01-12-2022 01:13 PM
Following an IOS upgrade, one particular stack of 8 2960x switch is having a problem with entering enable mode. When trying, it just says "% Error in authentication". Looking at a saved copy of the config, it looks like it was set to:
aaa authentication enable default group tacacs+ enable
and for some reason, the new IOS image doesn't like the tacacs+ config lines, and this stack never got a local enable secret set, so I'm thinking this is the problem.
I'm assuming a password recovery procedure is needed. From what I read, it sounds like I need to shut down all stack members, and do the recovery on the stack master switch, then turn all the member switches back on. It would probably be easier to schedule the downtime if all members didn't need to be shut off. Are there any alternatives to get this stack back to allowing enable mode again?
01-12-2022 01:49 PM
@spfister336 wrote:
"% Error in authentication".
I want to see the exact error message.
If the error message starts with "%ILET-1-DEVICE_AUTHENTICATION_FAIL" then this could, potentially, be CSCur56395.
There is no way to fix it other than to RMA the infernal switch.
NOTE: In my humble opinion, this is a "hardware defect" and should be treated as such (RMA).
01-12-2022 01:58 PM
That is the entire exact error message
01-12-2022 02:10 PM
@spfister336 wrote:
That is the entire exact error message
Do not waste any more time (troubleshooting). Contact Cisco TAC and organize for an RMA.
Look at the Bug ID. It is >1100 TAC Cases (and growing) attributed to this Bug ID alone.
01-12-2022 02:48 PM
what was version before and after upgrade. (this was suggested in most of the release notes) - always should have local account for safe recovery.
If the device working as expected and only issue with Login, then take the maintenance window and try password recovery :
still issue, please look at the bug @Leo Laohoo
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide