TACACS enable password is not working after completing ACS & MS AD integration

Enable password for (Router, Switches) is working fine if identify source is "Internal Users", unfortunately after completed the integration between ACS to MS AD, and change the Identity source to "AD1" I got the following result
1. able to access network device (cisco switch) using MS AD username and password via SSH/Telnet.
2. Enable password is not working (using the same user password configured in MS AD.
3. When I revert back and change the ACS identity source from "AD1" to "Internal Users" enable password is working fine.
Switch Tacacs Configuration
aaa new-model
aaa authentication login default none
aaa authentication login ACS group tacacs+ local
aaa authentication enable default group tacacs+ enable
aaa authorization exec ACS group tacacs+ local 
aaa authorization commands 15 ACS group tacacs+ local 
aaa accounting exec ACS start-stop group tacacs+
aaa accounting commands 15 ACS start-stop group tacacs+
aaa authorization console
aaa session-id common
tacacs-server host 10.X.Y.11
tacacs-server timeout 20
tacacs-server directed-request
tacacs-server key gacakey
line vty 0 4
 session-timeout 5 
 access-class 5 in
 exec-timeout 5 0
 login authentication ACS
 authorization commands 15 ACS
 authorization exec ACS
 accounting commands 15 ACS
 accounting exec ACS
 logging synchronous
This is my first ACS - AD integration experience, hoping to fix this issue with your support, thanks in advance.
Regards,

Hi Edward,
I created a new shell profiles named "root" as the default one "Permit Access" can't be access or modified, underneath the steps I've made.
1. Create a new shell profile name "root" with max privilege of 15. And then used it in "Default Device Admin/Authorization/Rule-1" shell profile - see attached file for more details.
2. Telnet the Switch and then Issue "debug aaa authentication" using both "Root Shell" and "Permit Access" applied in Rule-1 profile.
Note:
I also attached here the captured screen and debug result for the "shell profiles"

Similar Messages

  • Tacacs+ Enable password is not working on Cisco Switch

    Ladies/Gents,
    I am facing issues when enabling tacacs authentication on my cisco switch, aaa login/password is working, aaa enable is not. Underneath details of my devices.
    Cisco ACS 1121: version 5.1
    Cisco Switch 3560: ios ver 15
    I also attached here some documents for your review and comment (switch aaa configuration, debug aaa authentication, acs captured screen)
    Hoping to receive an update and comment from you soon.
    Thanks,
    Arnold

    Hi Edward,
    I created a new shell profiles named "root" as the default one "Permit Access" can't be access or modified, underneath the steps I've made.
    1. Create a new shell profile name "root" with max privilege of 15. And then used it in "Default Device Admin/Authorization/Rule-1" shell profile - see attached file for more details.
    2. Telnet the Switch and then Issue "debug aaa authentication" using both "Root Shell" and "Permit Access" applied in Rule-1 profile.
    Note:
    I also attached here the captured screen and debug result for the "shell profiles"

  • Password's not working after firmware 7.3.1

    I updated my Airport Extreme this morning from 7.2.x to 7.3.1.
    The update ask for the password and then installed itself. After the update, I try to manage the Airport, but the password isn't working. I'm talking about the password used to admin the Airport, not my user password. The wireless is still working.
    The password contained some spaces and ponctuation, something like: This is the password to the airport!!
    Any idea why? Is the only thing I can do is reset everything?
    Thanks.
    Maxime.

    The only reason I deleted it after the update was because it wasn't working for some odd reason and I honestly thought that I should be able to go on here and redownload it no problem
    There's no way to "troubleshoot" the app unless it's installed.
    https://discussions.apple.com/thread/3714540?tstart=0
    I know you're upset, but please do not startup duplicate topics. You make it that much harder to help you. Using Lion Recovery on a broandband connection doesn't take long.
    I have already Reset Safari & Empty Cache.
    You can't reset Safari without having the app installed.

