<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TACACS implementation failed in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tacacs-implementation-failed/m-p/1644493#M558757</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Adam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please enable the following debugs on the ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;deb aaa authentication&lt;/P&gt;&lt;P&gt;deb tacacs 255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;run a test aaa and please paste the output of the debugs along with the logs on the ACS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what do the ACS failed attempt logs say?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if there are no records there, then could check for the corresponding entry on the event viewer of windows in case of ACS for windows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this thread as answered if you feel your query is resolved. Do rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Apr 2011 14:18:25 GMT</pubDate>
    <dc:creator>andamani</dc:creator>
    <dc:date>2011-04-01T14:18:25Z</dc:date>
    <item>
      <title>TACACS implementation failed</title>
      <link>https://community.cisco.com/t5/network-security/tacacs-implementation-failed/m-p/1644491#M558752</link>
      <description>&lt;P&gt;&lt;!--[if gte mso 10]&gt;&lt;style&gt; /* Style Definitions */ table.MsoNormalTable {mso-style-name:"Table Normal"; mso-tstyle-rowband-size:0; mso-tstyle-colband-size:0; mso-style-noshow:yes; mso-style-parent:""; mso-padding-alt:0in 5.4pt 0in 5.4pt; mso-para-margin:0in; mso-para-margin-bottom:.0001pt; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; mso-ansi-language:#0400; mso-fareast-language:#0400; mso-bidi-language:#0400;}&lt;/style&gt;&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;!--[if gte mso 10]&gt;&lt;style&gt; /* Style Definitions */ table.MsoNormalTable {mso-style-name:"Table Normal"; mso-tstyle-rowband-size:0; mso-tstyle-colband-size:0; mso-style-noshow:yes; mso-style-parent:""; mso-padding-alt:0in 5.4pt 0in 5.4pt; mso-para-margin:0in; mso-para-margin-bottom:.0001pt; mso-pagination:widow-orphan; font-size:10.0pt; font-family:"Times New Roman"; mso-ansi-language:#0400; mso-fareast-language:#0400; mso-bidi-language:#0400;}&lt;/style&gt;&lt;![endif]--&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt;I’ve been working to enable TACACS on&amp;nbsp; firewall Cisco-ASA-FW. For unknown reason, I can’t authenticate with the&amp;nbsp; ACS server using TACACS id. Therefore, I would appreciate if you could&amp;nbsp; share with me how to troubleshoot and fix this problem. Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt;This is the config of aaa-server.&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P class="MsoNormal" style="line-height: 12pt;"&gt;&lt;SPAN style="color: black;"&gt;Cisco-ASA-FW# &lt;STRONG&gt;sh run aaa-server&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN style="color: black;"&gt;aaa-server TACACS+ protocol tacacs+&lt;/SPAN&gt;&lt;SPAN style="color: black;"&gt;&lt;BR /&gt;aaa-server TACACS+ (inside) host &lt;STRONG&gt;192.168.1.1&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="color: black;"&gt;&lt;BR /&gt;timeout 5&lt;/SPAN&gt;&lt;SPAN style="color: black;"&gt;&lt;BR /&gt;key ******&lt;/SPAN&gt;&lt;SPAN style="color: black;"&gt;&lt;BR /&gt;aaa-server TACACS+ (inside) host &lt;STRONG&gt;192.168.1.2&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;P class="MsoNormal" style="line-height: 12pt;"&gt;&lt;SPAN style="color: black;"&gt;timeout 5&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: 12pt;"&gt;&lt;SPAN style="color: black;"&gt;key ******&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: 12pt;"&gt;&lt;SPAN style="color: black;"&gt;Cisco-ASA-FW#&lt;/SPAN&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: 12pt;"&gt;&lt;SPAN style="color: black;"&gt;I did a testing on aaa-server&amp;nbsp; authentication, however the Authentication Server not responding.