cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
Announcements
Choose one of the topics below to view our ISE Resources to help you on your journey with ISE

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC! We will not comment or assist with your TAC case in these forums.
Please see How to Ask the Community for Help for other best practices.

5465
Views
0
Helpful
8
Replies
Beginner

Nexus 7000 and ACS AV-PAIRS

Dear all,

I'm having an issue with TACACS+ AAA setup with a Nexus 7000 running 4.2(2a) and ACS 4.2. I've added the av-pair string of

shell:roles="network-operator vdc-admin" into the TACACS+ settings under the group custom attributes. When I log in I the login hangs
waiting for the custom attribute pair to respond back the switch which it doesn't seem to do and it then dumps me into vdc-operator role and not the
vdc-admin role.

Can any one give me any additional pointers?

Thanks in advance,

Col

Everyone's tags (3)
8 REPLIES 8
Highlighted
Beginner

Re: Nexus 7000 and ACS AV-PAIRS

All,

Just for reference we've fixed this. The based VDC always seemed to honour the PRIV 15 under the ACS group and gave you network-admin, the correct syntax for vdc-admin passthrough on the av-pair is:

shell:user=admin-vdc

That's all you need.

Regards,

Col

Highlighted
Beginner

Re: Nexus 7000 and ACS AV-PAIRS

Colin,

I saw your post and figured I would give you a shout.  I have a client with a 7K installed.  We are running ACS 4.2 and all network equipment is functioning with the exception of the 7K.

We keep getting:

TACACS-3-TACACS_ERROR_MESSAGE: All servers failed to respond

Do you have a sample of your config for your 7K?  Did you have to do anything special in ACS for it to talk to the 7K?  Been beating my head on this for a few weeks and the Cisco Config guides don't solve my issue.  Follow them to a tee and still does not work.

Thanks,

Josh

Highlighted
Beginner

Re: Nexus 7000 and ACS AV-PAIRS

Hi,

I am also getting this message repeatedly on my NX5000, although the authentication and authorization are working fine. Will appreciate any clues. thanks

%TACACS-3-TACACS_ERROR_MESSAGE: All servers failed to respond

Highlighted
Beginner

Re: Nexus 7000 and ACS AV-PAIRS

Hi Colin Chambers,

Can you please post the error and the current config for tacacs on NX7000.

Highlighted
Beginner

Nexus 7000 and ACS AV-PAIRS

Hi Colin,

Can u help me to resolve the issue of ACS 4.2 with nexus 7k. wat configuration u did in ACS ?

Regards,

Veer Pratap Singh

Highlighted
Beginner

Re: Nexus 7000 and ACS AV-PAIRS

My server was sending minor version 0 instead of 1 when I saw the same error message.

Brian Holmes
Verizon
Highlighted
Beginner

Nexus 7000 and ACS AV-PAIRS

Highlighted
Beginner

Nexus 7000 and ACS AV-PAIRS

One other thing I had to send was TACACSPLUS-Priv-Level = ROOT

which by the way was not in any manual.  

Brian Holmes
Verizon