Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

CiscoSecure ACS for Windows 3.3 chooses the wrong NDG for NARs when the TACACS+ and the RADIUS NAS use the same IP address

Core issue

This problem occurs due to the presence of Cisco bug ID CSCeg51873.

The CiscoSecure ACS for Windows chooses a TACACS+ Network Device Group (NDG) to apply Network Access Restrictions (NARs), instead of a RADIUS NAR.

This problem occurs when these two conditions are met:

  1. Both a TACACS+ and RADIUS Network Access Server (NAS) are defined with the same IP address and placed in separate NDGs.
  2. Authentication is performed through RADIUS.

The NDG that contains the TACACS+ NAS is always used. ACS chooses the wrong NDG for NAR matching. As a result, access is blocked for all users, and the ACS Failed Authentication log displays the User access filtered error message.


As a workaround, stop all seven CiscoSecure ACS services in Windows and restart them.

Open a service request with the Cisco Technical Assistance Center (TAC)  for further assistance.