Cisco Support Community
Community Member

Problems with VPN3000 concentrator TACACS configuration

Hi, I have a problem with my Altiga. I try to configure TACACS for administrative management but I receive the following error:

41369 07/12/2002 14:09:55.390 SEV=4 AUTH/15 RPT=38

Server name =, type = TACACS+,

group = none (global server), status = Active

41373 07/12/2002 14:10:08.980 SEV=4 AUTH/9 RPT=43

Authentication failed: Reason = No error

handle = 83, server =, user = admin

What it means?



Cisco Employee

Re: Problems with VPN3000 concentrator TACACS configuration

Looks sort of like you don't have a user called "admin" in your TACACS server. An important thing to remember when using TACACS for your admin logins, is that as soon as you add a TACACS server in under the Administration - Access Rights - AAA Servers - Authentication menu, the usernames configured on the VPN3000 concentrator itself are no longer used. What I mean is that if you look under Administration - Access Rights - Administrators, you'll see 5 usernames that you can use to login with normally. when you add in a AAA server, these names are no longer used. The only thing that is used is the AAA Access Level configured under each of these users.

What you need to do is add users to your TACACS server, and set their privilege level on the TACACS server to be equal to one of these values unde teh 5 different users. These usernames do not have to be "admin", "cisco", "user" etc like you see on the concentrator, since as I said thery're not referenced any more. The only important thing is that the username on the TACACS server also has a privilege level that matches the AAA Access Level under one of these users. If it does, the user will then get the privilege's that you have defined under the VPN3000 user with that corresponding access level.

Difficult to understand, but basically ignore the usernames on the concentrator, and just look at the privileges and the access level number under those users.

Community Member

Re: Problems with VPN3000 concentrator TACACS configuration

What happens whent he TACACS server is unavailable, will it revert to the local usernames on the VPN concentrator ?

Cisco Employee

Re: Problems with VPN3000 concentrator TACACS configuration

I don't believe it does. It will go to teh next server in the list, but if it gets to the bottom of the list then it fails the connection. When this happens the only way to get in is directly connected to the console.

CreatePlease to create content