02-15-2019 07:27 AM - edited 02-15-2019 07:33 AM
I am not even sure where to begin looking for the error. I recently discovered that my tacacs server (ACS 5.8.1) is allowing ANY username to authenticate - including ones that do not appear in TACACS. If you use a legitimate username and an incorrect password, it denies you access to the devices. Yet if you were to use BillGates as your username (is not a valid username) and MelindaGates as the password (which is in violation of the password rules), you get logged into the devices in Enable Mode.
Anyone have any idea where to look to fix this. I am sure it is just a setting that says something like "continue" instead of "deny"...
Thanks!
Solved! Go to Solution.
02-15-2019 08:53 AM
02-15-2019 08:53 AM
02-15-2019 11:49 AM
Somehow the Default Device Admin Identity settings had If user not found set to Continue. Should have been reject. Now that I changed it, everything is back to normal.
Thanks! Great memory, by the way!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide