This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.
I have posted another Discussion regarding the same, Unfortunately still looking for response.
I am now not able to find my old post here :-( . Pls find the problem we are facing again.
1) Our ASA 5525 (configured in Active - Passive Mode) is not getting authenticating through TACACS (ACS) credentials since 2 days. earlier it were working fine. Seems logical connectivity between ASA and ACS breaked up. We suspecting some routing issue at ASA or wrong policy implemented accidently by team member.
2) We are able to logged into ASA by local password , But ASA is not allowing to run any command . we are getting message "Command Authorization failed" on execution of any CLI command.
Overall, we are not able to check any routing issue or wrong policy on ASA.
ACS related configuration on ASA are as (taken from Backup cofniguration we have).
aaa-server ACS (Inside) host 10.25.10.21
aaa-server ACS (Inside) host 10.25.10.22
user-identity default-domain LOCAL
aaa authentication enable console ACS LOCAL
aaa authentication http console ACS LOCAL
aaa authentication ssh console ACS LOCAL
aaa authorization command ACS
aaa accounting enable console ACS
aaa accounting ssh console ACS
aaa accounting command ACS
username admin12 password uupWMcdZZWi0G encrypted privilege 15
Kindly please share way forward to solve the issue.
So your problem is the "aaa authorization command ACS" line. I am 99% sure you have locked yourself out because what this says is all commands must be authorized by ACS and if ACS is unreachable fail.You needed the local keyword after it to fall back to using the privilege level if ACs is unreachable. At this point your only option is password recovery.
Not a good situation to be in :( I have a couple of quesitons:
1. Are you 100% the connection between ACS and your ASA is broken? For instance, do you see anything in the ACS logs when it comes to AAA and the ASA?
2. What version of ACS are you using
3. In the future, you need to make sure that the local database can be used for authorization as well
aaa authorization command ACS LOCAL
Thank you for rating helpful posts!
1.Check yourself with "test aaa group " command and confirm you are getting the Authentication log in ACS.
2.In that case, configure the command authorization on ACS for any particular user and give him the privilege of 15.
3.In command authorization, atleast add "no aaa authorization command ACS" command to the permitted and try to remove the command and proceed further.