<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA issue  ( command authorization failed) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-issue-command-authorization-failed/m-p/2378146#M89022</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Actually, the script I pasted above is giving me errors on authorization . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can input the AD credentials for login username and password, yet enter the enable mode, but in enable mdoe cannot run the SHOW RUN or SHOW VER commands and says COMMAND AUTHIRZATION FAILED ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need help on that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 07 Jan 2014 00:43:13 GMT</pubDate>
    <dc:creator>game123</dc:creator>
    <dc:date>2014-01-07T00:43:13Z</dc:date>
    <item>
      <title>AAA issue  ( command authorization failed)</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-issue-command-authorization-failed/m-p/2378143#M89019</link>
      <description>&lt;P&gt;I am getting the issue, and following is the script , cannot find&amp;nbsp; and locate the cause of error !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;version 12.2&lt;/P&gt;&lt;P&gt;no service pad&lt;/P&gt;&lt;P&gt;service timestamps debug datetime msec&lt;/P&gt;&lt;P&gt;service timestamps log datetime msec&lt;/P&gt;&lt;P&gt;service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname hexxor&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot-start-marker&lt;/P&gt;&lt;P&gt;boot-end-marker&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;enable secret 5 $1$Y.Nt$aZ9/2rl2DMbEnSGJVqmln1&lt;/P&gt;&lt;P&gt;enable password 7 0525112F05411F075231123E&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;username hexxor password 7 024D2A103F26243363593D1C2B5C&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login T-AUTH group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization console&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;P&gt;aaa authorization exec T-AUTHOR group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 T-AUTHOR group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa accounting exec T-ACC start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 T-ACC start-stop group tacacs+&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan50&lt;/P&gt;&lt;P&gt; ip address 128.1.50.54 255.255.255.0&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip default-gateway 128.1.50.254&lt;/P&gt;&lt;P&gt;no ip http server&lt;/P&gt;&lt;P&gt;ip http secure-server&lt;/P&gt;&lt;P&gt;ip sla enable reaction-alerts&lt;/P&gt;&lt;P&gt;logging trap debugging&lt;/P&gt;&lt;P&gt;logging 10.241.40.20&lt;/P&gt;&lt;P&gt;logging 128.1.50.245&lt;/P&gt;&lt;P&gt;access-list 1 permit 128.1.50.245&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;snmp-server host 10.241.40.27 Armageddon &lt;/P&gt;&lt;P&gt;snmp-server host 128.1.50.245 Armageddon &lt;/P&gt;&lt;P&gt;tacacs-server host 10.241.40.22&lt;/P&gt;&lt;P&gt;tacacs-server host 10.241.40.23&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;tacacs-server key 7 020813480E052F2E4D&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt; exec-timeout 5 0&lt;/P&gt;&lt;P&gt; password 7 1142374E2332201E2B3D1F210678&lt;/P&gt;&lt;P&gt; authorization commands 15 T-AUTHOR&lt;/P&gt;&lt;P&gt; authorization exec T-AUTHOR&lt;/P&gt;&lt;P&gt; accounting commands 15 T-ACC&lt;/P&gt;&lt;P&gt; accounting exec T-ACC&lt;/P&gt;&lt;P&gt; login authentication T-AUTH&lt;/P&gt;&lt;P&gt; transport preferred none&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; exec-timeout 5 0&lt;/P&gt;&lt;P&gt; password 7 06281801684358174E231727&lt;/P&gt;&lt;P&gt; authorization commands 15 T-AUTHOR&lt;/P&gt;&lt;P&gt; authorization exec T-AUTHOR&lt;/P&gt;&lt;P&gt; accounting commands 15 T-ACC&lt;/P&gt;&lt;P&gt; accounting exec T-ACC&lt;/P&gt;&lt;P&gt; login authentication T-AUTH&lt;/P&gt;&lt;P&gt; transport input telnet&lt;/P&gt;&lt;P&gt; transport output telnet&lt;/P&gt;&lt;P&gt;line vty 5 15&lt;/P&gt;&lt;P&gt; password 7 0228137B2F0B5E2F077A0C35&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:13:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-issue-command-authorization-failed/m-p/2378143#M89019</guid>
      <dc:creator>game123</dc:creator>
      <dc:date>2019-03-11T04:13:52Z</dc:date>
    </item>
    <item>
      <title>AAA issue  ( command authorization failed)</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-issue-command-authorization-failed/m-p/2378144#M89020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1- check your radius server logs and see what it says about this message.&lt;/P&gt;&lt;P&gt;2- add the following lines to your config:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt;aaa authorization commands 0 T-AUTHOR group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;gt;aaa authorization commands 1 T-AUTHOR group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: blue;"&gt;Rating useful replies is more useful than saying &lt;SPAN style="color: green;"&gt; "&lt;SPAN style="text-decoration: underline;"&gt;Thank you&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jan 2014 09:40:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-issue-command-authorization-failed/m-p/2378144#M89020</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2014-01-02T09:40:07Z</dc:date>
    </item>
    <item>
