Different servers for dialup-access and exec-access

Hi all,
I am trying to configure a 3640 for authorization. The 'tricky' part is that I have to make a difference between dialup-access on one hand and exec-access on the other hand.
I am using TACACS+ for authentication and authorization.
The original configuration of the router (without exec-authorization) is as follows:
aaa new-model
aaa authentication login default group tacacs+
aaa authentication login no_login enable
aaa authentication login sd_routers group tacacs+ enable
aaa authentication login sd_console enable
aaa authentication ppp default local group tacacs+
aaa authorization network default group tacacs+ none
aaa accounting exec default start-stop group tacacs+
aaa accounting network default start-stop group tacacs+
tacacs-server host x.x.x.x
tacacs-server host x.x.x.x
tacacs-server timeout 15
tacacs-server directed-request
To configure exec authorization I added this:
tacacs-server host y.y.y.y
tacacs-server host y.y.y.y
aaa group server tacacs+ dialup
server x.x.x.x
server x.x.x.x
aaa group server tacacs+ vtyaccess
server y.y.y.y
server y.y.y.y
aaa authorization network default group dialup
aaa authorization exec default group vtyaccess
aaa authorization commands 0 default group vtyaccess none
aaa authorization commands 1 default group vtyaccess none
aaa authorization commands 15 default group vtyaccess none
So I tried to setup 2 different server groups with each 2 servers so authorization for dialup would be controlled by 1 server (and 1 in backup) and authorization for exec would be controlled by another server (and 1 in backup).
Is there something I don't understand quite well because it does not seem to work?
Kindly regards,
Jan

Hi Rick,
Sorry for this late reply, but I only could test this tonight due to change-management.
I again configured the router and this is what I get.
At login:
Username:xxxxx
Password:
Access Permitted
% Authorization failed.
Connection to host lost.
authen debug:
Mar 9 19:51:08: AAA: parse name=tty131 idb type=-1 tty=-1
Mar 9 19:51:08: AAA: name=tty131 flags=0x11 type=5 shelf=0 slot=0 adapter=0 port=131 channel=0
Mar 9 19:51:08: AAA/MEMORY: create_user (0x616BDB04) user='NULL' ruser='NULL' ds0=0 port='tty131' rem_addr='x.x.x.x' authen_type=ASCII service=LOGIN priv=1 initial_task_id='0'
Mar 9 19:51:08: AAA/AUTHEN/START (1932337086): port='tty131' list='sd_routers'action=LOGIN service=LOGIN
Mar 9 19:51:08: AAA/AUTHEN/START (1932337086): found list sd_routers
Mar 9 19:51:08: AAA/AUTHEN/START (1932337086): Method=tacacs+ (tacacs+)
Mar 9 19:51:08: TAC+: send AUTHEN/START packet ver=192 id=1932337086
Mar 9 19:51:08: TAC+: ver=192 id=1932337086 received AUTHEN status = GETUSER
Mar 9 19:51:08: AAA/AUTHEN (1932337086): status = GETUSER
Mar 9 19:51:10: AAA/AUTHEN/CONT (1932337086): continue_login (user='(undef)')
Mar 9 19:51:10: AAA/AUTHEN (1932337086): status = GETUSER
Mar 9 19:51:10: AAA/AUTHEN (1932337086): Method=tacacs+ (tacacs+)
Mar 9 19:51:10: TAC+: send AUTHEN/CONT packet id=1932337086
Mar 9 19:51:11: TAC+: ver=192 id=1932337086 received AUTHEN status = GETPASS
Mar 9 19:51:11: AAA/AUTHEN (1932337086): status = GETPASS
Mar 9 19:51:14: AAA/AUTHEN/CONT (1932337086): continue_login (user='xxxxx')
Mar 9 19:51:14: AAA/AUTHEN (1932337086): status = GETPASS
Mar 9 19:51:14: AAA/AUTHEN (1932337086): Method=tacacs+ (tacacs+)
Mar 9 19:51:14: TAC+: send AUTHEN/CONT packet id=1932337086
Mar 9 19:51:15: TAC+: ver=192 id=1932337086 received AUTHEN status = PASS
Mar 9 19:51:15: AAA/AUTHEN (1932337086): status = PASS
Mar 9 19:51:17: AAA/MEMORY: free_user (0x616BDB04) user='xxxxx' ruser='NULL' port='tty131' rem_addr='x.x.x.x' authen_type=ASCII service=LOGIN priv=1
author debug:
Mar 9 19:42:50: AAA: parse name=tty131 idb type=-1 tty=-1
Mar 9 19:42:50: AAA: name=tty131 flags=0x11 type=5 shelf=0 slot=0 adapter=0 port=131 channel=0
Mar 9 19:42:50: AAA/MEMORY: create_user (0x6183BA20) user='NULL' ruser='NULL' ds0=0 port='tty131' rem_addr='x.x.x.x' authen_type=ASCII service=LOGIN priv=1 initial_task_id='0'
Mar 9 19:42:57: tty131 AAA/AUTHOR/EXEC (657940182): Port='tty131' list='' service=EXEC
Mar 9 19:42:57: AAA/AUTHOR/EXEC: tty131 (657940182) user='xxxxx'
Mar 9 19:42:57: tty131 AAA/AUTHOR/EXEC (657940182): send AV service=shell
Mar 9 19:42:57: tty131 AAA/AUTHOR/EXEC (657940182): send AV cmd*
Mar 9 19:42:57: tty131 AAA/AUTHOR/EXEC (657940182): found list "default"
Mar 9 19:42:57: tty131 AAA/AUTHOR/EXEC (657940182): Method=vtyaccess (tacacs+)
Mar 9 19:42:57: AAA/AUTHOR/TAC+: (657940182): user=xxxxx
Mar 9 19:42:57: AAA/AUTHOR/TAC+: (657940182): send AV service=shell
Mar 9 19:42:57: AAA/AUTHOR/TAC+: (657940182): send AV cmd*
Mar 9 19:42:57: AAA/AUTHOR (657940182): Post authorization status = ERROR
Mar 9 19:42:57: tty131 AAA/AUTHOR/EXEC (657940182): Method=NOT_SET
Mar 9 19:42:57: tty131 AAA/AUTHOR/EXEC (657940182): no methods left to try
Mar 9 19:42:57: AAA/AUTHOR (657940182): Post authorization status = ERROR
Mar 9 19:42:57: AAA/AUTHOR/EXEC: Authorization FAILED
I'm not really sure what you mean with changing the authentication and the inconsistency.
Thanks for the help!
Regards,
Jan

Similar Messages

  • Setting mail with Cox (or other services with different servers for pop and smtp)

    My Cox mail account uses different servers for pop and smtp (my personal ISP 1&1 does too).
    The mail applet on my Blackberry Curve 8330 with Verizon does not allow to define different servers for pop and smtp, and further, for SSL smtp mail, the port is fixed at 995 and cannot be changed, while Cox (and 1&1) want to use 587 or something like that.
    As a result, I can only receive mail with these services.
    I also have yahoo mail, which works fine, so I can send mail with it and it is not a life-and-death situation, but I would like to be able to just reply to email sent to my Cox address.
    I called Verizon and they said BlackBerry provides the mail access through their servers and the applet, so there is nothing they can do.
    Is there a way to set it such that I can not only receive but also send mail through either of these services?
    Thanks in advance,
    Didier
    PS: Other than that, the Curve on Verizon rocks!!! so much better down here than AT&T it's not even funny.

    OK, thank you for the input.
    The problem I have with this solution is like the one I have now using yahoo.
    There are 2 problems:
    1) mailing lists want the mail to come from the account that is subscribed, so if the cox account is subscribed, I can't contribute from the blackberry, and if the blackberry account is subscribed, I don't get my mail in Outlook. Neither is good for me.
    2) people who send me mail to the Cox account and get replies from me from the blackberry continue responding to the account that can send from the blackberry (not Cox), and from that point on I do not have that mail on the computer.
    The issue of having two copies is no big deal, I just delete the mail I do not need. I would rather have two than none.
    Really, Blackberry should modify the email service so that they directly support mail systems like those of Cox and 1&1. I am sure there are others. They should also allow the use of another port for SSL than 995. I have not seen anyone using 995 for SSL.
    Until recently, I had a BB provided by my employer, and we had a BES, and that worked really well. I would like to emulate as much of that functionality as possible without having to pay somebody another $10 or $20 a month just for the priviledge of having an account on a private BES server.
    Anyway, thanks for the exchange and suggestions.
    Didier

  • Setting Opportunity Access and Contact Access to null in Account Team

    Hi,
    We can set the the Opportunity Access and Contact Access to blank/null manually in the application but is it possible to set these to blank using import?
    Thanks,
    Teena

    Hi,
    Thanks for the reply. We have tried updating a record through Account Team > Import > Overwrite Existing Records where the Contact Access and Opportunity Access fields were blank. The import was successfull but the fields were not updated, they are still set to Full access. We used the Account EUID in the import file.
    Regards,
    Teena

  • Questions regarding Outlook Web App, Remote Desktop, Remote Web Access and VPN Access

    Hi there,
    I want to ask a series of questions regarding Outlook Web App, Remote Desktop, Remote Web Access and VPN access and was hoping whether you could help me. Below are my questions to ask you.
    Outlook Web App - What do I need to configure in order to get my Exchange account to work with the OWA app on my iPhone? Is Office 360 required on the server that hosts Outlook Web App in our organisation? When I configure the settings and
    connect I get the following message "couldn't connect -  We couldn't connect to the server. Check your information and make sure it's correct." I can connect with other devices using Outlook Web App.
    Remote Desktop - What do I need to configure in order to connect to my computer at work using Remote Desktop on my Windows Phone? When I configure the settings and connect I get the following message "Connection error - We couldn't connect
    to the remote PC. Make sure the PC is turned on and connected to the network, and that remote access is enabled. Inquiring minds may find this error code helpful: 0x204" I can connect with other devices using Remote Desktop. There are currently no
    RD Server settings in the Remote Desktop app on the Windows Phone and the only way I'm to connect to my PC at work is via Remote Desktop and not to be confused with the one by Microsoft, however the app is on a trial basis and times out every 5 minutes and
    can only be used once every hour unless I purchased the app for £2.99 off the App Store but would ideally like to use the Microsoft Remote Desktop app though.
    Remote Web Access - What do I need to configure in order to get Remote Web Access on my Windows Phone using a URL? When I log in using a URL I get the following message "There is a problem with this Web page. Please contact the person who manages
    the server" I can connect with other devices using Remote Web Access. Also how do you enable the background option for Remote Web Access? I know how to do this in Remote Desktop but not in Remote Web Access. Remote Web Access works on PCs regardless
    being onsite and offsite and on my iPhone, the same issue also occurs with my Nokia 5230s regardless of whether I'm using Opera Mobile or Mini or the latest Nokia Browser.
    VPN access - How do you configure VPN access on a Windows Phone using VPN? I cannot find the protocols PPTP, L2TP, SSTP and IPsec in order to configure VPN access on the Windows Phone apart from IKEv2.
    Many thanks,
    RocknRollTim

    Any help would be much appreciated.
    Kind regards,
    RocknRollTim

  • Protected access and Default access

    hi all,
    Can you tell exact difference between protected access and default access.
    Thanks in advance.

    default (for classes*), also known as "package" or "package private": accessible from within that class and other classes in the same package.
    protected: accessible from within that class, other classes in the same package, and subclasses.
    *Note that for interfaces, the "default" access is pubic, not "package private".                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       

  • In SAP BW landscape we should have separate servers for DEV, QA and PROD

    Hi all,
    In SAP BW system landscape we should have separate servers for DEV, QA and PROD.
    whether one server is enough for DEV and we can use virtual servers to QA & PROD?
    Regards,
    chandu

    Hi chandu,
    In my previous Organisation we got exactly the same landscape for BW as you described.BCS(BAYER COPSCIENCE LTD) operates a BW System Landscape with one centralized  Global Development System and three regional Quality Assurance and Production Systems located in Europe, Asia Pacific and Americas. This Landscape is to ensure consistent data models to be available in all regional systems as well as to minimize development efforts and make use of respective synergies.
    This is perfectly working  for BCS ,and I think, this is the most approriate way of handling of resources.
    Regards
    CSM Reddy

  • Using different templates for the desktop and phone versions of the same blog

    I have a site which was created in Adobe Muse and is hosted on Business Catalyst.
    I have created both a desktop and a phone versions of the site.
    I  want to know how I can integrate the blogs that I  currently have on the desktop site with the phone version that I just did, using different templates for the desktop and phone versions of the same blog. This is in order to ensure that visitors to the blogs on the website are directed to the templates that render correctly for the devices they are using.
    My current approach has been to create both a desktop and phone versions of the blogs. The problem with this however, is that the dates are different and the comments are separated between the two blog versions!
    I  have also tried enabling mobile templates in BC, but still couldn't find a way to specify the mobile versions of the templates for the same blog?
    To recap my problem, I basically  need a solution where the same blog uses different templates for desktop and mobile (both templates use different navigation headings and menu styles)
    Thanks.

