cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
388
Views
0
Helpful
2
Replies

3850 and Intermittent TACACS issue

mbhnt
Level 1
Level 1

Hi,


We've installed a 3850 (WS-C3850-48T) and added it so our ACS (v4.1) server but have a problem where it intermittently fails to authenticate a CLI session on the first attempt, the second attempt works fine. At first we thought we were getting the password wrong but we've now proved this isn't the case. The ACS Server also shows no record of the failed attempt in the log files.

 

Our AAA config is as below :-

aaa authentication login default group tacacs+ local
aaa authentication ppp default if-needed group tacacs+ local
aaa authorization network default group tacacs+ local
aaa accounting network default start-stop group tacacs+

tacacs-server host 10.x.x.x. single-connection key 7 *****************

 

Has any one else experience this and manged to fix the issue?

 

 

2 Replies 2

Josh Sprang
Level 1
Level 1

Have you tried running a debug tacsacs or debug tacacs events...  

 

http://www.cisco.com/c/en/us/td/docs/ios/12_2/debug/command/reference/122debug/dbfser.html#wp1019035

If you are not seeing a record of the failed attempts in the ACS log files, then looks like it is something on the 3850, or routing to the ACS server, does it  go thru a VPN tunnel or anything to get to the ACS

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card