      <title>AAA issue  ( command authorization failed)</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-issue-command-authorization-failed/m-p/2378145#M89021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are several authorization commands configured. It would be helpful to know which one might be the one causing the issue. Are we correct in assuming that authentication is processing successfully to TACACS and that TACACS authorization is where the problem is coming from?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you tell us whether the authorization failed message is generated when you attempt to login? Or is it generated when you attempt to enter some command?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 16:05:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-issue-command-authorization-failed/m-p/2378145#M89021</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2014-01-03T16:05:09Z</dc:date>
    </item>
    <item>
      <title>AAA issue  ( command authorization failed)</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-issue-command-authorization-failed/m-p/2378146#M89022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Actually, the script I pasted above is giving me errors on authorization . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can input the AD credentials for login username and password, yet enter the enable mode, but in enable mdoe cannot run the SHOW RUN or SHOW VER commands and says COMMAND AUTHIRZATION FAILED ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need help on that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jan 2014 00:43:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-issue-command-authorization-failed/m-p/2378146#M89022</guid>
      <dc:creator>game123</dc:creator>
      <dc:date>2014-01-07T00:43:13Z</dc:date>
    </item>
    <item>
      <title>AAA issue  ( command authorization failed)</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-issue-command-authorization-failed/m-p/2378147#M89023</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Based on what I think I understand in this reply it appears that the problem is caused in the named authorization method of T-AUTHOR. This named method sends an authorization request to the TACACS server. So it appears that the TACACS server is not authorizing the commands that you enter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest this as a first test:&lt;/P&gt;&lt;P&gt;- login to the device.&lt;/P&gt;&lt;P&gt;- go into enabl mode.&lt;/P&gt;&lt;P&gt;- attempt the show run command. (I assume that it will fail)&lt;/P&gt;&lt;P&gt;- check on the TACACS server. look in the logs for indications of how it processed the request and why it did not authorize it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to do a second test to verify the cause of the problem then I would suggest this:&lt;/P&gt;&lt;P&gt;- remove from the config these lines&lt;/P&gt;&lt;P&gt;aaa authorization exec T-AUTHOR group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 T-AUTHOR group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;then login to the device, go into enable mode, attempt the show run command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try one or both of these tests and post back to tell us of the results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jan 2014 03:54:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-issue-command-authorization-failed/m-p/2378147#M89023</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2014-01-07T03:54:39Z</dc:date>
    </item>
    <item>
      <title>AAA issue  ( command authorization failed)</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-issue-command-authorization-failed/m-p/2378148#M89024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Honestly,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All tips are fine ... but&amp;nbsp; i just restarted my ACS&amp;nbsp; and things started working fine. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;amazing ! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this happened in the CCIE&amp;nbsp; lab also to me&amp;nbsp; 4 years ago&amp;nbsp; !!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for all the advice anyways.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;keep up the good work!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-K-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jan 2014 18:55:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-issue-command-authorization-failed/m-p/2378148#M89024</guid>
      <dc:creator>game123</dc:creator>
      <dc:date>2014-01-13T18:55:02Z</dc:date>
    </item>
    <item>
      <title>AAA issue  ( command authorization failed)</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-issue-command-authorization-failed/m-p/2378149#M89025</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for posting back to the forum and letting us know that it has started to work correctly after a restart. It is sometimes helpful to be reminded that when strange symptoms are encountered that sometimes a restart will cause things to work normally again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Jan 2014 20:32:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-issue-command-authorization-failed/m-p/2378149#M89025</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2014-01-13T20:32:00Z</dc:date>
    </item>
  </channel>
</rss>

