<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HTTP authentication problem using Tacacs in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/http-authentication-problem-using-tacacs/m-p/1369285#M821937</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The result is clear according to Packet Tracer...&lt;/P&gt;&lt;P&gt;The connection is being denied by the ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Troubleshooting step:&lt;/P&gt;&lt;P&gt;Check the ACL applied to the interface where you're coming from, and make sure that such traffic is being permitted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question: Is this traffic intended to the ASA itself or through the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 09 Mar 2010 20:18:06 GMT</pubDate>
    <dc:creator>Federico Coto Fajardo</dc:creator>
    <dc:date>2010-03-09T20:18:06Z</dc:date>
    <item>
      <title>HTTP authentication problem using Tacacs</title>
      <link>https://community.cisco.com/t5/network-security/http-authentication-problem-using-tacacs/m-p/1369284#M821933</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to use SSH and HTTP to get authentication through ACS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am facing issue with only http authentication through ACS(Tacacs+).&lt;/P&gt;&lt;P&gt;when try to connect ASDM using tacacs+ authentication, the A/C gets locked in radius server.&lt;/P&gt;&lt;P&gt;At the same time SSh works fine&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS is mapped with RADIUS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have attached the HTTP and SSh related config&lt;/P&gt;&lt;P&gt;======================&lt;/P&gt;&lt;P&gt;aaa-server Two-Factor protocol tacacs+&lt;BR /&gt;aaa-server Two-Factor (Layer-3) host Cisco-ACS key abcd&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication enable console LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication http console Two-Factor&lt;BR /&gt;aaa authentication ssh console Two-Factor&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh Vikram_Shetty 255.255.255.255 Layer-3&lt;/P&gt;&lt;P&gt;http Vikram_Shetty 255.255.255.255 Layer-3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;========================================&lt;/P&gt;&lt;P&gt;Also attached the some troubleshooting output which i done, not sure if the method is correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried checking packet tracer and found the user PC with port http to acs ip on port http is getting droped due to ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;packet-tracer input layer-3 tcp 10.26.14.50 http 10.26.11.134 ht$&lt;BR /&gt; &lt;BR /&gt;Phase: 1&lt;BR /&gt;Type: FLOW-LOOKUP&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Found no matching flow, creating a new flow&lt;BR /&gt; &lt;BR /&gt;Phase: 2&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in&amp;nbsp;&amp;nbsp; Layer-3_All&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.248.0&amp;nbsp;&amp;nbsp; Layer-3&lt;BR /&gt; &lt;BR /&gt;Phase: 3&lt;BR /&gt;Type: ROUTE-LOOKUP&lt;BR /&gt;Subtype: input&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;in&amp;nbsp;&amp;nbsp; Layer-3_All&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 255.255.248.0&amp;nbsp;&amp;nbsp; Layer-3&lt;BR /&gt; &lt;BR /&gt;Phase: 4&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt; Forward Flow based lookup yields rule:&lt;BR /&gt; in&amp;nbsp; id=0x54d99b8, priority=111, domain=permit, deny=true&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hits=6077, user_data=0x0, cs_id=0x0, flags=0x4000, protocol=0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; src ip=0.0.0.0, mask=0.0.0.0, port=0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dst ip=0.0.0.0, mask=0.0.0.0, port=0, dscp=0x0&lt;BR /&gt; &lt;BR /&gt;Result:&lt;BR /&gt;input-interface: Layer-3&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: Layer-3&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule&lt;/P&gt;&lt;P&gt;===========================================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to open ASDM&amp;nbsp; https is being used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if i am not clear..need help to trace the root cause.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Amar&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:18:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-authentication-problem-using-tacacs/m-p/1369284#M821933</guid>
      <dc:creator>madhusudhan s</dc:creator>
      <dc:date>2019-03-11T17:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP authentication problem using Tacacs</title>
      <link>https://community.cisco.com/t5/network-security/http-authentication-problem-using-tacacs/m-p/1369285#M821937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The result is clear according to Packet Tracer...&lt;/P&gt;&lt;P&gt;The connection is being denied by the ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Troubleshooting step:&lt;/P&gt;&lt;P&gt;Check the ACL applied to the interface where you're coming from, and make sure that such traffic is being permitted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question: Is this traffic intended to the ASA itself or through the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Mar 2010 20:18:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-authentication-problem-using-tacacs/m-p/1369285#M821937</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-03-09T20:18:06Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP authentication problem using Tacacs</title>
      <link>https://community.cisco.com/t5/network-security/http-authentication-problem-using-tacacs/m-p/1369286#M821942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does asdm access work without the ACS with just local credentials?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authen http console LOCAL&lt;/P&gt;&lt;P&gt;username blah password blah priv 15&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Give it a shot and let us know.&lt;/P&gt;&lt;P&gt;Also, post the output of "sh run http"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Mar 2010 20:45:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-authentication-problem-using-tacacs/m-p/1369286#M821942</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-03-09T20:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP authentication problem using Tacacs</title>
      <link>https://community.cisco.com/t5/network-security/http-authentication-problem-using-tacacs/m-p/1369287#M821948</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes the http(asdm) work fine with local credential.&lt;/P&gt;&lt;P&gt;I have attached http configuration in first log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Amar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Mar 2010 04:08:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-authentication-problem-using-tacacs/m-p/1369287#M821948</guid>
      <dc:creator>madhusudhan s</dc:creator>
      <dc:date>2010-03-10T04:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP authentication problem using Tacacs</title>
      <link>https://community.cisco.com/t5/network-security/http-authentication-problem-using-tacacs/m-p/1369288#M821953</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question: Is this traffic intended to the ASA itself or through the ASA ?&lt;/P&gt;&lt;P&gt;Ans: Http allowed subnet are in one zone and the ACS/Radius in other zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is what you are asking, I am not very clear with above query.. Pls elaborate..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Amar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Mar 2010 04:31:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-authentication-problem-using-tacacs/m-p/1369288#M821953</guid>
      <dc:creator>madhusudhan s</dc:creator>
      <dc:date>2010-03-10T04:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP authentication problem using Tacacs</title>
      <link>https://community.cisco.com/t5/network-security/http-authentication-problem-using-tacacs/m-p/1369289#M821968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I was asking if the http connection is directed to the ASA itself or thorugh the ASA (but seems that is to the ASA since you're attempting to access asdm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still seems that the outside ACL is blocking the traffic. Have you verified this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On previous versions of ASA software, the ACL on an interface applied only to traffic passing through the ASA (not traffic directed to it), but now you can apply the ACL to both scenarios.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also the output of the ''sh run http'' will let us know if you have any other restrictions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Mar 2010 16:27:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/http-authentication-problem-using-tacacs/m-p/1369289#M821968</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-03-10T16:27:17Z</dc:date>
    </item>
  </channel>
</rss>

