<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Tacacs authentication request attributes in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-request-attributes/m-p/2387964#M88813</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Davide, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not exactly the same usage, BUT when you're attempting to authenticate to device via tacacs it would send remote address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/3/3/176335-Screen%20Shot%202014-01-13%20at%2012.59.41%20PM.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's the use case, if I may know?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 13 Jan 2014 12:00:25 GMT</pubDate>
    <dc:creator>Marcin Latosiewicz</dc:creator>
    <dc:date>2014-01-13T12:00:25Z</dc:date>
    <item>
      <title>Tacacs authentication request attributes</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-request-attributes/m-p/2387963#M88812</link>
      <description>&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hi ALL, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the authentication on a Router 2911 is done via tacacs (ACS 5.1). In the dashboard (or in the reports) of ACS&amp;nbsp; the IP address of the "calling station" (client used for authentication activity) is not reported. If I use RADIUS I could configure the router to send attributes (such as the number 31 = calling-station-id). How can I solve with tacacs protocol instead?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Davide &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:16:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-request-attributes/m-p/2387963#M88812</guid>
      <dc:creator>davide.fichera</dc:creator>
      <dc:date>2019-03-11T04:16:12Z</dc:date>
    </item>
    <item>
      <title>Tacacs authentication request attributes</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-request-attributes/m-p/2387964#M88813</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Davide, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not exactly the same usage, BUT when you're attempting to authenticate to device via tacacs it would send remote address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/3/3/176335-Screen%20Shot%202014-01-13%20at%2012.59.41%20PM.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's the use case, if I may know?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jan 2014 12:00:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-request-attributes/m-p/2387964#M88813</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2014-01-13T12:00:25Z</dc:date>
    </item>
    <item>
      <title>Tacacs authentication request attributes</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-request-attributes/m-p/2387965#M88816</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Marcin and thanks for your answer. The use case is a simple authentication activity. I've made a check and as you correctly show it is possible to retrieve the IP address of the remote client looking at the details of the log entry. It's very good news! However in the main (live) dashboard that information is not shown... Do you know why?&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/4/3/176345-ACS01.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Davide.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jan 2014 12:54:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-request-attributes/m-p/2387965#M88816</guid>
      <dc:creator>davide.fichera</dc:creator>
      <dc:date>2014-01-13T12:54:41Z</dc:date>
    </item>
    <item>
      <title>Tacacs authentication request attributes</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-request-attributes/m-p/2387966#M88819</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Davide, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think it was conscious design choice, the IP address in administration could be misleading. Although I'm not part of business unit so I'm not the best to comment. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you're looking for a place where it pops up, check accounting logs, you should be able to see the IP address as part of the audit session key. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/6/4/3/176346-Screen%20Shot%202014-01-13%20at%202.14.17%20PM.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jan 2014 13:15:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-request-attributes/m-p/2387966#M88819</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2014-01-13T13:15:01Z</dc:date>
    </item>
    <item>
      <title>Tacacs authentication request attributes</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-request-attributes/m-p/2387967#M88822</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Marcin, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;could you provide the detailed path to get the "audit session key" report shown above? Our version is ACS 5.1... maybe is missing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Davide&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jan 2014 13:55:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-request-attributes/m-p/2387967#M88822</guid>
      <dc:creator>davide.fichera</dc:creator>
      <dc:date>2014-01-13T13:55:33Z</dc:date>
    </item>
    <item>
      <title>Tacacs authentication request attributes</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-request-attributes/m-p/2387968#M88824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Davide, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No access to 5.1 I'm afraid, at least to one I can test freely. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;AAA Protocol &amp;gt; TACACS+ Accounting is where the session key should be visible. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Verfied for both IOS and ASA exec accounting. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;M. &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jan 2014 14:05:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-request-attributes/m-p/2387968#M88824</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2014-01-13T14:05:43Z</dc:date>
    </item>
    <item>
      <title>Tacacs authentication request attributes</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-request-attributes/m-p/2387969#M88825</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've found this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="1" cellpadding="3" cellspacing="0" id="wp155292table155286" style="color: #000000; font-size: 12px;" width="80%"&gt;&lt;TBODY&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&lt;P style="font-family: Arial, Helvetica, sans-serif; font-size: 11px; margin: 1px 0em 6px; text-indent: 0em;"&gt;&lt;A href="https://www.cisco.com/cisco/psn/bssprt/bss?searchType=bstbugidsearch&amp;amp;page=bstBugDetail&amp;amp;BugID=CSCth31525" target="_blank"&gt;CSCth31525&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;A name="wp159718"&gt;&lt;/A&gt;&lt;P style="font-family: Arial, Helvetica, sans-serif; font-size: 11px; margin: 1px 0em 6px; text-indent: 0em;"&gt;Live authentication report does not show TACACS+ data.&lt;/P&gt;&lt;A name="wp159737"&gt;&lt;/A&gt;&lt;P style="font-family: Arial, Helvetica, sans-serif; font-size: 11px; margin: 1px 0em 6px; text-indent: 0em;"&gt;Symptom: The TACACS+ live authentication report is missing data on some columns, including NAS and IP address.&lt;/P&gt;&lt;A name="wp159741"&gt;&lt;/A&gt;&lt;P style="font-family: Arial, Helvetica, sans-serif; font-size: 11px; margin: 1px 0em 6px; text-indent: 0em;"&gt;Conditions: This problem occurs only on ACS 5.1.&lt;/P&gt;&lt;A name="wp159745"&gt;&lt;/A&gt;&lt;P style="font-family: Arial, Helvetica, sans-serif; font-size: 11px; margin: 1px 0em 6px; text-indent: 0em;"&gt;Workaround: Use one of the other available reports to view this data.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;at &lt;A href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.2/release/notes/acs_52_rn.html"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.2/release/notes/acs_52_rn.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately it's a bug of this specific version...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Davide&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jan 2014 14:27:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-request-attributes/m-p/2387969#M88825</guid>
      <dc:creator>davide.fichera</dc:creator>
      <dc:date>2014-01-13T14:27:26Z</dc:date>
    </item>
    <item>
      <title>Tacacs authentication request attributes</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authentication-request-attributes/m-p/2387970#M88826</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Davide, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good find, this one has not been fixed in any ACS release and is considered an enhancement. &lt;/P&gt;&lt;P&gt;Go figure... &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jan 2014 15:56:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authentication-request-attributes/m-p/2387970#M88826</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2014-01-13T15:56:56Z</dc:date>
    </item>
  </channel>
</rss>

