取消
显示结果 
搜索替代 
您的意思是: 
cancel
5131
查看次数
0
有帮助
8
回复

思科最新的9300和9200添加三A认证失败,=找不到原因

linwei22403
Spotlight
Spotlight
老版本的3750,3650,3850都可以认证成功。但是C9200和C9300都认证不了ACS,SSH登录直接跳转到本地验证页面。以下是交换机展示相关配置截图




1 个已接受解答

已接受的解答

Terence.Jh
Spotlight
Spotlight
linwei22403 发表于 2020-8-21 17:10
这样配了下 还是不行,帮忙看看命令

授权的命令没敲??
aaa authorization exec BBraun_AAA group tacacs+ group ciscoacs local
aaa authorization commands 0 BBraun_AAA group tacacs+ group ciscoacs local
aaa authorization commands 1 BBraun_AAA group tacacs+ group ciscoacs local
aaa authorization commands 15 BBraun_AAA group tacacs+ group ciscoacs local

在原帖中查看解决方案

8 条回复8

Terence.Jh
Spotlight
Spotlight
linwei22403 发表于 2020-8-21 17:10
这样配了下 还是不行,帮忙看看命令

授权的命令没敲??
aaa authorization exec BBraun_AAA group tacacs+ group ciscoacs local
aaa authorization commands 0 BBraun_AAA group tacacs+ group ciscoacs local
aaa authorization commands 1 BBraun_AAA group tacacs+ group ciscoacs local
aaa authorization commands 15 BBraun_AAA group tacacs+ group ciscoacs local

linwei22403
Spotlight
Spotlight
aaa new-model
!
!
aaa authentication login default group tacacs+ local
aaa authorization exec default group tacacs+ local
aaa accounting exec default start-stop group tacacs+
aaa accounting commands 1 default start-stop group tacacs+
aaa accounting commands 15 default start-stop group tacacs+
aaa accounting network default start-stop group tacacs+
aaa accounting connection default start-stop group tacacs+
tacacs-server host 10.67.8.80 key 7 045802150C2E
tacacs-server host 10.67.8.90 key 7 1511021F0725
ip address 10.67.14.62 255.255.255.252

linwei22403
Spotlight
Spotlight
Switch Ports Model SW Version SW Image Mode
------ ----- ----- ---------- ---------- ----
* 1 41 C9300-24T 16.12.02 CAT9K_IOSXE INSTALL
2 41 C9300-24T 16.12.02 CAT9K_IOSXE INSTALL

linwei22403
Spotlight
Spotlight
ACS版本为5.2

Terence.Jh
Spotlight
Spotlight
linwei22403 发表于 2020-8-21 15:58
aaa new-model
!
!

C9K在你刷你这套就tacacs+命令时候应该提醒你了,仔细看诶
命令换成如下
aaa group server tacacs+ ciscoacs
server-private 10.67.8.90 key 7 1511021F0725
server-private 10.67.8.80 key 7 045802150C2E
aaa authentication login BBraun_AAA group tacacs+ group ciscoacs local

linwei22403
Spotlight
Spotlight
terence 发表于 2020-8-21 16:29
C9K在你刷你这套就tacacs+命令时候应该提醒你了,仔细看诶
命令换成如下

aaa group server tacacs+ acs
server-private 10.67.65.8 key 7 05080F1C2243
server-private 10.67.65.7 key 7 030752180500
!
aaa authentication login defalt group tacacs+ group acs local
aaa accounting exec default start-stop group tacacs+
aaa accounting commands 1 default start-stop group tacacs+
aaa accounting commands 15 default start-stop group tacacs+
aaa accounting network default start-stop group tacacs+
aaa accounting connection default start-stop group tacacs+

linwei22403
Spotlight
Spotlight
这样配了下 还是不行,帮忙看看命令

linwei22403
Spotlight
Spotlight
terence 发表于 2020-8-21 16:29
C9K在你刷你这套就tacacs+命令时候应该提醒你了,仔细看诶
命令换成如下

谢谢成功了
快捷链接