    There can be few reason for this, including page contents links or contents used in phone/tablet version.
    Please provide the site url , also try to publish the site as a trial site in Business Catalyst with all layouts which would help to isolate the issue.
    Thanks,
    Sanjit

  • Can you have different passwords for mail account and ICloud?

    Can you have different passwords for mail account and ICloud?

    Yes - you want to go under Notifications, Mail.   Set each acct the way you want.

  • Does anyone know if I can transfer apps between my 2 apple ids? I have different ids for my iPhone and iPad?

    Does anyone know if I can transfer apps between my 2 apple ids? I have different ids for my iPhone and iPad?

    You can't, all content that you download from the store is tied to the account that downloaded it, you can't merge accounts nor transfer content between them.

  • I have only one ID, but I have different passwords for my iPhone and iPad. How to fix that?

    I have only one ID, but I have different passwords for my iPhone and iPad. How to fix that?

    Hi Cristigil,
    Are you talking about your lock screen passcode? If so, go into Settings>General>Passcode Lock, and Change one of your Passcodes to match the other.
    Hope this helps!
    Cheers,
    GB

  • Question on best practice for NAT/PAT and client access to firewall IP

    Imagine that I have this scenario:
    Client(IP=192.168.1.1/24)--[CiscoL2 switch]--Router--CiscoL2Switch----F5 Firewall IP=10.10.10.1/24 (only one NIC, there is not outbound and inbound NIC configuration on this F5 firewall)
    One of my users is complaining about the following:
    When clients receive traffic from the F5 firewall (apparently the firewall is doing PAT not NAT, the client see IP address 10.10.10.1.
    Do you see this is a problem? Should I make another IP address range available and do NAT properly so that clients will not see the firewall IP address? I don't see this situation is a problem but please let me know if I am wrong.

    Hi,
    Static PAT is the same as static NAT, except it lets you specify the protocol (TCP or UDP) and port for the local and global addresses.
    This feature lets you identify the same global address across many different static statements, so long as the port is different for each statement (you CANNOT use the same global address for multiple static NAT statements).
    For example, if you want to provide a single address for global users to access FTP, HTTP, and SMTP, but these are all actually different servers on the local network, you can specify static PAT statements for each server that uses the same global IP address, but different ports
    And for PAT you cannot use the same pair of local and global address in multiple static statements between the same two interfaces.
    Regards
    Bjornarsb

  • Have dead phone, cannot sign-in b/c of Secret Question. Plan head is daughter (out of country). No access for plan members and no access if phone dead. Need to learn deals, buy a phone, etc. ADVICE?

    HOW CAN I REPLACE MY DEAD PHONE;  BUY A NEW ONE, ADDING TO FAMILY PLAN WHEN I CAN"T EVEN SIGN-IN? 
    I hope this community can tell me tell how I can  get through the Verizon sign-in process soI can buy a phone to replace my currently dead one. 
    I am a member of a Family Plan run by my daughter (out of the country for a week)and even with her ID and password, Verizon does not accept my sign-in attempt when I could not answer her Secret Question.   With a dead phone, I cannot get from Verizon including a PIN.  I can use my husband's phone (also in the Familhy Plan) but Verizon does not allow access to anyone but the registered plan administrator.  My phone number-- with decades of phone bills from Verizon --- is "not recognized. "  Huh?
    I am so frustrated.  HELP!!  How can I access Verizon:
    --to buy a phone and add to Family plan;
    --delete dead phone from plan;
    --learn the gory financial details of a contract, and
    --arrange for that new phone to be shipped to me.
    I had tried the live chat, but I had to leave the page to locate my daughter's phone number.  Since I never actually type it out, and since it was locked inside my dead phone, I had to reach out to my family so they could look ion their contact phone lists.  And now I cannot regain access Chasmine, my chat person.
    I would be grateful for any advice.   I am without a working phone and beginning to believe I shall remain that way.  I would walk away from Verizon except it would work against my family and their contracts.  However,  I have learned just how powerful an essential company can be when it takes advantage of people dependent on its "services."
    Meanwhile, the reality is I need to know how to deal with Verizon and get a phone.  All thoughts are welcome and appreciated. I cannot even find a phone number to try to talk to a Verizon person.   Thank you

    Youll still have to be the account owner to make those changes.
    Is the account owner unavailable to make that change from their location?
    Customer Service
    (800) 922-0204
    or dial *611 from your mobile phone
    View the *611 On-Screen App for Android Video
    6 AM - 11 PM, Mon - Sun
    Emergency Service Hours
    11 PM - 6 AM, Mon - Sun

  • How to set up full access and limited access wireless networks to laptops

    Dear Apple,
    I just received my Apple 1 TB Time Capsule. Can someone please help me with a network configuration I want to set up?
    I have a cable modem, and, three computers: a G4 iMAC (system 10.5.5), an Apple MacBook (system 10.5.5), and, a PC laptop.
    The Time Capsule is connect directly to the cable modem.
    Regarding the computers:
    (1) I want the G4 iMAC to connect directly, via an Ethernet cable, to the Time Capsule, WITH FULL ALLOWED ACCESS to the Time Capsule and to the back-up function of the Time Machine feature, and, with allowed access to my HP inkjet printer (class 6110);
    (2) I also want the MacBook laptop to wirelessly link to the Time Capsule via the Airport utility on the laptop, and, WITH FULL ALLOWED ACCESS to the Time Capsule and to the back-up function of the Time Machine feature (using WPA/WPA2 security, and, without the network name visible to third parties), and, WITH allowed access to my HP inkjet printer (class 6110);
    (3) I want the PC laptop to wirelessly link to the Time Capsule (using WEP security), but WITHOUT ACCESS to the Time Machine, WITHOUT access to the back-ups on the iMAC, WITHOUT access to the back-ups on the MacBook, and, WITHOUT access to the inkjet printer --- I only want the PC to use the Time Capsule as a WIRELESS ROUTER so that the PC laptop can access the internet.
    (4) And, finally, I want to specify (Time-Capsule/Time-Machine/server ) access ONLY to the iMAC and the MacBook, so that others cannot gain any access.
    I specifically need help to set up and configure the Time Capsule so that the PC laptop, as stated above, should have limited access to the Time Capsule --- namely, only to access the internet, and, not even be aware of stored data on the Time Capsule, not even be aware of the inkjet printer, and, not even see my WPA network name when the PC scans for wireless devices.
    I also want the iMAC and the MacBook to have access to each other’s data stored on the Time Capsule (like a common server).
    I have an old D-Link DI-624 wireless router that I used before buying the Time Capsule, which is available, if needed. Hopefully, I can configure the Time Capsule so that I would not need the old D-Link.
    Thank you in advance,
    David.

    The basic method for remote access is not changed.
    http://gigaom.com/apple/access-your-time-capsule-over-the-internet/
    You have a few issues.
    The really big one.. the school firewall should not let you connect to home.
    Check the IT admin at your school but if they allow anything but a few protocols like http and https through, they are not doing their job. You cannot afford in a large network to have every Tom Dick and Harry access any open device.. that can introduce viruses and trojans into the network behind the firewall.
    The general method for remote access on large networks is vpn and the TC offers no vpn connection.. just AFP.
    If you intend using 3G wireless stick or the like then you can get access.
    The next issue is static public IP or how to find the TC.. you need some way to find the IP if your ISP does not offer static ip, and the tc has no dyndns client. Since Apple shut down new users for mobileme and will close that service there is no method to find the TC IP without owning your own domain. You would be better placing the TC in bridge behind a router that does offer dyndns and port forward AFP (TCP 548) to it.

  • Are there benefits to adding crossover cable between two servers for DFS replication and SQL Always On?

    I have two identical servers with 4 network interfaces each. The primary usage for two servers is hosting SQL Server instance with Always On high availability and dfs replication. Two network interfaces from each server will be used to connect to main network,
    while for the other two (on each) I was thinking about using crossover cable to possibly provide shorter path for two servers to communicate.
    Will there be any benefits to doing so, moreover, would teaming two crossover cable help more?
    Edit: Below is the link to the article where I got the idea of moving DFS Replication traffic to crossover. I wasn't able to find any info whether same thing is applied to SQL Always On high availability.
    http://blogs.technet.com/b/filecab/archive/2006/08/24/449013.aspx

    Hi,
    According to your description, my understanding is that you want to connect 2 servers by crossed cable(2 NICs).
    Just as the blog suggested, directly connect the servers by crossed cable and configure corresponding route entries will improve efficiency.
    If both servers have 2 NICs to connect, I recommend you to team the 2 NICs for bandwidth aggregation. NIC teaming is supported by Windows Server 2012/2012 R2, detailed information you may reference:
    NIC Teaming Overview
    https://technet.microsoft.com/en-us/library/hh831648.aspx
    besides, for file servers, SMB Multichannel (a feature included with Windows Server 2012/2012 R2 and part of the SMB 3.0 protocol) will helpful for increasing the network performance and availability. Detailed information reference:
    The basics of SMB Multichannel, a feature of Windows Server 2012 and SMB 3.0
    http://blogs.technet.com/b/josebda/archive/2012/05/13/the-basics-of-smb-multichannel-a-feature-of-windows-server-2012-and-smb-3-0.aspx
    For SQL server, suggestions in SQL Server Best Practices would be helpful for you:
    https://technet.microsoft.com/en-us/sqlserver/bb671430.aspx
    Best Regards,
    Eve Wang
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • Different sort for Z10 contacts and phone contacts

    Hi, I need my contacts sorted by last name, rather than the first name default. I changed the sort order in the standrad contact list and this worked as expected. But: In the phone contact list, sorting is still by first name - and I found no setting to change the sort order. I'd expect that the contact list is sorted identically in both contexts, but seems not to be. Any idea? Thanks!

    Hello,
    I too noticed some challenges with PUSH and Contact/Calendar sync (in my case, with Hotmail/Outlook.com via active sync). I found that it was better to turn off PUSH and instead let it manually synchronize at my chosen interval. Since I use a different provider for email, changing that doesn't affect my configuration for email, and that continues to PUSH via that account.
    We are all hoping that this issue, and all others, get resolved in future OS updates. But for now, I recommend defeating PUSH and instead configuring for interval-based synchronization.
    Good luck!
    Occam's Razor nearly always applies when troubleshooting technology issues!
    If anyone has been helpful to you, please show your appreciation by clicking the button inside of their post. Please click here and read, along with the threads to which it links, for helpful information to guide you as you proceed. I always recommend that you treat your BlackBerry like any other computing device, including using a regular backup schedule...click here for an article with instructions.
    Join our BBM Channels
    BSCF General Channel
    PIN: C0001B7B4   Display/Scan Bar Code
    Knowledge Base Updates
    PIN: C0005A9AA   Display/Scan Bar Code

Maybe you are looking for

  • Adobe creative suite 5.5 design premium upgrade

    I am installing adobe creative suite 5.5 design premium upgrade on a new laptop.  I installed the upgrade and entered the serial number and received the green check.  It never ask for a prevoius serial number from the previous product.  Each time I o

  • IPhone pre order

    Hi,  I plan on pre ordering the iPhone at full price. I am on a family plan, but I am not the Account Holder. I am authorized on the account, but I understand that I will have to be signed onto the account holder's account to be able to pre order. My

  • New camera support?

    I'm not sure if anyone here can answer this, will LR3 have support for the new Fuji X100 in the next update? Any ideas when the next update will ship if it will support it? Thanks!

  • Cannot install Illustrator CS6 from Adobe Application Manager

    I just signed up for Creative Cloud, and am getting the message "The download appears corrupted. Press Cancel, wait a few minutes and try again (-60)" error when trying to install Illustrator using the Application Manager. I have successfully install

  • Can't access one particular secure page

    I can access any secure page I try to except the log in page to our web hosting company. I click the link from their home page and just get a new, blank window in Safari. It doesn't work in FireFox or Opera either. Anybody got any ideas how to solve