  • Password does not work after Lock windows 8

    Hi Experts,
    I have windows 8 Pro on my Laptop. I have started facing a weird issue if late.
    When I login to the laptop after restart of PC, it connects fine but when I am connected to my domain in my office network, after locking screen (Windows+L) the system does not accept the password. I have to disable the Wi-Fi and then it logs in and
    when I enable Wi-Fi I am in the network and continue to work. here are answers to some basic questions I am sure will be asked.
    - I am entering the correct password.
    - When I am connected to domain I get this problem. At home, it works fine and accepts password after unlocking system. But as soon as I connect to VPN, same problem.
    - I have tried connecting via LAN cable and face the same issue.
    - problem is not with my account, only with my desktop, I can connect from other desktops and other folks using my laptop face the same problem.
    - Our IT guy here has given me a workaround to disable wifi everytime I have to relogin after locking screen. It works but it is not a very good workaround. disabling enabling wifi disconnects all my applications.
    Have asked me to reimage the laptop. I have not given it a thought but I am getting more and more frustrated.
    - I have tried deleting my profile and same problem, i don't think my profile may be a problem though as other folks using my laptop face the same problem.
    Just when i started getting comfortable with Windows 8, i am stuck with this nightmare.
    looking forward for some suggestions.
    Yogi

    Hi,
    I'm a bit confused with your description. Is your account was domain account when encountering this problem?
    When did this problem occures, if it just occures recently, it would be better to use system restore to reset your system to a former normal state.
    Roger Lu
    TechNet Community Support

  • Password does not work after time machine restore and can not reset from CD

    The hard drive failed on my Power Mac G5. I replaced it and restored everything from Time Machine. The two non -admin accounts I can log into fine but my password for the admin account does not.  I tried resetting it booting from the OSX CD and using the password reset utility. It says it has done its thing but then I reboot and try to log in same problem.  It even has the old password hint.  I changed that  so I could see if it worked. I tried both my account and the root account out of desperation.  Any help appreciated!

    Hello, there's some corruption on the HDD, try this...
    Reset OS X Password Without an OS X CD...
    http://theappleblog.com/2008/06/22/reset-os-x-password-without-an-os-x-cd/
    Admin Hack...
    http://www.hackmac.org/?q=node/4
    Starts up like the first time you buy a new Mac, but after filling in all that info again, you should have access to the computer and the other Users & files will still be there... give the new User a different name than an existing one.

  • My app store is not working after installing mavericks. When I open app store it repeatedly asking me to login with apple ID and to provide User name and Password for proxy authentication in a loop.I am a newbie to mac,Please help me.

    My app store is not working after installing mavericks. When I open app store it repeatedly asking me to login with apple ID and to provide User name and Password for proxy authentication in a loop.I am a newbie to mac,Please help me.

    Hmmmm... would appear that you need to be actually logged in to enable the additional menu features.
    Have you tried deletting the plists for MAS?
    This page might help you out...
    http://www.macobserver.com/tmo/answers/how_to_identify_and_fix_problems_with_the _mac_app_store
    Failing that, I will have to throw this back to the forum to see if anyone else can advise further.
    Let me know how you get on?
    Thanks.

  • HT4889 Password not working after migration

    I migrated files from my iMac to my MacBook Air.  However, once completed, my login passwords would not work on teh MacBook Air.  I know I am using the right password.  How do I fix this?

    In the meantime I was able to solve the problem.
    The problem arises when the operating system on the target computer is an older version than on the source computer. I had OS X 10.8.2 Mountain Lion on my old MacBook Air (Source) and OS X 10.7.x Lion on the new MacBook Air (Target).
    After installing OS X 10.8 from an USB Stick the problem was solved and I was able to log in. The transfer of user accounts and programs was done.

  • Upgrade of our 10.4.11 laptop to 10.5 is accomplished and we now need to upgrade Quicktime and iTunes; however, the user name and password is now not working after the upgrade to 10.5.

    Object is to sync address and calendar between laptop with Max OS 10.4.11 and iPhone. Upgrade of our 10.4.11 laptop to 10.5 is accomplished and we now need to upgrade Quicktime and iTunes; however, the user name and password for the laptop is now not working after the upgrade to 10.5., though it was working prior to the upgrade, for file sharing.

