<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi,When you say u can not in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ssh-after-acs-server-quot-locked-up-quot-and-had-to-be/m-p/2545959#M90024</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;When you say u can not access device remotely are you not able to ssh to device or there is no rechablity itself?&lt;/P&gt;&lt;P&gt;Is ssh is the problem then do you get a login prompt? Any error message? Also have you checked ACS failed logs for any messages?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Najaf&lt;/P&gt;</description>
    <pubDate>Thu, 12 Jun 2014 02:17:25 GMT</pubDate>
    <dc:creator>kcnajaf</dc:creator>
    <dc:date>2014-06-12T02:17:25Z</dc:date>
    <item>
      <title>ssh after ACS server "locked up" and had to be reconfigured no longer works.</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-after-acs-server-quot-locked-up-quot-and-had-to-be/m-p/2545958#M90023</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a VPN tunnel between an ASA5520 and a Cisco 891.&lt;/P&gt;&lt;P&gt;I had the 891 configured with the following:&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ VTY&lt;BR /&gt;&amp;nbsp;ip tacacs source-interface Loopback0&lt;BR /&gt;!&lt;BR /&gt;aaa group server tacacs+ TACACS-ACS&lt;BR /&gt;&amp;nbsp;server 10.8.x.x&lt;BR /&gt;&amp;nbsp;server 10.16.y.x&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login CONSOLE none&lt;BR /&gt;aaa authentication login VTY group tacacs+ local&lt;BR /&gt;aaa authorization exec VTY group tacacs+ local&lt;BR /&gt;aaa authorization commands 0 VTY group tacacs+&lt;BR /&gt;aaa authorization commands 15 VTY group tacacs+&lt;BR /&gt;aaa accounting commands 15 VTY start-stop group tacacs+&lt;BR /&gt;aaa accounting commands 15 CONSOLE start-stop group tacacs+&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip tacacs source-interface Loopback0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;tacacs-server host 10.8.x.x key 7 yadayadayadayada&lt;BR /&gt;tacacs-server host 10.16.y.x key 7 yadayadayadayada&lt;BR /&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;BR /&gt;&amp;nbsp;access-class 1 in&lt;BR /&gt;&amp;nbsp;authorization commands 15 VTY&lt;BR /&gt;&amp;nbsp;authorization exec VTY&lt;BR /&gt;&amp;nbsp;accounting commands 15 VTY&lt;BR /&gt;&amp;nbsp;login authentication VTY&lt;BR /&gt;&amp;nbsp;transport input ssh&lt;BR /&gt;line vty 5 15&lt;BR /&gt;&amp;nbsp;access-class 1 in&lt;BR /&gt;&amp;nbsp;authorization commands 15 VTY&lt;BR /&gt;&amp;nbsp;authorization exec VTY&lt;BR /&gt;&amp;nbsp;accounting commands 15 VTY&lt;BR /&gt;&amp;nbsp;login authentication VTY&lt;BR /&gt;&amp;nbsp;transport input ssh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I no longer can access device remotely. I am sure it has to do with the ACS server, but not sure where to look.&lt;/P&gt;&lt;P&gt;Any help would be&amp;nbsp; greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:47:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-after-acs-server-quot-locked-up-quot-and-had-to-be/m-p/2545958#M90023</guid>
      <dc:creator>Steve Coady</dc:creator>
      <dc:date>2019-03-11T04:47:11Z</dc:date>
    </item>
    <item>
      <title>Hi,When you say u can not</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-after-acs-server-quot-locked-up-quot-and-had-to-be/m-p/2545959#M90024</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;When you say u can not access device remotely are you not able to ssh to device or there is no rechablity itself?&lt;/P&gt;&lt;P&gt;Is ssh is the problem then do you get a login prompt? Any error message? Also have you checked ACS failed logs for any messages?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Najaf&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2014 02:17:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-after-acs-server-quot-locked-up-quot-and-had-to-be/m-p/2545959#M90024</guid>
      <dc:creator>kcnajaf</dc:creator>
      <dc:date>2014-06-12T02:17:25Z</dc:date>
    </item>
    <item>
      <title>Najaf Thank you for the</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-after-acs-server-quot-locked-up-quot-and-had-to-be/m-p/2545960#M90026</link>
      <description>&lt;P&gt;Najaf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the response.&lt;/P&gt;&lt;P&gt;I mean I have no remote management access. Traffic is passing&lt;/P&gt;&lt;P&gt;This is a new site&lt;/P&gt;&lt;P&gt;I get login prompt&lt;/P&gt;&lt;P&gt;My Active director credentials and my local username/pass do not work.&lt;/P&gt;&lt;P&gt;Both worked prior to the ACS problems with bad sectors on HD. The ACS was reconfigured.&lt;/P&gt;&lt;P&gt;This appears to be the only site that is having trouble.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2014 16:27:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-after-acs-server-quot-locked-up-quot-and-had-to-be/m-p/2545960#M90026</guid>
      <dc:creator>Steve Coady</dc:creator>
      <dc:date>2014-06-12T16:27:50Z</dc:date>
    </item>
    <item>
      <title>Hi,Do you see any failed</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-after-acs-server-quot-locked-up-quot-and-had-to-be/m-p/2545961#M90039</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Do you see any failed authentication logs on ACS?&lt;/P&gt;&lt;P&gt;Where did you manage to get the aaa configuration? Are you using this as a standard template?&lt;/P&gt;&lt;P&gt;Could you try modifying the configuration as below?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;config terminal&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.399999618530273px;"&gt;no aaa group server tacacs+ TACACS-ACS&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.399999618530273px;"&gt;aaa group server tacacs+ VTY&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.399999618530273px;"&gt;&amp;nbsp;server 10.8.x.x&lt;/SPAN&gt;&lt;BR style="font-size: 14.399999618530273px;" /&gt;&lt;SPAN style="font-size: 14.399999618530273px;"&gt;&amp;nbsp;server 10.16.y.x&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.399999618530273px;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.399999618530273px;"&gt;After this verify if tacacs&amp;nbsp;authentication&amp;nbsp;is working fine with below command (hope this command work on your device)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.399999618530273px;"&gt;test aaa group tacacs VTY &amp;lt;username&amp;gt; &amp;lt;password&amp;gt; lega&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.399999618530273px;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.399999618530273px;"&gt;Najaf&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2014 18:04:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-after-acs-server-quot-locked-up-quot-and-had-to-be/m-p/2545961#M90039</guid>
      <dc:creator>kcnajaf</dc:creator>
      <dc:date>2014-06-12T18:04:13Z</dc:date>
    </item>
    <item>
      <title>I get the following  message</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-after-acs-server-quot-locked-up-quot-and-had-to-be/m-p/2545962#M90041</link>
      <description>&lt;P&gt;I get the following&amp;nbsp; message&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attempting authentication test to server-group tacacs+ using tacacs+&lt;/P&gt;&lt;P&gt;*Jun 12 18:19:15.245: %AAA-3-BADSERVERTYPEERROR: Cannot process accounting server type *invalid_group_handle*No authoritative response from any server.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2014 18:21:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-after-acs-server-quot-locked-up-quot-and-had-to-be/m-p/2545962#M90041</guid>
      <dc:creator>Steve Coady</dc:creator>
      <dc:date>2014-06-12T18:21:55Z</dc:date>
    </item>
    <item>
      <title>Hi,This is configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-after-acs-server-quot-locked-up-quot-and-had-to-be/m-p/2545963#M90043</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;This is configuration issue.&lt;/P&gt;&lt;P&gt;Have you added the loop back interface ip of router on to AAA server as a AAA client?&lt;/P&gt;&lt;P&gt;Are the shared key same on both router and aaa?&lt;/P&gt;&lt;P&gt;If both the above are fine the remove the entire aaa configuration and apply them frsh as below.&lt;/P&gt;&lt;P&gt;no aaa new mode&lt;/P&gt;&lt;P&gt;enable password ***********&lt;BR /&gt;username admin privilege 15 password *********&lt;BR /&gt;aaa new-model&amp;nbsp;&lt;BR /&gt;aaa group server tacacs+ VTY&lt;BR /&gt;&amp;nbsp;server 10.8.x.x&lt;BR /&gt;&amp;nbsp;server 10.16.y.x&lt;BR /&gt;aaa authentication login VTY group tacacs+ local&lt;BR /&gt;aaa authentication enable VTY group Tacacs+ enable&lt;/P&gt;&lt;P&gt;tacacs-server host 10.8.x.x key 7 xxxxx (xxxxx should be the same key used in ACS)&lt;BR /&gt;tacacs-server host 10.16.y.x key 7 xxxxx (xxxxx should be the same key used in ACS)&lt;BR /&gt;line vty 0 4&lt;BR /&gt;login authentication VTY&lt;/P&gt;&lt;P&gt;Hope that helps&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Najaf&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2014 18:44:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-after-acs-server-quot-locked-up-quot-and-had-to-be/m-p/2545963#M90043</guid>
