<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not able to run any command thru console (Command authorization failed) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/not-able-to-run-any-command-thru-console-command-authorization/m-p/3196112#M1065620</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At first glance, your problem looks like to be user privilege&amp;nbsp;on ACS. As per your description you only upgrade the ASA but make sure everything is ok on ACS. Maybe you can delete ASA as client on ACS and add it again. Do the same for your user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;This can be some syncronization isseu between two platforms after upgrade..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2017 18:11:57 GMT</pubDate>
    <dc:creator>Flavio Miranda</dc:creator>
    <dc:date>2017-10-09T18:11:57Z</dc:date>
    <item>
      <title>Not able to run any command thru console (Command authorization failed)</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-run-any-command-thru-console-command-authorization/m-p/3195973#M1065619</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I currently upgraded the IOS of the firewall 5540.&lt;/P&gt;
&lt;P&gt;Prior to the upgrade, I deleted the aaa commands in case I could get locked once it rebooted.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;no aaa authentication serial console TACACS+ LOCAL&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;no aaa authentication enable console TACACS+ LOCAL&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;no aaa authorization command TACACS+ LOCAL&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TACACS+ refers to the ACS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After the upgrade, I added the aaa commands back and noticed that I couldn't run any command on console and got this error message&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;enc-wups-ex-vpnasa5540-1/act# sh run&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Command authorization failed&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I typed any command, I got that error message.&lt;/P&gt;
&lt;P&gt;If I removed "&lt;SPAN&gt;&lt;STRONG&gt;aaa authorization command TACACS+ LOCAL&lt;/STRONG&gt;" I could run any command on console.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And,&amp;nbsp;I could run any command thru SSH having those aaa commands.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My colleague resolved this issue. He said&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;remove it and logg off console&lt;/P&gt;
&lt;P&gt;then add it from ssh&lt;/P&gt;
&lt;P&gt;and then login&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I'm not sure when he said "remove it and logg off console"&lt;/P&gt;
&lt;P&gt;Did he remove it on console? If he did, how could he remove it although he couldn't run any command?&lt;/P&gt;
&lt;P&gt;Maybe he used local username?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:27:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-run-any-command-thru-console-command-authorization/m-p/3195973#M1065619</guid>
      <dc:creator>ohforce55</dc:creator>
      <dc:date>2020-02-21T14:27:40Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to run any command thru console (Command authorization failed)</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-run-any-command-thru-console-command-authorization/m-p/3196112#M1065620</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;At first glance, your problem looks like to be user privilege&amp;nbsp;on ACS. As per your description you only upgrade the ASA but make sure everything is ok on ACS. Maybe you can delete ASA as client on ACS and add it again. Do the same for your user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;This can be some syncronization isseu between two platforms after upgrade..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 18:11:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-run-any-command-thru-console-command-authorization/m-p/3196112#M1065620</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2017-10-09T18:11:57Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to run any command thru console (Command authorization failed)</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-run-any-command-thru-console-command-authorization/m-p/3196142#M1065621</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your reply.&lt;/P&gt;
&lt;P&gt;When I checked the ACS, there was no any issue.&lt;/P&gt;
&lt;P&gt;I don't think this is the privilege issue as well because I could run any command before the upgrade with the credential.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 19:11:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-run-any-command-thru-console-command-authorization/m-p/3196142#M1065621</guid>
      <dc:creator>ohforce55</dc:creator>
      <dc:date>2017-10-09T19:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to run any command thru console (Command authorization failed)</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-run-any-command-thru-console-command-authorization/m-p/3197276#M1065622</link>
      <description>&lt;P&gt;Hi&amp;nbsp; ohforce55,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you checked the event logs at ACS? that will give you a good idea that why ACS is unauthorizing you to enter any command.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 18:36:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-run-any-command-thru-console-command-authorization/m-p/3197276#M1065622</guid>
      <dc:creator>Spooster IT Services</dc:creator>
      <dc:date>2017-10-11T18:36:19Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to run any command thru console (Command authorization failed)</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-run-any-command-thru-console-command-authorization/m-p/3197277#M1065623</link>
      <description>&lt;P&gt;Hi&amp;nbsp; ohforce55,&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;Have you checked the event logs at ACS? that will give you a good idea that why ACS is unauthorizing you to enter any command.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Oct 2017 18:37:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-run-any-command-thru-console-command-authorization/m-p/3197277#M1065623</guid>
      <dc:creator>Spooster IT Services</dc:creator>
      <dc:date>2017-10-11T18:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: Not able to run any command thru console (Command authorization failed)</title>
      <link>https://community.cisco.com/t5/network-security/not-able-to-run-any-command-thru-console-command-authorization/m-p/3198358#M1065624</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There wasn't even the log for it since I couldn't run any command.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 14:26:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/not-able-to-run-any-command-thru-console-command-authorization/m-p/3198358#M1065624</guid>
      <dc:creator>ohforce55</dc:creator>
      <dc:date>2017-10-13T14:26:01Z</dc:date>
    </item>
  </channel>
</rss>

