Acs 4.2.1.15 and ssh authentication with ios xr

Hello,
we have a new acs appliance (1113) with version 4.2.1.15 and we want to authenticate user through ssh from routers with ios xr software. unfortunately this doesn't work.
Here ist our configuration of the router:
line template VTY
access-class ingress abcd
tacacs-server host x.x.x.x port 49 single-connection
tacacc-server key 7 test
tacacs source-interface Loopback13
ssh server v2
ssh timeout 60
! AAA config
aaa accounting exec default start-stop group tacacs+
aaa accounting network default start-stop group tacacs+
aaa accounting commands default start-stop group tacacs+
aaa authorization exec default group tacacs+ none
aaa authorization commands default group tacacs+ none
aaa authentication login default group tacacs+ local
does anybody has a solution for this problem?
thnx and best regards
Torsten Waibel

Hello,we
have a new acs appliance (1113) with version 4.2.1.15 and we want to
authenticate user through ssh from routers with ios xr software.
unfortunately this doesn't work.Here ist our configuration of the router:##################################################line template VTY
access-class ingress abcd!tacacs-server host x.x.x.x port 49 single-connectiontacacc-server key 7 test!tacacs source-interface Loopback13!ssh server v2
ssh timeout 60! AAA config
aaa accounting exec default start-stop group tacacs+
aaa accounting network default start-stop group tacacs+
aaa accounting commands default start-stop group tacacs+
aaa authorization exec default group tacacs+ none
aaa authorization commands default group tacacs+ none
aaa authentication login default group tacacs+ local##################################################does anybody has a solution for this problem?thnx and best regardsTorsten Waibel
Hi Torsten Waibel,
For ssh to support you should have a cryptography ios image in router and check the following command in line vty that transpot input ssh under line vty cofiguration.
If helpful do rate the post
Ganesh.H

Similar Messages

  • TS3694 I tried to update my iphone 3gs from ios 5 to 6 but because of software crash and while restoring with ios 6 it is not activated. Now I degrade it in ios 4 and can not use any app. How can I update this iphone?

    I tried to update my iphone 3gs from ios 5 to 6 but because of software crash and while restoring with ios 6 it is not activated. Now I degrade it in ios 4 and can not use any app. How can I update this iphone?

    Downgrading the iOS is not supported, and likely has caused the problems you are experiencing.
    You'll need to go elsewhere for support.

  • My iPad 2 keeps going into no service mode since upgrading to iOS 8.0 and the same with iOS 8.0.2

    My iPad 2 keeps going into no service mode since upgrading to iOS 8.0 and the same with iOS 8.0.2

    Hi jhatlanta, 
    I understand you are using a cellular iPad 2 and since upgrading to iOS 8 (and 8.0.2) your iPad drops the cellular connection and says, "No Service".
    So you have done step 5 in this list, but please test the other steps.
    If you see No Service in the status bar of your iPhone or iPad
    If you're in your carrier's coverage area
    Follow these steps, testing after each.
    Tap Settings > Enable Airplane Mode, wait five seconds, then turn off airplane mode.
    Restart your device.
    Remove the SIM card. If the SIM card is damaged, worn, or bent, or if it's too big or small for the SIM tray, contact your carrier for a new one. Then reinsert the SIM card.
    Check for a carrier-settings update: Connect to a Wi-Fi network, tap Settings > General > About, and install any available carrier-settings updates. If you can't connect to Wi-Fi, connect your device to a computer that has iTunes.
    Update your iPhone to the latest version of iOS.
    Reset network settings by tapping Settings > General > Reset > Reset Network Settings. This will reset all network settings, including Bluetooth pairing records, Wi-Fi passwords, VPN, and APN settings.
    Contact your carrier to check for any network or account issues.
    Restore your iPhone.
    Best Regards,
    Nubz

  • Does it make sense to buy an iPod touch 5th gen. 64 gb with iOS 7 and upgrade it to iOS 8, or spend a few bucks more and buy one with iOS 8 already installed?

    Does it make sense to buy an iPod touch 5th gen. 64 gb with iOS 7 and upgrade it to iOS 8, or spend a few bucks more and buy one with iOS 8 already installed?

    The iOS update us free so I would get the less expensive one.
    If you are getting a used one make sure this is done before you purchase it. Otherwise it may still have the Activatin Lock on
    Find My iPhone Activation Lock
    Apple's new iCloud tool can show if a used iPhone is stolen

  • I have an iPad 2, and I believe with iOS 7.1, can I download iOS 7.1.1 on it ???

    I have an iPad 2, and I believe with iOS 7.1, can I download iOS 7.1.1 on it ???

    Yes. Use the device's Software Update function in General, or update it from iTunes on a computer.
    (107446)

  • Please help. At work we have netgear and tplink. Since I updated my mini iPad and iPhone 4S with ios 7 and wifi drops all the time.

    Please help. At work we have netgear and tplink. Since I updated my mini iPad and iPhone 4S with ios 7wifi drops all the time.  What is the problem?

    Try this  - Reset the iPad by holding down on the Sleep and Home buttons at the same time for about 10-15 seconds until the Apple Logo appears - ignore the red slider - let go of the buttons. (This is equivalent to rebooting your computer.) No data/files will be erased. http://support.apple.com/kb/ht1430
    Some things to try first:
    1. Turn Off your iPad. Then turn Off (disconnect power cord for 30 seconds or longer) the wireless router & then back On. Now boot your iPad. Hopefully it will see the WiFi.
    2. Go to Settings>Wi-Fi and turn Off. Then while at Settings>Wi-Fi, turn back On and chose a Network.
    3. Change the channel on your wireless router (Auto or Channel 6 is best). Instructions at http://macintoshhowto.com/advanced/how-to-get-a-good-range-on-your-wireless-netw ork.html
    4. Go into your router security settings and change from WEP to WPA with AES.
    5.  Renew IP Address: (especially if you are drooping internet connection)
        •    Launch Settings app
        •    Tap on Wi-Fi
        •    Tap on the blue arrow of the Wi-Fi network that you connect to from the list
        •    In the window that opens, tap on the Renew Lease button
    6. Potential Quick Fixes When Your iPad Won’t Connect to Your Wifi Network
    http://ipadinsight.com/ipad-tips-tricks/potential-quick-fixes-when-your-ipad-won t-connect-to-your-wifi-network/
    ~~~~~~~~~~~~~~~~~~~~~~~~~
    Fix WiFi Issue for iOS 7
    http://ipadnerds.com/fix-wifi-issue-ios-7/
    iOS 6 Wifi Problems/Fixes
    Wi-Fi Fix for iOS 6
    https://discussions.apple.com/thread/4823738?tstart=240
    How To: Workaround iPad Wi-Fi Issues
    http://www.theipadfan.com/workaround-ipad-wifi-issues/
    Another Fix For iOS 6 WiFi Problems
    http://tabletcrunch.com/2012/10/27/fix-ios-6-wifi-problems-ssid/
    Wifi Doesn't Connect After Waking From Sleep - Sometimes increasing screen brightness prevents the failure to reconnect after waking from sleep. According to Apple, “If brightness is at lowest level, increase it by moving the slider to the right and set auto brightness to off.”
    Fix For iOS 6 WiFi Problems?
    http://tabletcrunch.com/2012/09/27/fix-ios-6-wifi-problems/
    Did iOS 6 Screw Your Wi-Fi? Here’s How to Fix It
    http://gizmodo.com/5944761/does-ios-6-have-a-wi+fi-bug
    How To Fix Wi-Fi Connectivity Issue After Upgrading To iOS 6
    http://www.iphonehacks.com/2012/09/fix-wi-fi-connectivity-issue-after-upgrading- to-ios-6.html
    iOS 6 iPad 3 wi-fi "connection fix" for netgear router
    http://www.youtube.com/watch?v=XsWS4ha-dn0
    Apple's iOS 6 Wi-Fi problems
    http://www.zdnet.com/apples-ios-6-wi-fi-problems-linger-on-7000004799/
    ~~~~~~~~~~~~~~~~~~~~~~~
    iPad: Issues connecting to Wi-Fi networks
    http://support.apple.com/kb/ts3304
    How to Boost Your Wi-Fi Signal
    http://ipad.about.com/od/iPad_Troubleshooting/a/How-To-Boost-Your-Wi-Fi-Signal.h Mt
    Troubleshooting a Weak Wi-Fi Signal
    http://ipad.about.com/od/iPad_Troubleshooting/a/Troubleshooting-A-Weak-Wi-Fi-Sig nal.htm
    How to Fix a Poor Wi-Fi Signal on Your iPad
    http://ipad.about.com/od/iPad_Troubleshooting/a/How-To-Fix-A-Poor-Wi-Fi-Signal-O n-Your-iPad.htm
    iOS Troubleshooting Wi-Fi networks and connections  http://support.apple.com/kb/TS1398
    iPad: Issues connecting to Wi-Fi networks  http://support.apple.com/kb/ts3304
    WiFi Connecting/Troubleshooting http://www.apple.com/support/ipad/wifi/
    How to Fix: My iPad Won't Connect to WiFi
    http://ipad.about.com/od/iPad_Troubleshooting/ss/How-To-Fix-My-Ipad-Wont-Connect -To-Wi-Fi.htm
    iOS: Connecting to the Internet http://support.apple.com/kb/HT1695
    iOS: Recommended settings for Wi-Fi routers and access points  http://support.apple.com/kb/HT4199
    How to Quickly Fix iPad 3 Wi-Fi Reception Problems
    http://osxdaily.com/2012/03/21/fix-new-ipad-3-wi-fi-reception-problems/
    iPad Wi-Fi Problems: Comprehensive List of Fixes
    http://appletoolbox.com/2010/04/ipad-wi-fi-problems-comprehensive-list-of-fixes/
    Connect iPad to Wi-Fi (with troubleshooting info)
    http://thehowto.wikidot.com/wifi-connect-ipad
    10 Ways to Boost Your Wireless Signal
    http://www.pcmag.com/article2/0,2817,2372811,00.asp
    Fix iPad Wifi Connection and Signal Issues  http://www.youtube.com/watch?v=uwWtIG5jUxE
    Fix Slow WiFi Issue https://discussions.apple.com/thread/2398063?start=60&tstart=0
    How To Fix iPhone, iPad, iPod Touch Wi-Fi Connectivity Issue http://tinyurl.com/7nvxbmz
    Unable to Connect After iOS Update - saw this solution on another post.
    https://discussions.apple.com/thread/4010130
    Note - When troubleshooting wifi connection problems, don't hold your iPad by hand. There have been a few reports that holding the iPad by hand, seems to attenuate the wifi signal.
    Some Wi-Fi losses may stem from a problematic interaction between Wi-Fi and cellular data connections. Numerous users have found that turning off Cellular Data in Settings gets their Wi-Fi working again.
    You may have many apps open which can possibly cause the slowdown and possibly the loss of wifi. In iOS 4-6 double tap your Home button & at the bottom of the screen you will see the icons of all open apps. Close those you are not using by pressing on an icon until all icons wiggle - then tap the minus sign. For iOS 7 users, there’s an easy way to see which apps are open in order to close them. By double-tapping the home button on your iPhone or iPad, the new multitasking feature in iOS 7 shows full page previews of all your open apps. Simply scroll horizontally to see all your apps, and close the apps with a simple flick towards the top of the screen.
    Wi-Fi or Bluetooth settings grayed out or dim
    http://support.apple.com/kb/TS1559
    ~~~~~~~~~~~~~~~
    If any of the above solutions work, please post back what solved your problem. It will help others with the same problem.
     Cheers, Tom

  • My iPhone 5 is blocked and goes wrong with IOS 8.2.

    My iPhone 5 is blocked and goes wrong with IOS 8.2. How can officially return to IOS 7.12?
    The phone goes slow, hard contacts are loaded, the phone got stuck a few times.
    I would like to return to the IOS 7.12, but can not. Problems have occurred since the IOS8, but I hoped to solve with iOS 8.1 or 8.2. On the contrary, the situation was worsened.
    What can I do?

    I have a 64GB model
    Contacts are displayed harder. Not appear depending on usage, as IOS 7.
    All functions of the smartphone go late.
    Now I installed iOS 8.1 and did not improve anything
    It happens rarely that's right, the smartphone to block everything and need to restart. But we claim that we have an Apple that should function without resets
    I understand that the processor does not support well IOS8 iPhone 5, but I want to return to IOS 7 as the smartphone was perfect
    Apple must know these problems and have to accept a return to IOS7 for iPhone 5
    They were given a warning only 3, 3 g, 4, 4s
    I have friends with iPhone 5 that meet the same problem and they will return to IOS7 if possible
    I think that Apple has a problem in this regard
    Another version of IOS 8 can not resolve the situation, because it seems that the processor can not handle this software
    I would be very happy if Apple will understand the situation, and someone at Apple will give me an answer or a solution

  • Machine Authentication and User Authentication with ACS v5.1... how?

    Hi!
    I'm having trouble setting up Machine Authentication and User Authentication on ACS v5.1 using WinXP SP3 (or SP2) as supplicant.
    This is the goal:
    On wireless (preferably on wired too) networks, get the WinXP to machine authenticate against AD using certificates so the machine is possible to reach via for example ping, and it can also get GPO Updates.
    Then, when the user actually logs in, I need User Authentication, so we can run startup scripts, map the Home Directory and so on.
    I have set up a Windows Sertificate server, and the client (WinXP) are recieving both machine and user certificates just fine.
    I have also managed to set up so Machine Authenticaton works, by setting up a policy rule that checks on certificate only:
    "Certificate Dictionary:Common Name contains .admin.testdomain.lan"
    But to achieve that, I had to set EAP Type in WinXP to Smart Card or other Certificate, and then no PEAP authentication occurs, which I assume I need for User Authentication? Or is that possible by using Certificates too?
    I just don't know how to do this, so is there a detailed guide out there for this? I would assume that this is something that all administrators using wireless and WinXP would like to achieve.
    Thank you.

    Hello again.
    I found out how to do this now..
    What I needed to do was to add a new Certificate Authentication Profile that checks against Subject Alternative Name, because that was the only thing I could find that was the same in both user certificate and machine certificate.
    After adding that profile to the Identity Store Sequences, and making tthe appropriate rule in the policy, it works.
    You must also remember to change the AuthMode option in Windows XP Registry to "1".
    What I really wanted to do was to use the "Was Machine Authenticated" condition in the policies, but I have never gotten that conditon to work, unfortunately.
    That would have plugged a few security holes for me.

  • HTTP Basic Auth and Username Authentication with Symmetric Key

    Hi,
    I have a webservice happily running on tomcat 5.5 using "Username Authentication with Symmetric Key" I have certificates setup and everything works fine. I can even connect a .net client and use the service.
    Now I have an additional requirement of authorization per operation basis so I'm planning on using the roles. My current setup uses tomcat-users.xml to configure users but I seem unable to identify the role of the user from within my code as wsContext.isUserInRole("briefing") always returns false even when it clearly isn't. Where wsContext = @Resource private WebServiceContext wsContext.
    So I figure perhaps I need to add HTTP Basic Auth to tomcat for it to gather this information so I added security-constraints to the web.xml and this seems to do the trick: at least it does for my .net client.
    If I do:
      Service service = new Service();
      Port client = service.getPort();
      BindingProvider bp = (BindingProvider)client;
      bp.getRequestContext().put(BindingProvider.USERNAME_PROPERTY, "myusername");
      bp.getRequestContext().put(BindingProvider.PASSWORD_PROPERTY, "mypassword");Then it all works fine. However, I'd like a little less transparency: I don't want to have to do this every time I make a call.
    My question(s) is:
    1) Am I going about this the right way (perhaps I am somehow getting the incorrect reference to the WebServiceContext)
    2) If I am going about this the right way I imagine the whole BindingProvider code needs to be added to as a policy configuration but I'm really not sure where to start especially as I'm using wsimport to generate everything: I'm not even sure where to configure this so it will not get overwritter.
    Thanks for any help.

    Doh! Ok So I've added a SOAP Handler to automatically add the username and password for the HTTP Basic Auth.
    All in all does this setup sound right?

  • App Store app nearly unusable on iPad 3 and iPhone 4 with iOS 6

    Thankfully I do not have any WiFi troubles with iOS 6 but I am facing another problem. iOS 6 offers that revamped App Store app which looks nice to me on my iPad 3 and iPhone 4, both using iOS 6. But it is nearly impossible to use that App Store app. I am quite often moving. apps onto and. off my devices and if possible I am doing it without using the USB connection to my mac, I like to use WiFi.
    I have to admit that I am owning more than 3.000 different apps by now. It always took some time to het those apps listed in iTunes on my Mac, in iOS 5 it also was no high speed listing. but at least it worked. Now after changing to iOS 6 the simple listing takes much more time. When changing the lsting type from "actual" to "by name" it even takes more time (and why is it still not possible to set the prefered view type within some preferences option?). When the view type finally has changed scrolling, detail look onto selected applications and the overall handling of this lsting is awfully slow.
    But the really annoying thing is that I can not scroll further than letter "D" or "E" - the App Store app constantly crashes (but remains active in the taskbar). You can imagine that this behaviour takes even more time on a iPhone 4.....!
    Does anybody in here face the same troubles?

    P.S. I solved the problem now and I'm only left with "installing..." status. Here's how got rid of that "waiting..." status:
    1) Open iTunes with your device connected to the laptop or pc.
    2) On the left sidebar, press "Apps".
    3) Then on the lower right, you'll see like in my case, "30 (this varies on the number of apps available for updates) Updates Available".
    4) Click on the desired app you want to update.
    5) Lastly, after updating, press the "sync" button.
    It worked, though my apps are currently stuck on "installing..." status. I don't know if this'll work in your case, but there's no harm in trying the procedure, right?

  • Having issues with netgear genie and air play with iOS 6

    Is anyone having issues with netgear genie and the fact they can not AirPrint with iOS 6.    Any solutions for this

    The list of AirPrint supported printers is here:
    AirPrint Basics
    Netgear Genie is not on this supported list so it is probably best to contact Netgear.

  • No picture albums and music sync with iOS 5 on iPad 2 and iPhone 4

    Sie tdem Umstieg auf iOS 5 lassen sich auf dem iPhone 4 gar keine Bilderalben vom Mac synchorinsieren, auf dem iPad 2 hat es einmal mit einem Teil funktioniert, nur sind die Bilder auch noch quer durch verschiedene Alben bunt gemischt. iPod Photo Cache gelöscht, alles ausprobiert, was man so im Internet findet und aus Erfahrung auch noch helfen könnte. Leider hat nichts geholfen.
    no picture albums sync, no music sync with iMac with iOS 5. neither via usb nor wifi. tried all tricks on iPad and iPhone. bother!

    Hello Suzanil3726,
    It sounds like you would like to open another tab in Safari without closing the ones you already have open. The + symbol you are looking for to open another tab is in the upper right hand corner in Safari on the iPad using iOS 7.
    From: iPad User Guide
              http://help.apple.com/ipad/7/#/iPad999d68f9
    Thank you for using Apple Support Communities.
    All the best,
    Sterling

  • Machine and User authentication with ISE 1.2.1

    Hi ,
    Can any one tell me in machine authentication what access need to be enable DACL for machine logon?
    Can we enable the access on port level ? direct to tcp/udp or ip level what is the best practice.
    Thanks 
    Pranav

    is this what you are looking for EAP Chaining which uses a machine certificate or a machine username / password locked to the device through the Microsoft domain enrollment process. When the device boots, it is authenticated to the network using 802.1X. When the user logs onto the device, the session information from the machine authentication and the user credentials are sent up to the network as part of the same user authentication. The combination of the two indicates that the device belongs to the corporation and the user is an employee.
    http://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise/design-zone-security/howto_80_eapchaining_deployment.pdf

  • DAD and Database Authentication with db link

    I have a report that access a table via dblink and displays the result set.
    I am trying to implement the database authentication for this using DAD. I created the new DAD without the plsqlusername and password. When I run this application with the valid apex_public_user I get a
    ORA-00942: table or view does not exist ORA-02063: preceding line from DB1
    But I can run the same SQL from sqlplus for the same user. What am I doing wrong? Any help appreciated.
    Thanks

    Found what was causing the problem. I had not given the workspace user the necessary permissions on the remote database.

  • OSB, REST, and browser authentication with OAM

    All,
    I'm looking for some advice regarding the consumption of REST services (from the users browser) in an environment that utilizes OAM security and the Oracle Service Bus. Let me set the stage.
    We've configured an instance of OAM with OHS acting as a proxy to our applications. One of our apps wants to pull some data (using an AJAX call) from a service directly to the browser. The service is currently protected using HTTP Basic authentication. This works fine for Java apps that want to make those service calls directly, but not so well when it is the browser that wants to make the call.
    My assumption (up to this point) had been that I would be able to utilize the OAM Identity Asserter on the service bus in much the same way that we have been using it to propagate identity to our application servers. After speaking with some of the service developers (guys more intimately familiar with the OSB than I am) we haven't tried to do this before and are unsure of the proper implementation to acheive our goal.
    So, with all of that being said, am I barking up the wrong tree? Would it be incorrect to have a REST service written that is serviced by two different OSB proxies? One that enforces HTTP Basic, and one that (somehow) uses the OAM_REMOTE_USER and an appropriate identity asserter to pass identity in such a manner that the OSB would be able to enforce security in that manner?
    Is there a better way to secure REST services being made from the browser?
    Thank you for any help/direction you can provide.
    --james                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       

    If you want to use custom authentication plugin then OAM provides a way to create a custom authentication module and you can orchestrate your steps based on your conditions. See http://docs.oracle.com/cd/E21764_01/doc.1111/e12491/authnapi.htm for more details.
    Hope this helps,
    Sagar

Maybe you are looking for