      <dc:creator>kcnajaf</dc:creator>
      <dc:date>2014-06-12T18:44:14Z</dc:date>
    </item>
    <item>
      <title>Najaf What about these other</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-after-acs-server-quot-locked-up-quot-and-had-to-be/m-p/2545964#M90044</link>
      <description>&lt;P&gt;Najaf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What about these other commands on the line?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;BR /&gt;&amp;nbsp;access-class 1 in&lt;BR /&gt;&amp;nbsp;authorization commands 15 VTY&lt;BR /&gt;&amp;nbsp;authorization exec VTY&lt;BR /&gt;&amp;nbsp;accounting commands 15 VTY&lt;BR /&gt;&amp;nbsp;login authentication VTY&lt;BR /&gt;&amp;nbsp;transport input ssh&lt;BR /&gt;line vty 5 15&lt;BR /&gt;&amp;nbsp;access-class 1 in&lt;BR /&gt;&amp;nbsp;authorization commands 15 VTY&lt;BR /&gt;&amp;nbsp;authorization exec VTY&lt;BR /&gt;&amp;nbsp;accounting commands 15 VTY&lt;BR /&gt;&amp;nbsp;login authentication VTY&lt;BR /&gt;&amp;nbsp;transport input ssh&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2014 19:01:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-after-acs-server-quot-locked-up-quot-and-had-to-be/m-p/2545964#M90044</guid>
      <dc:creator>Steve Coady</dc:creator>
      <dc:date>2014-06-12T19:01:27Z</dc:date>
    </item>
    <item>
      <title>I wiped it out and</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-after-acs-server-quot-locked-up-quot-and-had-to-be/m-p/2545965#M90047</link>
      <description>&lt;P&gt;I wiped it out and reconfigured as you requested. Still no access.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2014 20:40:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-after-acs-server-quot-locked-up-quot-and-had-to-be/m-p/2545965#M90047</guid>
      <dc:creator>Steve Coady</dc:creator>
      <dc:date>2014-06-12T20:40:25Z</dc:date>
    </item>
    <item>
      <title>I get the following messages</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-after-acs-server-quot-locked-up-quot-and-had-to-be/m-p/2545966#M90049</link>
      <description>&lt;P&gt;I get the following messages when I config line vty 0 4&lt;/P&gt;&lt;P&gt;Cisco891(config-line)# authorization commands 15 VTY&lt;BR /&gt;AAA: Warning authorization list "VTY" is not defined for CMD priv&lt;/P&gt;&lt;P&gt;Cisco891(config-line)# authorization exec VTY&lt;BR /&gt;AAA: Warning authorization list "VTY" is not defined for EXEC&lt;/P&gt;&lt;P&gt;Cisco891(config-line)# accounting commands 15 VTY&lt;BR /&gt;AAA: Warning accounting list "VTY" is not defined for CMD priv 15&lt;/P&gt;&lt;P&gt;Cisco891(config-line)# login authentication VTY&lt;BR /&gt;AAA: Warning authentication list "VTY" is not defined for LOGIN.&lt;/P&gt;&lt;P&gt;Cisco891(config-line)#^Z&lt;BR /&gt;Cisco 891#&lt;BR /&gt;*Jun 12 20:46:00.793: %SYS-5-CONFIG_I: Configured from console by console&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am I doing wrong?!?!?!?!?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2014 20:50:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-after-acs-server-quot-locked-up-quot-and-had-to-be/m-p/2545966#M90049</guid>
      <dc:creator>Steve Coady</dc:creator>
      <dc:date>2014-06-12T20:50:10Z</dc:date>
    </item>
    <item>
      <title>Hi,I wanted you to try</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-after-acs-server-quot-locked-up-quot-and-had-to-be/m-p/2545967#M90050</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I wanted you to try minimum configurations first. Even with out other configuration things should work..&lt;/P&gt;&lt;P&gt;Have you checked at AAA server end to confirm your router IP address is added there and shared key are matching?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Najaf&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jun 2014 01:26:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-after-acs-server-quot-locked-up-quot-and-had-to-be/m-p/2545967#M90050</guid>
      <dc:creator>kcnajaf</dc:creator>
      <dc:date>2014-06-13T01:26:07Z</dc:date>
    </item>
  </channel>
</rss>

