cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1420
Views
0
Helpful
9
Replies

ssh after ACS server "locked up" and had to be reconfigured no longer works.

Steve Coady
Beginner
Beginner

Hello

 

I have a VPN tunnel between an ASA5520 and a Cisco 891.

I had the 891 configured with the following:

aaa group server tacacs+ VTY
 ip tacacs source-interface Loopback0
!
aaa group server tacacs+ TACACS-ACS
 server 10.8.x.x
 server 10.16.y.x
!
aaa authentication login CONSOLE none
aaa authentication login VTY group tacacs+ local
aaa authorization exec VTY group tacacs+ local
aaa authorization commands 0 VTY group tacacs+
aaa authorization commands 15 VTY group tacacs+
aaa accounting commands 15 VTY start-stop group tacacs+
aaa accounting commands 15 CONSOLE start-stop group tacacs+

!

ip tacacs source-interface Loopback0

!

tacacs-server host 10.8.x.x key 7 yadayadayadayada
tacacs-server host 10.16.y.x key 7 yadayadayadayada
tacacs-server directed-request

!

line vty 0 4
 access-class 1 in
 authorization commands 15 VTY
 authorization exec VTY
 accounting commands 15 VTY
 login authentication VTY
 transport input ssh
line vty 5 15
 access-class 1 in
 authorization commands 15 VTY
 authorization exec VTY
 accounting commands 15 VTY
 login authentication VTY
 transport input ssh

 

I no longer can access device remotely. I am sure it has to do with the ACS server, but not sure where to look.

Any help would be  greatly appreciated.

 

 

 

 

sMc
1 Accepted Solution

Accepted Solutions

kcnajaf
Rising star
Rising star

Hi,

When you say u can not access device remotely are you not able to ssh to device or there is no rechablity itself?

Is ssh is the problem then do you get a login prompt? Any error message? Also have you checked ACS failed logs for any messages?

Regards

Najaf

View solution in original post

9 Replies 9

kcnajaf
Rising star
Rising star

Hi,

When you say u can not access device remotely are you not able to ssh to device or there is no rechablity itself?

Is ssh is the problem then do you get a login prompt? Any error message? Also have you checked ACS failed logs for any messages?

Regards

Najaf