&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P class="MsoNormal" style="line-height: 12pt;"&gt;&lt;SPAN style="color: black;"&gt;Cisco-ASA-FW# &lt;STRONG&gt;test aaa-server authentication TACACS+&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN style="color: black;"&gt;Server IP Address or name: &lt;STRONG&gt;192.168.1.1&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="color: black;"&gt;&lt;BR /&gt;Username: &lt;STRONG&gt;networker&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="color: black;"&gt;&lt;BR /&gt;Password: &lt;STRONG&gt;**********&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;INFO: Attempting Authentication test to IP address &amp;lt;192.168.1.1&amp;gt;&lt;/SPAN&gt;&lt;SPAN style="color: black;"&gt;(timeout: 10 seconds)&lt;/SPAN&gt;&lt;P class="MsoNormal" style="line-height: 12pt;"&gt;&lt;STRONG style="color: red; "&gt;ERROR: Authentication Server not responding: No error&lt;/STRONG&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: 12pt;"&gt;&lt;SPAN style="color: black;"&gt;Cisco-ASA-FW#&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: 12pt;"&gt;&lt;SPAN style="color: black;"&gt;Cisco-ASA-FW# &lt;STRONG&gt;test aaa-server authentication TACACS+&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: 12pt;"&gt;&lt;SPAN style="color: black;"&gt;Server IP Address or name: &lt;STRONG&gt;192.168.1.2&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: 12pt;"&gt;&lt;SPAN style="color: black;"&gt;Username: &lt;STRONG&gt;networker&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: 12pt;"&gt;&lt;SPAN style="color: black;"&gt;Password: &lt;STRONG&gt;**********&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="line-height: 12pt;"&gt;&lt;SPAN style="color: black;"&gt;INFO: Attempting Authentication test to IP address &amp;lt;192.168.1.2&amp;gt;(timeout: 10 seconds)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: red; "&gt;ERROR: Authentication Server not responding: No error&lt;/STRONG&gt;&lt;SPAN style="color: black;"&gt;&lt;BR /&gt;Cisco-ASA-FW#&lt;/SPAN&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I did a further checking on the firewall and found this.&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;Cisco-ASA-FW#sh log | i &lt;SPAN style="font-size: 10pt;"&gt;192.168.1.1&lt;/SPAN&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt;"&gt;Mar 31 2011&lt;/SPAN&gt; &lt;SPAN style="font-size: 10pt;"&gt;09:39:07 10.10.10.10 : %ASA-2-113023: AAA Marking TACACS+ server 192.168.1.1 in aaa-server group TACACS+ as ACTIVE&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;Mar 31 2011&lt;/SPAN&gt; &lt;SPAN style="font-size: 10pt;"&gt;10:02:46 10.10.10.10 : %ASA-2-113022: AAA Marking TACACS+ server 192.168.1.1 in aaa-server group TACACS+ as&lt;STRONG style="color: red; "&gt;FAILED&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;Mar 31 2011&lt;/SPAN&gt; 10:13:07 10.10.10.10 : %ASA-2-113023: AAA Marking TACACS+ server 192.168.1.1 in aaa-server group &lt;SPAN style="font-size: 10pt;"&gt;TACACS+ as ACTIVE&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt;"&gt;Mar 31 2011&lt;/SPAN&gt; &lt;SPAN style="font-size: 10pt;"&gt;10:36:17 10.10.10.10 : %ASA-2-113022: AAA Marking TACACS+ server 192.168.1.1 in aaa-server group TACACS+ as &lt;STRONG style="color: red; "&gt;FAILED&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;This is the log that I found on syslog server&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN&gt;UNIX-Server{networker}: tail -f logfile | grep Cisco-ASA-FW | grep 192.168.1.1&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN&gt;Mar 31 10&lt;/SPAN&gt;:10:23 Cisco-ASA-FW Apr 01 2011 10:10:23 &lt;STRONG style="background: none repeat scroll 0% 0% yellow; "&gt;10.10.10.10&lt;/STRONG&gt; : %ASA-6-302013: &lt;STRONG&gt;Built&lt;/STRONG&gt; &lt;STRONG&gt;outbound TCP connection&lt;/STRONG&gt; 4036746 for &lt;STRONG style="background: none repeat scroll 0% 0% yellow; "&gt;inside:192.168.1.1&lt;/STRONG&gt;/49 (192.168.1.1/49) &lt;STRONG style="background: none repeat scroll 0% 0% yellow; "&gt;to identity:172.16.10.10&lt;/STRONG&gt;/39567 &lt;SPAN&gt;(172.16.10.10/39567)&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;SPAN&gt;Mar 31 10&lt;/SPAN&gt;:10:23 Cisco-ASA-FW Apr 01 2011 10:10:23 &lt;STRONG style="background: none repeat scroll 0% 0% yellow; "&gt;10.10.10.10&lt;/STRONG&gt; : %ASA-6-&lt;STRONG style="background: none repeat scroll 0% 0% yellow; "&gt;110003: Routing failed to locate next hop for TCP from identity:172.16.10.10&lt;/STRONG&gt;/39567&lt;SPAN&gt;&lt;STRONG style="background: none repeat scroll 0% 0% yellow; "&gt;to inside:192.168.1.1&lt;/STRONG&gt;/49&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;SPAN&gt;Mar 31 10&lt;/SPAN&gt;:12:08 Cisco-ASA-FW Apr 01 2011 10:12:08 10.10.10.10 : %ASA-6-302013: Built outbound TCP connection 4036779 for inside:192.168.1.1/49 (192.168.1.1/49) to &lt;SPAN&gt;identity:172.16.10.10/31388 (172.16.10.10/31388)&lt;/SPAN&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;SPAN&gt;Mar 31 10&lt;/SPAN&gt;:12:08 Cisco-ASA-FW Apr 01 2011 10:12:08 10.10.10.10 : %ASA-6-110003: Routing failed to locate next hop for TCP from identity:172.16.10.10/31388 to &lt;SPAN&gt;inside:192.168.1.1/49&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;Based on the error message above, I've found this info from Cisco website.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;&lt;style&gt;&lt;!==mce:3--&gt; &lt;/P&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:15:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tacacs-implementation-failed/m-p/1644491#M558752</guid>
      <dc:creator>Adam David</dc:creator>
      <dc:date>2019-03-11T20:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS implementation failed</title>
      <link>https://community.cisco.com/t5/network-security/tacacs-implementation-failed/m-p/1644492#M558756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Adam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please show/check the outputs of the interface ip addresses and the routing table on the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It appears that the TACACS servers are not in a directly connected subnet.&lt;/P&gt;&lt;P&gt;Has a static route been defined to that subnet on the inside interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"show route" will show the routing table. Check if there is a route to the Tacacs subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To configure a static route:&lt;/P&gt;&lt;P&gt;route inside 192.168.1.0 255.255.255.0 &lt;NEXT hop="" ip=""&gt;&lt;/NEXT&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Shrikant&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;P.S.: Please mark the question resolved if it has been answered. Do rate helpful posts. Thanks.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Apr 2011 12:49:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tacacs-implementation-failed/m-p/1644492#M558756</guid>
      <dc:creator>Shrikant Sundaresh</dc:creator>
      <dc:date>2011-04-01T12:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS implementation failed</title>
      <link>https://community.cisco.com/t5/network-security/tacacs-implementation-failed/m-p/1644493#M558757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Adam,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please enable the following debugs on the ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;deb aaa authentication&lt;/P&gt;&lt;P&gt;deb tacacs 255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;run a test aaa and please paste the output of the debugs along with the logs on the ACS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what do the ACS failed attempt logs say?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if there are no records there, then could check for the corresponding entry on the event viewer of windows in case of ACS for windows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this thread as answered if you feel your query is resolved. Do rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Apr 2011 14:18:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tacacs-implementation-failed/m-p/1644493#M558757</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-04-01T14:18:25Z</dc:date>
    </item>
  </channel>
</rss>

