09-27-2017 02:43 PM
I have a user where their TACACS accounts is unable to login to the Cisco Prime server after they run our Java client that connects to Cisco Prime using the HTTP REST API calls.
Below are the APIs used by our Java Client. We may make several ConfigVersions and extractUnsanitizedFile calls since our Java client is pulling the device configurations from Cisco Prime.
/webacs/api/v1/data/Devices
/webacs/api/v1/op/devices/exportDevices
/webacs/api/v1/data/ConfigVersions
/webacs/api/v1/op/configArchiveService/extractUnsanitizedFile
Any ideas on what could cause this behavior? The version of Cisco Prime is 3.1.
Thanks,
Eddy
10-02-2017 02:29 PM
I want to make sure I understand here: on steps 1-4, Prime Infrastructure is configured to use TACACS+ in the AAA mode settings? Does the API client succeed in step 2? If not, what is the response? In step 4, what local account do they use? What fallback settings do they have configured (I assume they've changed from the defaults, because unless it's the root account logging in with a local account shouldn't work when AAA mode is TACACS+)? Is the user that they are logging in as the same one used by their API client?
10-03-2017 05:56 PM
Hi Spencer,
Please see responses in line.
I want to make sure I understand here: on steps 1-4, Prime Infrastructure is configured to use TACACS+ in the AAA mode settings?
Does the API client succeed in step 2? If not, what is the response?
In step 4, what local account do they use?
What fallback settings do they have configured (I assume they've changed from the defaults, because unless it's the root account logging in with a local account shouldn't work when AAA mode is TACACS+)?
Is the user that they are logging in as the same one used by their API client?
Thanks,
Eddy
10-04-2017 11:47 AM
Understood. Well, enabling fallback on auth failure or no ACS response does make issues like this harder to diagnose. That's because at any given moment, we could be authenticating against the local or TACACS+ service; and the reasons could be varied. For instance, we could be authenticating against local because the TACACS server was unresponsive, or because it rejected the credentials we sent it. I'd recommend disabling fallback (be sure to have root or super user credentials for Prime Infrastructure handy, because if anything goes wrong, they will be the only users able to login). By disabling fallback, you should get a more consistent picture of what's happening, which will allow you to identify users that may be misconfigured in TACACS+.
05-08-2018 06:43 AM
Hi, not sure if this is still relevant! we had the same issue when authenticating to a TACACS server with Prime 3.4 the TACACS stated that the connection and authentication had happened but Prime still wouldn't load in with the same errors. We checked against known devices that are compatible and our TACACS wasn't on the list so we assumed this was the reason. Did you ever find a fix ?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide