cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
586
Views
5
Helpful
2
Replies

appliance cannot log in using TACACS+ , but AAA test is successful

Hi,

I have configured tacacs on my fortiproxy appliance and can successfully contact cisco ISE using the AAA test commands (with my credentials). Although, the server is contactable and the credentials have been recognized via ISE - When i log out of the appliance and try logging in with my tacacs credentials it fails to authenticate. Is there anything on ISE that needs to be configured to allow the GUI to log into the appliance ?

Best Regards,

Sabeel 

2 Accepted Solutions

Accepted Solutions

I have configured tacacs on my fortiproxy appliance and can successfully contact cisco ISE using the AAA test commands (with my credentials). 

is this a local account of fotiproxy ?

 

Although, the server is contactable and the credentials have been recognized via ISE - When i log out of the appliance and try logging in with my tacacs credentials it fails to authenticate.

 Do you have user source from different or on ISE you created a users ?

have you added fortiproxy as NAD on ISE ?

what logs you see on ISE when you try to login ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

View solution in original post

thomas
Cisco Employee
Cisco Employee

You need to include actual errors and details from the ISE LiveLogs.

"The credentials have been recognized by ISE" and "it fails to authenticate" is not specific for any troubleshooting or offering advice for next steps.

You have not followed up on @balaji.bandi 's very legitimate questions so I will refer you to the TAC.

View solution in original post

2 Replies 2

I have configured tacacs on my fortiproxy appliance and can successfully contact cisco ISE using the AAA test commands (with my credentials). 

is this a local account of fotiproxy ?

 

Although, the server is contactable and the credentials have been recognized via ISE - When i log out of the appliance and try logging in with my tacacs credentials it fails to authenticate.

 Do you have user source from different or on ISE you created a users ?

have you added fortiproxy as NAD on ISE ?

what logs you see on ISE when you try to login ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

thomas
Cisco Employee
Cisco Employee

You need to include actual errors and details from the ISE LiveLogs.

"The credentials have been recognized by ISE" and "it fails to authenticate" is not specific for any troubleshooting or offering advice for next steps.

You have not followed up on @balaji.bandi 's very legitimate questions so I will refer you to the TAC.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: