cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6253
Views
0
Helpful
8
Replies

Nexus 7000 and ACS AV-PAIRS

cochambe
Level 1
Level 1

Dear all,

I'm having an issue with TACACS+ AAA setup with a Nexus 7000 running 4.2(2a) and ACS 4.2. I've added the av-pair string of

shell:roles="network-operator vdc-admin" into the TACACS+ settings under the group custom attributes. When I log in I the login hangs
waiting for the custom attribute pair to respond back the switch which it doesn't seem to do and it then dumps me into vdc-operator role and not the
vdc-admin role.

Can any one give me any additional pointers?

Thanks in advance,

Col

8 Replies 8

cochambe
Level 1
Level 1

All,

Just for reference we've fixed this. The based VDC always seemed to honour the PRIV 15 under the ACS group and gave you network-admin, the correct syntax for vdc-admin passthrough on the av-pair is:

shell:user=admin-vdc

That's all you need.

Regards,

Col

Colin,

I saw your post and figured I would give you a shout.  I have a client with a 7K installed.  We are running ACS 4.2 and all network equipment is functioning with the exception of the 7K.

We keep getting:

TACACS-3-TACACS_ERROR_MESSAGE: All servers failed to respond

Do you have a sample of your config for your 7K?  Did you have to do anything special in ACS for it to talk to the 7K?  Been beating my head on this for a few weeks and the Cisco Config guides don't solve my issue.  Follow them to a tee and still does not work.

Thanks,

Josh

Hi,

I am also getting this message repeatedly on my NX5000, although the authentication and authorization are working fine. Will appreciate any clues. thanks

%TACACS-3-TACACS_ERROR_MESSAGE: All servers failed to respond

Hi Colin Chambers,

Can you please post the error and the current config for tacacs on NX7000.

Hi Colin,

Can u help me to resolve the issue of ACS 4.2 with nexus 7k. wat configuration u did in ACS ?

Regards,

Veer Pratap Singh

brian.holmes
Level 1
Level 1

My server was sending minor version 0 instead of 1 when I saw the same error message.

Brian Holmes
Verizon

Yun Pan
Level 1
Level 1

brian.holmes
Level 1
Level 1

One other thing I had to send was TACACSPLUS-Priv-Level = ROOT

which by the way was not in any manual.  

Brian Holmes
Verizon
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: