cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1511
Views
0
Helpful
3
Replies

TACACS Authentication issue

Erland Medrano
Level 1
Level 1

Hi Cisco,

Good day!

Need your help on my problem, the problem is that a switch that we are trying to integrate to ACS can't authenticate via TACACS. based on our testing and troubleshooting, the ACS before config is Single connect device and TACACS+ Draft Compliant Single Connect Support is chosen. but when trying to change the configuration to Legacy TACACS + Single Connect support it works fine. 

Question: what is the standard procedure for enrollment 1 or 2 (See below) ? what is the different?

1. Single connect Device and TACACAS + Draft Compliant Single Connect Support

or

2. Just Legacy TACACS + Single Connect Support 

3 Replies 3

karans
Level 1
Level 1

Hi Erland,

The difference between Single connect Device and TACACAS + Draft Compliant Single Connect Support OR Legacy TACACS + Single Connect Support is former will send single connect flag to the NAS and latter will not send the single connect flag to NAS device.

You can also refer this draft for better understanding,

http://tools.ietf.org/html/draft-grant-tacacs-02

thanks for verification 

Any recommended best practices for this setting?