Strange Authentication Problem AAA/RSA
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-26-2011 04:04 AM - edited 03-10-2019 06:06 PM
Hey all,
I am scratching my head with an issue I have on a couple of routers.
We use AAA authentication with RSA Tokens. The router in question only accepts a telnet input.
When telnetting to the router I receive a prompt, i put in my details and then the window closes.
My details works on 95% of all other devices whether i use ssh or telnet so i know the tacacs server settings are good. To be sure I have checked them and they are the same as other users which have no issues.
I have checked the logs on the tacacs servers and neither of them have logs of my failed attempts.
The router in question is a 2600 with c2600-i-mz.120-2.XC2 image on it. I dont think this is an issue as login credentials work for other users.
I enabled telnet and tacacs debugging but cannot make head or tails of it.
I have attached the output of the failed attempt...can anyone come up with a suggestion as to why this is not working.
Cheers,
- Labels:
-
AAA
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-26-2011 07:48 AM
After further investigation I now know that I am in fact passing the RSA authentication, What caught my eye is that when I login I see the login banner and then immediately afterwards I see "authentication failed".
Answers on a postcard...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-26-2011 11:51 PM
Issue resolved. Router had IP for an old ACS server which was apparently demobbed....however it wasnt. This servers config was out of date. Removed the IP leaving the actual ACS server and works fine.