    @ BDAqua > I tried your suggestion but no luck. holding opt+command just gave me a blue screen and it rebotted, pushing the disk out of the drive. Yes, the macbook has 1 gb of ram. I realize that the min req. call for 2 gb of ram so i've got an order in for another dimm to put into the machine. Thanks for your suggestions.
    @ a_brody > Yes. The machine was plugged into a power source. The disk promts you to do that and i recall aspect this form other installs. Thanks for the reminder tho! ( btw your second post is like greek to me man!) 
    @ Kuncklesmac > You're right about Snow Leopard being an upgrade from Leopard. I'm aware of this. And yes previously i've been told by Apple that I needed the Box Set (not the family pack.  i am using the family pack for OS Snow Leopard) to upgrade my 10.4.11 mac - they never mentioned adding ram but i figured that out on my own and an apple specialist recommended it when i purchased Snow Leopard and confirmed that I coul duse the Snow Leopard to upgarde from Tiger (10.4.11). I've also read extensively (as i said above) that it isn't necessary (always) to buy the box set. Several 10.4.11 users report having upgraded using the Snow Leopard upgrade disk only (not the Box Set) without trouble on intel macs (also see the apple link i posted). So i'm just ondering how they did it and i cannot. 
    Thanks fo rall yor help!

  • After a restore from Time Machine my login password does not work.

    My HD crashed and I replaced the HD.  I then restored from Time Machine.  After it was done restoring it prompted me for my apple ID and password and account info.  Now when I try to login, the password does not work.  After several failed passwords, it says I can reset my password using my apple ID.  How do you do this?  I click on the message and it just disappears.  I can't login!

    Is it your actual Apple ID login password that you're talking about (which is obviously working since you got into this forum) or the password for your user account. If the latter, simply boot to your ML Recovery partition (holding down the Command and R keys while booting) and set a new password via Terminal.
    Boot into your Recovery partition and, from the Utilities menu, open Terminal. In Terminal, type in:
    resetpassword
    ...a small app will run allowing you to select a user and change the password for that use. Enter the new password twice (the second time to verify) and give yourself a password 'hint'. Then reboot and use your new password on your account.
    Clinton

  • My Mac was just completely reset and now my passwords do not work. How do I fix so that I can reload Office?

    I bought  Macbook Pro in May, 2012. It was working great until Safari started crashing. After hours of reading posts and calling Apple Support, I finally had to take it in to the Apple Store and have the whole computer wiped and reset. When I got it back, it goes straight to the main open screen without requiring a password. Thats fine, except I am trying to reload Office for Mac and I need a password to get it to load. My old passwords will not work anymore, obviously. How do I load Office then?
    Thanks in advance.

    admin password?  http://osxdaily.com/2011/08/24/reset-mac-os-x-10-7-lion-password/

  • My apple id password will not work in app store after I reset it. Has anyone had this problem

    My apple id password will not work in app store after I reset it. It says the new password, verified by apple, is the wrong one when I purchase things in the store. Has anyone had this problem?

    OK.  Did you have a question?  Do you use the "Contact Us" link at the bottom right hand corner of this page?

  • Changed Password Not working after restart[What to do]

    Recently I've changed my password, but it's not working after restart.
    I've noticed that, input option is not taking one of the password characters which is '!'.
    I've the recovery disks, system accepts my fingerprint too.
    Any help will be highly appreciated.
    Thanks.

    Hello,
    Let me explain you what happened.
    One evening I was trying to open my ThinkPad. Usually it asks for
    fingerprint or password(I'm not sure which password, power-on/hard
    drive). But this time I failed using my finger. and I tried with
    password, but could not recall.
    Then I restart and again tried with finger, this time it worked. Now
    after login in Windows XP I removed all old fingerprints and create
    few new. When I create new, it was asking for password, or new
    password to replace. As I could not recall the pass, I've given new
    password to replace.
    Now to check I gave a restart. Fingerprint accepted for Power-on but
    also asking for password again(Now I can see it's for Hard Drive). I
    tried with new password. But it's not working. And even not taking one
    character ('!') of the password.
    Now can you tell me, if I did change password for Hard Drive in the
    last description. Or is that possible to change it from Windows XP
    environment. Else it's possible that the Hard Drive password remain as
    it was which has been set from ThinkVantage before OS boot. Let me
    know if you've any query which I've missed.
    Thanks.

  • Fingerprint Reader not working after windows password reset

    Hi There
    I was using windows login (single admin user) and fingerprint reader to login to my Thinkpad T510. Yesterday night I changed windows password and I didn't update finger print. Unfortunately I am not able to login when I tried to login using windows login today, I forgot the password and when I tried finger print reader it is just throwing error.
    Why finger print is not working after windows password reset? What should I do to login?
    Help would be appreciated!!

    I just called the tech support just now? I just asked the 'why the finger print reader not recognizing the finger print after changing windows password?', and he gave the following answers
    1. You should change fingerprint while changing windows password.  I don't understand the reason behind it, btw is this true?
    2. We can't do anything for this issue.

  • Zsh completion can not work after re-login

    I follow http://www.linux-mag.com/id/1106/
    my .zshrc
    autoload -U compinit
    compinit
    zstyle ':completion:*' verbose yes
    zstyle ':completion:*:descriptions' format '%B%d%b'
    zstyle ':completion:*:messages' format '%d'
    zstyle ':completion:*:warnings' format 'No matches for: %d'
    zstyle ':completion:*' group-name
    if [ -d ~/zshfunc ] ; then
    r() {
    local f
    f=(~/zshfunc/*(.))
    unfunction $f:t 2> /dev/null
    autoload -U $f:t
    fpath=(~/zshfunc $fpath)
    autoload -U ~/zshfunc/*(:t)
    fi
    There is a ~/zshfunc/_fossil script, but it can not work after re-login.
    The temp workaround is re-type 'compinit' manually.
    fossil <tab> # will use file name as completion
    compinit
    fossil <tab> # will show commands for fossil
    Last edited by dlin (2014-11-10 00:47:14)

    Hi
    Thanks for the tip. However, I elected not to save the XP SP2 uninstall files when I installed SP2. so I appear to be stuffed.
    There must be some creative drivers that work with an audigy with XP SP2 installed!
    If not then its either re-format the Hard Dri've and re-install everything again (Doh!!) or get another (not Creative Labs) soundcard.
    this is really bugging me.
    Zonker

  • Hello sir i purchased second hand iphone4s with ios 7 beta version after 2 month on 6 oct my iphone ask for a uers id that is unknown by me my new id and password also not work when i contavt with previous owner and use his id and password which he use on

    plz help me by mail me on   [email protected]

    the previos owner id and password also not work there what i do all do everything downdrade , upgrade but everytime ask for previous id and password...........i also erase find my phone from previous user id

Maybe you are looking for

  • HTTP connectivity error while using Blackberry MDS and JDE 5.0.0

    Hello, I am using BB MDS simulator 4.1.2 and BB JDE 5.0.0 for testing sample Oracle ADF Mobile client apps that I have developed. My app tries to access webservices via HTTP. Here is where I am encountering a HTTP connectivity issue. 1. For instance,

  • Do awm 10.2.0.3.0A  be the same awm 10.2.0.3.0 ???

    hi all, there is many post talk about awm 10.2.0.3.0 and its advances like: Sparcity Advisor ... I use currently the awm 10.2.0.3.0A and in this version, there's not the function Sparcity Advisor. Can you explain me how to get the awm 10.2.0.3.0? Wha

  • How to find the Actual Responder Name Displayed in a Notification

    Hi, Where are the details of the Actual Responder Details stored in the case of the below scenario If a notification for one user was closed by another user through access to the first user's worklist, the name of the second user, who actually took t

  • What column pertains to payment document number(AP)

    Hi, what column pertains to payment document number or Payment Voucher Number as well as Related AP Voucher Number (This is the pre-defined voucher number generated by Oracle). Please include the table_name (ex test.pdn). Thanks Edited by: 796711 on

  • Help! Syncing my iPhone on a new Mac after my old Mac died

    My old Mac Pro died. It's at the Apple Store right now getting a quote for repair. I have an iPhone 3GS with the new 4.01 OS. I'm syncing it with my Macbook Pro. When I try to sync my apps, I get a notice that mny existing applications will be replac