-p/2590181#M75343</link>
      <description>&lt;P&gt;Actually, I spoke too soon. It is working for some users and not others, even though they are set up exactly the same way. Some can authenticate and some cannot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where can I go to see what is failing?&lt;/P&gt;</description>
      <pubDate>Wed, 31 Dec 2014 16:44:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-6-authentication-problem/m-p/2590181#M75343</guid>
      <dc:creator>Colin Higgins</dc:creator>
      <dc:date>2014-12-31T16:44:45Z</dc:date>
    </item>
    <item>
      <title>OK, I have an update I found</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-6-authentication-problem/m-p/2590182#M75344</link>
      <description>&lt;P&gt;OK, I have an update&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I found the reports in ACS, so that is not an issue. Here is what is happening&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a Catalyst 6509 that has been added to the ACS 5.6 server as a AAA client. Key has been verified, and user accounts are fine (I have verified authentication against other network devices without a problem).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the AAA settings for the switch are&lt;/P&gt;&lt;P&gt;aaa new-model&lt;BR /&gt;aaa authentication login listsw2s group tacacs+ local&lt;BR /&gt;aaa authentication enable default group tacacs+ enable&lt;BR /&gt;aaa authorization exec listsw2s group tacacs+ local&lt;/P&gt;&lt;P&gt;tacacs-server host 172.25.50.8&lt;BR /&gt;tacacs-server timeout 3&lt;BR /&gt;tacacs-server directed-request&lt;BR /&gt;tacacs-server key &amp;lt;key&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I do a test aaa group tacacs &amp;lt;username&amp;gt; &amp;lt;password&amp;gt;&lt;/P&gt;&lt;P&gt;and enable aaa debugging on the switch, it says user authenticated. If I look in the logs on the ACS server, it verifies that the user was authenticated without a problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, if I ssh into the switch and attempt to authenticate using the same credentials, it fails.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nothing shows up in the ACS log, and the aaa debugging indicates it is trying to use the local database and failing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The switch seems to be "stuck" somehow, and refusing to use the tacacs server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone seen this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Dec 2014 17:37:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-6-authentication-problem/m-p/2590182#M75344</guid>
      <dc:creator>Colin Higgins</dc:creator>
      <dc:date>2014-12-31T17:37:01Z</dc:date>
    </item>
    <item>
      <title>OK, I have the solution the</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-6-authentication-problem/m-p/2590183#M75345</link>
      <description>&lt;P&gt;OK, I have the solution&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the authentication list of the vty lines 04 and 5 15 didn't match. The list specified in the aaa settings did not match the one in the line (one digit off). Therefore, the switch was never looking to ACS when authenticating ssh users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Dec 2014 18:01:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-6-authentication-problem/m-p/2590183#M75345</guid>
      <dc:creator>Colin Higgins</dc:creator>
      <dc:date>2014-12-31T18:01:31Z</dc:date>
    </item>
  </channel>
</rss>

