cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
459
Views
2
Helpful
5
Replies

SDWAN-ISE Integration TACACS+ no supported authentication method

riazgul72112
Level 1
Level 1

 I have implemented SD-WAN LAB on 20.6.2 version. Dual Transport with end to end reachability. 
Physical LAN subnet of management PC redistributed into SD-WAN overlay, static routes are configured for loopbacks of all Service VPNs for all vEDGE Routers, towards point A from physical machine. 

ISE is configured with Loopback IPs of all vEDGE Routers with policy enforcement for TACACS+ users, when I initiate ssh session to any of the vedge routers on loopback its connected, as I enter the credentials everything goes well, but I get one response from the server saying "user group returned by tacacs+ server is invalid".

 

I have two users, and two roles created on Manager. Using custom attributes in TACACS+ Profiles I am providing the same names as created on Manager. 
Also attaching snaps here. 

 

image.pngTACACS Error.png

5 Replies 5

Just to confirm, when you configure aaa template, did you use the loopback as source interface for aaa connectivity to ISE server?

Yes loopback set as source for AAA traffic.

Did you check TACACS logs on ISE server?

HTH,
Please rate and mark as an accepted solution if you have found any of the information provided useful.

The logs shows authentication and authorization successful and return with the user group role name. 

How did you configure TACACS shell profile?

Raw data should be as below:

Viptela-Group-Name=netadmin

Viptela-Group-Name=operator

 

HTH,
Please rate and mark as an accepted solution if you have found any of the information provided useful.

Review Cisco Networking for a $25 gift card