cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
382
Views
4
Helpful
2
Replies

Unable to access VPN 3030 after IP change / Password Reset

niesommer
Level 1
Level 1

Hi,

I have lost admin access from the network SSH / Web interface does not work after performing a password reset. I can only access the device through the console and using the default admin account. The VPN concentrator authenticates correctly the users etc. but the TACACS+ authentication test in the Admin AAA servers fails even though the ACS TACACS+ server authenticates correctly the user and it is reachable. There is something I'm missing in the config but don't know what.

What do I need to enable for this to work again?

Any help is much appreciated.

Thanks,

2 Replies 2

ajagadee
Cisco Employee
Cisco Employee

Hi,

Since the User Authentication server and Admin Authentication server are configured in two different places, capture the logs when the test from the admin page fails. Also, do you see the request on the TACACS+ Server from the VPN3000.

Are the users and admin using the same server. Also, check for IP Reachability from the VPN3000 to the TACACS+ server and the server TCP Port is not being blocked by a firewall.

I hope it helps.

Regards,

Arul

** Please rate all helpful posts **

Hi,

I will check the log again when it fails. The TACACS and RADIUS server is the same for admins and users. the FW has allow ip any any for this device. The TACACS server is pingable from the VPN3000 GW. The request is seen on the ACS server and shows up in the permitted log. but still fails on the VPN 3000.

Thanks,