09-21-2011 05:42 AM - edited 03-10-2019 06:25 PM
I am running ACS 4.1.1.23 on a Microsoft server and I am trying to get TACACS to work with two Linux servers. The servers are capable of TACACS, are using port 49 and have the correct shared secret. I believe I do not have the devices configured properly on the ACS side. These 2 servers currently are using RADIUS and we are getting bit by the bug where the ACS application will start rejecting RADIUS authentication requests but still accept TACACS requests. Any help would be greatlly appreciated.
Regards,
-Hunter
09-23-2011 06:59 AM
You need to define the Linux systems to be AAA clients on ACS using TACACS+. Go to the Network Configuration page, select each of the Linux servers and change their authentication protocol to TACACS+.
09-23-2011 07:11 AM
I already did that. It is a Red hat 5 Server Enterprise. In etc/services it has port 49 as both udp and tcp. There is nothing in the ACS log, despite the fact that it can communicate with the box.
09-23-2011 07:15 AM
The steps I detailed earlier are to be executed on ACS, not the Linux boxes.
09-23-2011 07:21 AM
That is where I did it.
09-23-2011 07:27 AM
Then I would set the log level detail to full (System Configuration -> Service Control), reproduce the problem, and then look in the auth.log and tcs.log files for clues. You may also want to run tcpdump on the Linux boxes to see the traffic between them and ACS.
09-23-2011 07:58 AM
Here was the problem. The NGD group is configured fro RADIUS and that over rides TACACS+. I made the shared secret the same as the Radius one and now it works. Thanks for your replies.
Regards,
-Hunter
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide