<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to access ACS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-access-acs/m-p/1878474#M936943</link>
    <description>&lt;P&gt;Good day,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are having an issue with a couple of switches we have daisy chained off of each other. We have a 2960 8 port going to a 2950 24 port then to our core switch a 6507. The problem is we cannot authenticate to the ACS server attached to the 6507 from the 2960. We can however authenticate to the ACS from the 2950. We do have similar setups like this in different parts of our network that work. I have compared the configurations from theses switches and nothing stand out. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2960&lt;/P&gt;&lt;P&gt;G0/8 trunk allowed vlan 59,3300&lt;/P&gt;&lt;P&gt;switchport mode trunk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;connect to &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2950 &lt;/P&gt;&lt;P&gt;G0/1 trunk allowed vlan 59,3300&lt;/P&gt;&lt;P&gt;switchport mode trunk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;connect to &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6507&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;humv&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 12:32:42 GMT</pubDate>
    <dc:creator>Stacey Hummer</dc:creator>
    <dc:date>2020-02-21T12:32:42Z</dc:date>
    <item>
      <title>Unable to access ACS</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-acs/m-p/1878474#M936943</link>
      <description>&lt;P&gt;Good day,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are having an issue with a couple of switches we have daisy chained off of each other. We have a 2960 8 port going to a 2950 24 port then to our core switch a 6507. The problem is we cannot authenticate to the ACS server attached to the 6507 from the 2960. We can however authenticate to the ACS from the 2950. We do have similar setups like this in different parts of our network that work. I have compared the configurations from theses switches and nothing stand out. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2960&lt;/P&gt;&lt;P&gt;G0/8 trunk allowed vlan 59,3300&lt;/P&gt;&lt;P&gt;switchport mode trunk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;connect to &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2950 &lt;/P&gt;&lt;P&gt;G0/1 trunk allowed vlan 59,3300&lt;/P&gt;&lt;P&gt;switchport mode trunk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;connect to &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6507&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;humv&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:32:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-acs/m-p/1878474#M936943</guid>
      <dc:creator>Stacey Hummer</dc:creator>
      <dc:date>2020-02-21T12:32:42Z</dc:date>
    </item>
    <item>
      <title>Unable to access ACS</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-acs/m-p/1878475#M936944</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In such cases I find it useful to see if the packets are actually arriving at the ACS server. If you're running ACS on Windows, it's pretty simple to load Wireshark, start a capture and watch for the packets coming in during a failed authentication attempt. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm assuming you verified the obvious like the device's management IP being correctly entered and the tacacs key matching.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Common issues include:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a. the device sourcing from other than the expected IP address and thus not matching its definition in ACS. This can be fixed by either changing the device definition on ACS or using "ip tacacs source-interface" command on the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;b. the packets not arriving at all from the source device. This is usually caused by a network configuration error. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also debug tacacs on the switch while you try to authenticate to your ACS server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Jan 2012 23:42:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-acs/m-p/1878475#M936944</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2012-01-27T23:42:58Z</dc:date>
    </item>
  </channel>
</rss>

