10-26-2022 07:46 AM
Hi,
I have configured tacacs on my fortiproxy appliance and can successfully contact cisco ISE using the AAA test commands (with my credentials). Although, the server is contactable and the credentials have been recognized via ISE - When i log out of the appliance and try logging in with my tacacs credentials it fails to authenticate. Is there anything on ISE that needs to be configured to allow the GUI to log into the appliance ?
Best Regards,
Sabeel
Solved! Go to Solution.
10-26-2022 11:19 AM
I have configured tacacs on my fortiproxy appliance and can successfully contact cisco ISE using the AAA test commands (with my credentials).
is this a local account of fotiproxy ?
Although, the server is contactable and the credentials have been recognized via ISE - When i log out of the appliance and try logging in with my tacacs credentials it fails to authenticate.
Do you have user source from different or on ISE you created a users ?
have you added fortiproxy as NAD on ISE ?
what logs you see on ISE when you try to login ?
11-09-2022 03:30 PM - edited 11-09-2022 03:32 PM
You need to include actual errors and details from the ISE LiveLogs.
"The credentials have been recognized by ISE" and "it fails to authenticate" is not specific for any troubleshooting or offering advice for next steps.
You have not followed up on @balaji.bandi 's very legitimate questions so I will refer you to the TAC.
10-26-2022 11:19 AM
I have configured tacacs on my fortiproxy appliance and can successfully contact cisco ISE using the AAA test commands (with my credentials).
is this a local account of fotiproxy ?
Although, the server is contactable and the credentials have been recognized via ISE - When i log out of the appliance and try logging in with my tacacs credentials it fails to authenticate.
Do you have user source from different or on ISE you created a users ?
have you added fortiproxy as NAD on ISE ?
what logs you see on ISE when you try to login ?
11-09-2022 03:30 PM - edited 11-09-2022 03:32 PM
You need to include actual errors and details from the ISE LiveLogs.
"The credentials have been recognized by ISE" and "it fails to authenticate" is not specific for any troubleshooting or offering advice for next steps.
You have not followed up on @balaji.bandi 's very legitimate questions so I will refer you to the TAC.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: