12-13-2006 04:29 PM - edited 03-03-2019 03:02 PM
Hi,
I am getting following message in TACACS failed attempts log.
Message Type: Unknown NAS
Regards
SKRAO
12-13-2006 06:00 PM
You are getting requests from a network device that is not defined under AAA clients (Network Configuration). You can use wild cards to allow any address, or you can setup individual devices.
Please rate helpful posts.
12-14-2006 03:06 AM
SKRAO
I agree with David that the reason you are getting these messages is that some device in your network is configured to use your TACACS server but the server is not configured to talk to the IP address that is in the source address of the TACACS packet. There can be two reasons this happens: the server is not configured for this client device at all, or the server is configured to talk to this client device using a different IP address. If the client device has more than one interface which it can use to send to the TACACS server then the server might receive packets from either interface and each one uses its own address as the source address by default. In this situation it is very useful to configure: ip tacacs source-address
to specify which address the client should use. It is probably best practice to specify a loopback address for this.HTH
Rick
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide