cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3963
Views
5
Helpful
7
Replies

Tacacs configuration but no response from server

I been instruct to register our devices to new destination of Tacacs ISE server, but when tested, i not able to communicate with the ISE server, why is it ? 

below is the config

 

1 Accepted Solution

Accepted Solutions
7 Replies 7

marce1000
VIP
VIP

 

 - Are the endpoint devices registered in ISE ?

M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

According to them , Yes

 

 

Hello

If you have any firewalls between the host and the tacacs, test to make sure the tcp port 49 being allowed.

 

telnet 10.x.x.143 49 


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul

johnd2310
Level 8
Level 8

Hi,
Have you checked the logs on the Tacacs server? Could be an issue with the key not matching.

 

Thanks
John

**Please rate posts you find helpful**

test from the device , telnet to port 49, fail - but this is not the indication as other device registered also not able to telnet port 49, also there is no FW in between, it is MPLS line

 

refer to the attachment, it is registered in the ISE, but i will ask the Admin to check the log

 

I open debug tacacs & debug aaa authenti - but there is no debug apprear

Hello

Tacacs uses port tcp 49 , if you don't get a response from this port then I suggest to look as to why its failing, its the possible root cause to your probem.

 

Res

Paul


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul

 

 

 

Review Cisco Networking products for a $25 gift card