cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Choose one of the topics below for SD-WAN Resources to help you on your journey with SD-WAN

This community is for technical, feature, configuration and deployment questions.
For production deployment issues, please contact the TAC!
We will not comment or assist with your TAC case in these forums.

437
Views
0
Helpful
4
Replies
AbuRafay63
Beginner

SDWAN TACACS congfiurations on ISR

Dears,

 

I have configured tacacs on sdwan cedge isr. But cedge is not initiating communication with tacacs server which is behind firewall and on firewall there are no logs from source to destination. Reachability is there. need to know how i can troubleshoot as i am unable to see log files to see where is problem. Also see below config if i miss any config.

 

aaa group server tacacs+ tacacs-512
server-private 10.x.x.x port 49 timeout 5 key 7 12390653395a0a2422
server-private 10.x.x.x port 49 timeout 5 key 7 0324584f2d5e276c46
ip tacacs source-interface GigabitEthernet0
ip vrf forwarding Mgmt-intf
!
aaa authentication login default local group tacacs-512
aaa authorization exec default local group tacacs-512
!
 

1 ACCEPTED SOLUTION

Accepted Solutions

Do you have the proper routing in VPN512 to reach the TACACS server?

Oscar Desentis
Customer Success Specialist (SD-WAN)

View solution in original post

4 REPLIES 4
osdesent
Cisco Employee

Are you trying to reach your TACACS server via VPN512? 

Oscar Desentis
Customer Success Specialist (SD-WAN)

yes through vpn 512.. reachability is there.

AbuRafay63
Beginner

Dear,

 

Yes its under Mgmt-Intf vrf.... we are using cedge ISR in sdwan network.. Thanks

Do you have the proper routing in VPN512 to reach the TACACS server?

Oscar Desentis
Customer Success Specialist (SD-WAN)

View solution in original post