<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Tacacs+ authorization failed in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-authorization-failed/m-p/2410368#M96462</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is difficult to tell from the logs what the problem is. Perhaps we could give better advice if you would post configuration (at least the aaa portion) of the switch having a problem and from a switch that is working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 18 Nov 2013 02:06:16 GMT</pubDate>
    <dc:creator>Richard Burts</dc:creator>
    <dc:date>2013-11-18T02:06:16Z</dc:date>
    <item>
      <title>Tacacs+ authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authorization-failed/m-p/2410367#M96461</link>
      <description>&lt;P&gt;Dear All:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; We have a trouble about the Tacace Authorization was not working on the small part of the 2960 switch ,if I &lt;STRONG&gt;show run int f0/1&lt;/STRONG&gt;、&lt;STRONG&gt;show authentication sessions int f0/1 &lt;/STRONG&gt; on the Switch of 2960 ,the log display "&lt;STRONG&gt;% Authorization failed&lt;/STRONG&gt;.",but the other commards and other type of network device are works fine.it very strange. there are 2960 version and ACS version as follow:&lt;/P&gt;&lt;P&gt;1. 2960: 15.0(2)SE2、12.2(55)SE5、12.2(55)SE6&lt;/P&gt;&lt;P&gt;2.ACS:Release 4.2(1) Build 15 Patch 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; I believe acs server failure of certainly,but in the acs I can't find any error message and tacacs logging ,is that a bug? thx!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is debuging:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;authorization failed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:54.416 China: AAA: parse name=tty2 idb type=-1 tty=-1&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:54.416 China: AAA: name=tty2 flags=0x11 type=5 shelf=0 slot=0 adapter=0 port=2 channel=0&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:54.416 China: AAA/MEMORY: create_user (0x3B80FFC) user='ABCD' ruser='WHN00S8' ds0=0 port='tty2' rem_addr='192.168.10.10' authen_type=ASCII service=NONE priv=15 initial_task_id='0', vrf= (id=0) key=DCCAA7AF &lt;/P&gt;&lt;P&gt;.Oct 21 15:28:54.416 China: tty2 AAA/AUTHOR/CMD (2700905137): Port='tty2' list='' service=CMD&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:54.416 China: AAA/AUTHOR/CMD: tty2 (2700905137) user='ABCD'&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:54.416 China: tty2 AAA/AUTHOR/CMD (2700905137): send AV service=shell&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:54.416 China: tty2 AAA/AUTHOR/CMD (2700905137): send AV cmd=show&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:54.416 China: tty2 AAA/AUTHOR/CMD (2700905137): send AV cmd-arg=running-config&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:54.416 China: tty2 AAA/AUTHOR/CMD (2700905137): send AV cmd-arg=interface&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:54.416 China: tty2 AAA/AUTHOR/CMD (2700905137): send AV cmd-arg=FastEthernet&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:54.416 China: tty2 AAA/AUTHOR/CMD (2700905137): send AV cmd-arg=0/1&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:54.416 China: tty2 AAA/AUTHOR/CMD (2700905137): send AV cmd-arg=&amp;lt;cr&amp;gt;&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:54.416 China: tty2 AAA/AUTHOR/CMD (2700905137): found list "default"&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:54.416 China: tty2 AAA/AUTHOR/CMD (2700905137): Method=tacacs+ (tacacs+)&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:54.416 China: AAA/AUTHOR/TAC+: (2700905137): user=ABCD&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:54.416 China: AAA/AUTHOR/TAC+: (2700905137): send AV service=shell&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:54.416 China: AAA/AUTHOR/TAC+: (2700905137): send AV cmd=show&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:54.416 China: AAA/AUTHOR/TAC+: (2700905137): send AV cmd-arg=running-config&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:54.416 China: AAA/AUTHOR/TAC+: (2700905137): send AV cmd-arg=interface&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:54.416 China: AAA/AUTHOR/TAC+: (2700905137): send AV cmd-arg=FastEthernet&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:54.416 China: AAA/AUTHOR/TAC+: (2700905137): send AV cmd-arg=0/1&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:54.416 China: AAA/AUTHOR/TAC+: (2700905137): send AV cmd-arg=&amp;lt;cr&amp;gt;&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:59.566 China: AAA/AUTHOR (2700905137): Post authorization status = ERROR&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:59.566 China: tty2 AAA/AUTHOR/CMD (2700905137): Method=LOCAL&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:59.566 China: AAA/AUTHOR/LOCAL: no entry for ABCD&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;.Oct 21 15:28:59.566 China: AAA/AUTHOR (2700905137): Post authorization status = ERROR&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:59.566 China: tty2 AAA/AUTHOR/CMD (2700905137): Method=NOT_SET&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:59.566 China: tty2 AAA/AUTHOR/CMD (2700905137): no methods left to try&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;.Oct 21 15:28:59.566 China: AAA/AUTHOR (2700905137): Post authorization status = ERROR&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;.Oct 21 15:28:59.566 China: AAA/MEMORY: free_user (0x3B80FFC) user='ABCD' ruser='WHN00S8' port='tty2' rem_addr='192.168.10.10' authen_type=ASCII service=NONE priv=15&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Normal: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;.Oct 21 15:50:22.142 China: AAA: parse name=tty2 idb type=-1 tty=-1&lt;/P&gt;&lt;P&gt;.Oct 21 15:50:22.142 China: AAA: name=tty2 flags=0x11 type=5 shelf=0 slot=0 adapter=0 port=2 channel=0&lt;/P&gt;&lt;P&gt;.Oct 21 15:50:22.142 China: AAA/MEMORY: create_user (0x3B81044) user='ABCD' ruser='WHN00S8' ds0=0 port='tty2' rem_addr='192.168.10.10' authen_type=ASCII service=NONE priv=15 initial_task_id='0', vrf= (id=0) key=9718AC2E &lt;/P&gt;&lt;P&gt;.Oct 21 15:50:22.142 China: tty2 AAA/AUTHOR/CMD (3465703407): Port='tty2' list='' service=CMD&lt;/P&gt;&lt;P&gt;.Oct 21 15:50:22.142 China: AAA/AUTHOR/CMD: tty2 (3465703407) user='ABCD'&lt;/P&gt;&lt;P&gt;.Oct 21 15:50:22.142 China: tty2 AAA/AUTHOR/CMD (3465703407): send AV service=shell&lt;/P&gt;&lt;P&gt;.Oct 21 15:50:22.142 China: tty2 AAA/AUTHOR/CMD (3465703407): send AV cmd=show&lt;/P&gt;&lt;P&gt;.Oct 21 15:50:22.142 China: tty2 AAA/AUTHOR/CMD (3465703407): send AV cmd-arg=running-config&lt;/P&gt;&lt;P&gt;.Oct 21 15:50:22.142 China: tty2 AAA/AUTHOR/CMD (3465703407): send AV cmd-arg=&amp;lt;cr&amp;gt;&lt;/P&gt;&lt;P&gt;.Oct 21 15:50:22.142 China: tty2 AAA/AUTHOR/CMD (3465703407): found list "default"&lt;/P&gt;&lt;P&gt;.Oct 21 15:50:22.142 China: tty2 AAA/AUTHOR/CMD (3465703407): Method=tacacs+ (tacacs+)&lt;/P&gt;&lt;P&gt;.Oct 21 15:50:22.142 China: AAA/AUTHOR/TAC+: (3465703407): user=ABCD&lt;/P&gt;&lt;P&gt;.Oct 21 15:50:22.142 China: AAA/AUTHOR/TAC+: (3465703407): send AV service=shell&lt;/P&gt;&lt;P&gt;.Oct 21 15:50:22.142 China: AAA/AUTHOR/TAC+: (3465703407): send AV cmd=show&lt;/P&gt;&lt;P&gt;.Oct 21 15:50:22.142 China: AAA/AUTHOR/TAC+: (3465703407): send AV cmd-arg=running-config&lt;/P&gt;&lt;P&gt;.Oct 21 15:50:22.142 China: AAA/AUTHOR/TAC+: (3465703407): send AV cmd-arg=&amp;lt;cr&amp;gt;&lt;/P&gt;&lt;P&gt;.Oct 21 15:50:22.369 China: AAA/AUTHOR (3465703407): Post authorization status = PASS_ADD&lt;/P&gt;&lt;P&gt;.Oct 21 15:50:22.369 China: AAA/MEMORY: free_user (0x3B81044) user='ABCD' ruser='WHN00S8' port='tty2' rem_addr='192.168.10.10' authen_type=ASCII service=NONE priv=15&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:05:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authorization-failed/m-p/2410367#M96461</guid>
      <dc:creator>Cheng Chen</dc:creator>
      <dc:date>2019-03-11T04:05:39Z</dc:date>
    </item>
    <item>
      <title>Tacacs+ authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authorization-failed/m-p/2410368#M96462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is difficult to tell from the logs what the problem is. Perhaps we could give better advice if you would post configuration (at least the aaa portion) of the switch having a problem and from a switch that is working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Nov 2013 02:06:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authorization-failed/m-p/2410368#M96462</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2013-11-18T02:06:16Z</dc:date>
