06-17-2018 07:51 AM - edited 02-21-2020 10:58 AM
Hello All
after a fresh migration of ACS 5.7 to ISE 2.3 I encounter a problem of managing my equipment with TACACS +
my ISE 2.3 is well integerer in AD, the groups are there, I can do a test of the users with success, but when try to authenticate on a equipment which uses my ISE like server authentication with AD like source identity I receive message "13036 Selected Shell Profile is DenyAccess", but when I use internals users with the same rules, everything is fine
Thanks
06-17-2018 09:03 AM
Hi,
What conditions are you using in your authorization rules for AD users? Can you please post a screenshot of your authorization rules?
06-17-2018 09:19 AM
you can find the print screen of authorizations used
06-17-2018 10:01 AM
06-17-2018 10:17 AM
Steps
|
13013 |
Received TACACS+ Authentication START Request - AD1 |
|
15049 |
Evaluating Policy Group - My.user |
|
15008 |
Evaluating Service Selection Policy - my.domain.com |
|
15048 |
Queried PIP - my.domain.com |
|
15048 |
Queried PIP - DEVICE.Device Type |
|
15041 |
Evaluating Identity Policy - my.domain.com |
|
22072 |
Selected identity source sequence - AD1 |
|
15013 |
Selected Identity Source - AD1 |
|
13045 |
TACACS+ will use the password prompt from global TACACS+ configuration |
|
13015 |
Returned TACACS+ Authentication Reply |
|
13014 |
Received TACACS+ Authentication CONTINUE Request ( Step latency=5596ms) |
|
15041 |
Evaluating Identity Policy |
|
22072 |
Selected identity source sequence - identity_tacacs |
|
15013 |
Selected Identity Source - AD1 |
|
24430 |
Authenticating user against Active Directory - AD1 |
|
24325 |
Resolving identity - My.user |
|
24313 |
Search for matching accounts at join point - my.domain.com |
|
24319 |
Single matching account found in forest - my.domain.com |
|
24323 |
Identity resolution detected single matching account |
|
24343 |
RPC Logon request succeeded - My.user@my.domain.com |
|
24402 |
User authentication against Active Directory succeeded - AD1 |
|
22037 |
Authentication Passed |
|
15036 |
Evaluating Authorization Policy |
|
24432 |
Looking up user in Active Directory |
|
24325 |
Resolving identity |
|
24313 |
Search for matching accounts at join point |
|
24319 |
Single matching account found in forest |
|
24323 |
Identity resolution detected single matching account |
|
24355 |
LDAP fetch succeeded |
|
24416 |
User's Groups retrieval from Active Directory succeeded |
|
15048 |
Queried PIP - AD1.ExternalGroups (2 times) |
|
13036 |
Selected Shell Profile is DenyAccess |
|
13015 |
Returned TACACS+ Authentication Reply |
06-22-2018 12:05 PM
is there any answer
06-22-2018 12:20 PM
06-25-2018 12:30 PM
I am talking to Cisco BU about this INCORRECT error message. I migrated my ACS 5.7 to ISE 2.3, experienced the same problem but I realized it had nothing to do with shell profile or similar.
One of the conditions in the AUTHZ Policy was not matched and I got the same Shell Profile Error. So like RJI said, check if your matching ALL the conditions of the corresponding AUTHZ policy.
thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide