<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue with ACS 4.2 in Authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/issue-with-acs-4-2-in-authentication/m-p/2353952#M88920</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mohammad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think I see the problem right away.&lt;/P&gt;&lt;P&gt;The ACS is dropping the packet due to IP mismatch.&lt;/P&gt;&lt;P&gt;Check the IP addresses.&lt;/P&gt;&lt;P&gt;The IP that you have defined is 147.23&lt;/P&gt;&lt;P&gt;The IP that the device is using is 149.24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that you have multiple interfaces on the device and its using its own routing table.&lt;/P&gt;&lt;P&gt;If you want to force the device to use a specific IP for T+, then use "ip tacacs source-interface &lt;INTERFACE&gt;"&lt;/INTERFACE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or if you want to change this on the server end, then define, 149.24 as a network device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**Share your knowledge. It’s a way to achieve immortality. &lt;BR /&gt;--Dalai Lama** &lt;BR /&gt; &lt;BR /&gt;Please Rate if helpful. &lt;BR /&gt;Regards &lt;BR /&gt;Ed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Jan 2014 13:16:55 GMT</pubDate>
    <dc:creator>edwjames</dc:creator>
    <dc:date>2014-01-09T13:16:55Z</dc:date>
    <item>
      <title>Issue with ACS 4.2 in Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-acs-4-2-in-authentication/m-p/2353949#M88913</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;Hey guys.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I ve got a problem with the ACS 4.2 just in authentication&lt;/P&gt;&lt;P&gt;I have a 3750 Catalyst and installed an ACS 4.2 both in 1 zone. They can ping each other and there is no problem in their connectivity. I ve created a user called “test” in ACS local database, defined the switch in ACS database and configured 3750 with below commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication attempts login 10&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local enable&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;tacacs-server host 192.168.149.30&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;tacacs-server key 7 046803071F&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I try to login via the “test” user the below problem is appeared in my screen while debugging the authentication process in switch:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 10pt; "&gt;Apr&amp;nbsp; 1 05:29:11: AAA/BIND(00000049): Bind i/f&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;Apr&amp;nbsp; 1 05:29:11: AAA/AUTHEN/LOGIN (00000049): Pick method list 'default'&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;Apr&amp;nbsp; 1 05:29:11: TPLUS: Queuing AAA Authentication request 73 for processing&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-size: 10pt; "&gt;Apr&amp;nbsp; 1 05:29:11: TPLUS: processing authentication start request id 73&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;Apr&amp;nbsp; 1 05:29:11: TPLUS: Authentication start packet created for 73(test)&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;Apr&amp;nbsp; 1 05:29:11: TPLUS: Using server 192.168.149.30&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;Apr&amp;nbsp; 1 05:29:12: TPLUS(00000049)/0/NB_WAIT/82F6C3C: Started 5 sec timeout&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;Apr&amp;nbsp; 1 05:29:12: TPLUS(00000049)/0/NB_WAIT: socket event 2&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;Apr&amp;nbsp; 1 05:29:12: TPLUS(00000049)/0/NB_WAIT: wrote entire 39 bytes request&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;Apr&amp;nbsp; 1 05:29:12: TPLUS(00000049)/0/READ: socket event 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;SW48-3#&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;Apr&amp;nbsp; 1 05:29:12: TPLUS(00000049)/0/READ: Would block while reading&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;Apr&amp;nbsp; 1 05:29:12: TPLUS(00000049)/0/READ: socket event 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;Apr&amp;nbsp; 1 05:29:12: TPLUS(00000049)/0/READ: errno 32&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;Apr&amp;nbsp; 1 05:29:12: TPLUS(00000049)/0/82F6C3C: Processing the reply packet&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;Apr&amp;nbsp; 1 05:29:12: AAA/LOCAL/LOGIN(00000049): user test not found&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;Apr&amp;nbsp; 1 05:29:12: AAA/LOCAL/LOGIN(00000049): get password&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;Apr&amp;nbsp; 1 05:29:12: AAA/LOCAL/LOGIN(00000049): failover&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;Apr&amp;nbsp; 1 05:29:12: AAA/AUTHEN/ENABLE(00000049): Processing request action LOGIN&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;Apr&amp;nbsp; 1 05:29:12: AAA/AUTHEN/ENABLE(00000049): Done status GET_PASSWORD&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;SW48-3#&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;Apr&amp;nbsp; 1 05:29:16: AAA/AUTHEN/ENABLE(00000049): Processing request action LOGIN&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin-bottom: 0.0001pt;"&gt;&lt;STRONG&gt;Apr&amp;nbsp; 1 05:29:16: AAA/AUTHEN/ENABLE(00000049): Done status FAIL - bad password&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to confirm that the password is definitely correct and there is not any authorization process.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will be very thankful if someone can help me to troubleshoot this matter.&amp;nbsp; (or any doc that shows how to authenticate a user via ACS 4.2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Moe&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:15:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-acs-4-2-in-authentication/m-p/2353949#M88913</guid>
      <dc:creator>m_sadeghpour</dc:creator>
      <dc:date>2019-03-11T04:15:12Z</dc:date>
    </item>
    <item>
      <title>Issue with ACS 4.2 in Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-acs-4-2-in-authentication/m-p/2353950#M88916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Moe,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What are all the debugs that you have used here?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the debugs:&lt;/P&gt;&lt;P&gt;the request to falling back to local, user is not there in the internal DB and then its falling back to the enable password to which it fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the attempt or report on the ACS?&lt;/P&gt;&lt;P&gt;Can you share screenshots of the ACS configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**Share your knowledge. It’s a way to achieve immortality. &lt;BR /&gt;--Dalai Lama** &lt;BR /&gt; &lt;BR /&gt;Please Rate if helpful. &lt;BR /&gt;Regards &lt;BR /&gt;Ed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jan 2014 16:13:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-acs-4-2-in-authentication/m-p/2353950#M88916</guid>
      <dc:creator>edwjames</dc:creator>
      <dc:date>2014-01-08T16:13:12Z</dc:date>
    </item>
    <item>
      <title>Issue with ACS 4.2 in Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-acs-4-2-in-authentication/m-p/2353951#M88919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tnx for your reply Ed.&lt;/P&gt;&lt;P&gt;As it was already mentioned the user was created on local ACS database and the switch was added too.&lt;/P&gt;&lt;P&gt;I have attached a screenshot of configured ACS and its report section.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the debug commands that was used to capture above information on switch are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug aaa authentication&lt;/P&gt;&lt;P&gt;debug tacacs authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;honelsty, I have never been that much confused about ACS.&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/8/2/3/174328-Untitled.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Moe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jan 2014 04:27:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-acs-4-2-in-authentication/m-p/2353951#M88919</guid>
      <dc:creator>m_sadeghpour</dc:creator>
      <dc:date>2014-01-09T04:27:35Z</dc:date>
    </item>
    <item>
      <title>Issue with ACS 4.2 in Authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/issue-with-acs-4-2-in-authentication/m-p/2353952#M88920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mohammad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think I see the problem right away.&lt;/P&gt;&lt;P&gt;The ACS is dropping the packet due to IP mismatch.&lt;/P&gt;&lt;P&gt;Check the IP addresses.&lt;/P&gt;&lt;P&gt;The IP that you have defined is 147.23&lt;/P&gt;&lt;P&gt;The IP that the device is using is 149.24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that you have multiple interfaces on the device and its using its own routing table.&lt;/P&gt;&lt;P&gt;If you want to force the device to use a specific IP for T+, then use "ip tacacs source-interface &lt;INTERFACE&gt;"&lt;/INTERFACE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or if you want to change this on the server end, then define, 149.24 as a network device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**Share your knowledge. It’s a way to achieve immortality. &lt;BR /&gt;--Dalai Lama** &lt;BR /&gt; &lt;BR /&gt;Please Rate if helpful. &lt;BR /&gt;Regards &lt;BR /&gt;Ed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jan 2014 13:16:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issue-with-acs-4-2-in-authentication/m-p/2353952#M88920</guid>
      <dc:creator>edwjames</dc:creator>
      <dc:date>2014-01-09T13:16:55Z</dc:date>
    </item>
  </channel>
</rss>