    </item>
    <item>
      <title>Tacacs+ authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authorization-failed/m-p/2410369#M96463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where exactly are you looking for logs? Did you check under reports and activities &amp;gt; tacacs administration.&lt;/P&gt;&lt;P&gt;Also, please provide the output of &lt;STRONG&gt;"show run | in aaa"&lt;/STRONG&gt; and &lt;STRONG&gt;"show run | begin line"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~BR &lt;BR /&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;**Do rate helpful posts**&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Nov 2013 07:27:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authorization-failed/m-p/2410369#M96463</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-11-18T07:27:49Z</dc:date>
    </item>
    <item>
      <title>Tacacs+ authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authorization-failed/m-p/2410370#M96464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Rick,there are our all devices standard configuration about aaa section, as a result of ACS 4.2 was end of support ，we can't open a case with cisco ,it's very rascally,but I can found some important message from the "ACS→System Configuration→Support":&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS 11/14/2013 14:47:09 I 0043 6768 0x0 &amp;lt;&amp;lt;&amp;lt; RECEIVED FROM CLIENT:WHN_Office TYPE=AUTHOR, SEQ=1, FLAGS=1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS 11/14/2013 14:47:09 I 0043 6768 0x0 SESSIONID 108458144 (0x676f0a0), DATALEN 143 (0x8f)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS 11/14/2013 14:47:09 I 0043 6768 0x0 type=AUTHOR, priv_lvl=15, authen=1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS 11/14/2013 14:47:09 I 0043 6768 0x0 METHOD=none&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS 11/14/2013 14:47:09 I 0043 6768 0x0 SVC=0 USER_LEN=7 PORT_LEN=4 REM_ADDR_LEN=14 ARG_CNT=7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS 11/14/2013 14:47:09 I 0043 6768 0x0 USER=TXW7401&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS 11/14/2013 14:47:09 I 0043 6768 0x0 PORT=tty1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS 11/14/2013 14:47:09 I 0043 6768 0x0 REM_ADDR=172.31.132.246&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS 11/14/2013 14:47:09 I 0043 6768 0x0 arg[0](size=13)=service=shell&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS 11/14/2013 14:47:09 I 0043 6768 0x0 arg[1](size=8)=cmd=show&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS 11/14/2013 14:47:09 I 0043 6768 0x0 arg[2](size=22)=cmd-arg=running-config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS 11/14/2013 14:47:09 I 0043 6768 0x0 arg[3](size=17)=cmd-arg=interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS 11/14/2013 14:47:09 I 0043 6768 0x0 arg[4](size=20)=cmd-arg=FastEthernet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS 11/14/2013 14:47:09 I 0043 6768 0x0 arg[5](size=11)=cmd-arg=0/1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS 11/14/2013 14:47:09 I 0043 6768 0x0 arg[6](size=12)=cmd-arg=&lt;CR&gt;&lt;/CR&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS 11/14/2013 14:47:09 I 0043 6768 0x0 END &amp;gt;&amp;gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TCS 11/14/2013 14:47:09 I 0043 4880 0x82ee &amp;lt;&amp;lt;&amp;lt; PACKET TO CLIENT:WHN_Office TYPE:AUTHOR/PASS_ADD, SEQ 2, FLAGS 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS 11/14/2013 14:47:09 I 0043 4880 0x82ee SESSIONID 108458144 (0x676f0a0), DATALEN 6 (0x6)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS 11/14/2013 14:47:09 I 0043 4880 0x82ee type=AUTHOR/REPLY status=1 (AUTHOR/PASS_ADD) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS 11/14/2013 14:47:09 I 0043 4880 0x82ee msg_len=0, data_len=0 arg_cnt=0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCS 11/14/2013 14:47:09 I 0043 4880 0x82ee End &amp;gt;&amp;gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;base on these above messages,acs received messages from client ,it had authenticated the commands and authorized. but the switch display authorization failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa section：&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication login console local&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local &lt;/P&gt;&lt;P&gt;aaa authorization commands 0 default group tacacs+ local &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ local &lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 0 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;chencheng&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Nov 2013 12:07:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authorization-failed/m-p/2410370#M96464</guid>
      <dc:creator>Cheng Chen</dc:creator>
      <dc:date>2013-11-18T12:07:52Z</dc:date>
    </item>
    <item>
      <title>Tacacs+ authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authorization-failed/m-p/2410371#M96465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sir:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; In the acs server ,I can found authorize passd commad only from tacacs administrator,but the failed logs was not in here. thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication login console local&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local &lt;/P&gt;&lt;P&gt;aaa authorization commands 0 default group tacacs+ local &lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ local &lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 0 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt; exec-timeout 30 0&lt;/P&gt;&lt;P&gt; login authentication console&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt; exec-timeout 30 0&lt;/P&gt;&lt;P&gt; transport input all&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; access-class 30 in&lt;/P&gt;&lt;P&gt; exec-timeout 30 0&lt;/P&gt;&lt;P&gt; transport input telnet&lt;/P&gt;&lt;P&gt;line vty 5 15&lt;/P&gt;&lt;P&gt; access-class 10 in&lt;/P&gt;&lt;P&gt; exec-timeout 30 0&lt;/P&gt;&lt;P&gt; transport input telnet&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Nov 2013 12:13:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authorization-failed/m-p/2410371#M96465</guid>
      <dc:creator>Cheng Chen</dc:creator>
      <dc:date>2013-11-18T12:13:34Z</dc:date>
    </item>
    <item>
      <title>Tacacs+ authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authorization-failed/m-p/2410372#M96466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;chencheng&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is surprising that the logs from the server show that it did authorize the command but that the switch is showing failure. Is this happening consistently all the time or is it an occasional problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wonder if it is significant that the switch is not logging authorization error but is indicating "post authorization"&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;China: AAA/AUTHOR (2700905137): Post authorization status = ERROR&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do have one suggestion for you to try. Would you change this line&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ local &lt;/P&gt;&lt;P&gt;and make it like this&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ if-authenticated &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Nov 2013 13:16:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authorization-failed/m-p/2410372#M96466</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2013-11-18T13:16:11Z</dc:date>
    </item>
    <item>
      <title>Tacacs+ authorization failed</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-authorization-failed/m-p/2410373#M96468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HeHe，Yes，It's surprising. this log happened on a few swtich of 2960,and the other device working fine.but I'm sure that it was acs out of the fault.by the way,I'm adopt your suggestings and try again .if the issue solve ,I will be inform you.thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;chencheng&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Nov 2013 14:30:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-authorization-failed/m-p/2410373#M96468</guid>
      <dc:creator>Cheng Chen</dc:creator>
      <dc:date>2013-11-18T14:30:46Z</dc:date>
    </item>
  </channel>
</rss>

