cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2888
Views
0
Helpful
5
Replies

ASA Command Authorization Failed - Not getting authenticated by ACS

netbeginner
Explorer
Explorer

Hello Experts, 

I have posted another Discussion regarding the same, Unfortunately still looking for response. 

I am now not able to find my old post here :-( . Pls find the problem we are facing again.

1) Our ASA 5525 (configured in Active - Passive Mode) is not getting authenticating through TACACS (ACS) credentials since 2 days. earlier it were working fine. Seems logical connectivity between ASA and ACS breaked up. We suspecting some routing issue at ASA or wrong policy implemented accidently by team member. 

2) We are able to logged into ASA by local password , But ASA is not allowing to run any command . we are getting message "Command Authorization failed" on execution of any CLI command.

Overall, we are not able to check any routing issue or wrong policy on ASA.

ACS related configuration on ASA are as (taken from Backup cofniguration we have).

aaa-server ACS (Inside) host 10.25.10.21
key Cisco123
aaa-server ACS (Inside) host 10.25.10.22
key Cisco123
user-identity default-domain LOCAL
aaa authentication enable console ACS LOCAL
aaa authentication http console ACS LOCAL
aaa authentication ssh console ACS LOCAL
aaa authorization command ACS
aaa accounting enable console ACS
aaa accounting ssh console ACS
aaa accounting command ACS

username admin12 password uupWMcdZZWi0G encrypted privilege 15

Kindly please share way forward to solve the issue.

Rgds

****

5 Replies 5

netbeginner
Explorer
Explorer

Pls reply/.

Nathan Spitzer
Beginner
Beginner

So your problem is the "aaa authorization command ACS" line. I am 99% sure you have locked yourself out because what this says is all commands must be authorized by ACS and if ACS is unreachable fail.You needed the local keyword after it to fall back to using the privilege level if ACs is unreachable. At this point your only option is password recovery. 

nspasov
Cisco Employee
Cisco Employee

Not a good situation to be in :( I have a couple of quesitons:

1. Are you 100% the connection between ACS and your ASA is broken? For instance, do you see anything in the ACS logs when it comes to A