AAA Config not working

Unanswered Question
Mar 15th, 2007


I've the following configuration on a switch:

aaa new-model

aaa authentication fail-message ^CCC

Failled to Authenticate!

Please Contact IT Networks Group for further information.


aaa authentication login default group tacacs+ local

aaa authorization exec default group tacacs+ local

aaa authorization network default group tacacs+ local

aaa accounting exec default start-stop group tacacs+

aaa accounting commands 15 default start-stop group tacacs+

tacacs-server host 170.x.x.164 key tennetwork

tacacs-server host 170.x.x.166 key tennetwork

and we have the ACS Server with the switch created, right key, etc. When I try to login with an user which was locally created, everything goes well. But when I try to use an user from an External User Database, in this case Active Directory, even showing authentication ok on the Passed authentications, the Switch is throwing me out, with failed to authenticate message.

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Vivek Santuka Thu, 03/15/2007 - 09:19


Try this :-

tacacs-server timeout 15

I think the switch is timing out while ACS talks to AD.




This Discussion