07-03-2018 03:28 AM - edited 03-01-2019 06:40 PM
Dear Network Engineers,
CISCO#test aaa group tacacs+ raghr pass legacy
Attempting authentication test to server-group tacacs+ using tacacs+
User was successfully authenticated.
but still device not accessible via TACACS credentials ..and only accessible via local credentials.,
Kindly help me what could be the cause.
07-03-2018 03:50 PM
can you share the AAA configuration.
BB
07-03-2018 08:10 PM
What is your TACACS+ server? The best place to check is usually the logs on it.
It could be any number of things - linkage to the external ID store, authorization policy, configuration on the network device etc.
07-03-2018 10:05 PM
07-04-2018 12:22 AM
You need to distinguish between authentication (who can log in) and authorization (who can do what). You can authenticate via TACACS and authorize locally. The device's AAA (Authentication Authorization and Accounting) settings control that.
07-06-2018 06:33 AM
Thanks MArvin ,
Got it ...
1 ,have cheked in ACS and observed no configuration issue.
2.switch side as you mentioned checked authorization but it has all the configuration like other switches.
removing all those authorization and adding it back will help?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide