*Oct 2 16:58:45: %SEC_LOGIN-4-LOGIN_FAILED: Login failed [user: domainuser] [Source: 10.0.0.10] [localport: 22] [Reason: Login Authentication Failed] at 16:58:45 KRAST Fri Oct 2 2015
2015-10-02 16:58:45 +0700 10.20.0.15: shell login for 'domainuser' from 10.0.0.10 on tty322 succeeded*Oct 2 17:19:56: %SEC_LOGIN-4-LOGIN_FAILED: Login failed [user: domainuser] [Source: 10.0.0.10] [localport: 22] [Reason: Login Authentication Failed] at 17:19:56 KRAST Fri Oct 2 2015
*Oct 2 17:02:37: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: rootik] [Source: 10.0.0.10] [localport: 22] at 17:02:37 KRAST Fri Oct 2 2015*Oct 2 17:02:57: %SYS-5-CONFIG_I: Configured from console by prootik on vty0 (10.0.0.10)id = spawnd {enable secret 5 ****************!aaa new-modelaccess log = ">/var/log/tac_plus/access/%Y%m%d.log"
accounting log = ">/var/log/tac_plus/acct/%Y%m%d.log"
skip missing groups = yesaaa authentication login default group TACSERVICE localaaa authentication enable default group TACSERVICE enableaaa authorization config-commandsaaa authorization exec default group TACSERVICE if-authenticatedaaa authorization commands 15 default group TACSERVICE if-authenticatedaaa accounting send stop-record authentication failureaaa accounting exec default start-stop group TACSERVICEaaa accounting commands 15 default start-stop group TACSERVICESome Cisco devices don't like receiving attributes they don't expect, unless you configure the device with
tacacs-server attribute allow unknown
Kind regards,
Daniel
I add option "skip missing groups = yes" in config:
but situation has not changed.
I noticed another strange situation. When I log from console it's all ok, problems arise when I use telnet and ssh.
Oct 5 14:25:15 s-tacacs01 tac_plus[4720]: startup (version 201509121904)Oct 5 14:25:21 s-tacacs01 tac_plus[4668]: SIGHUP: restartingOct 5 14:25:21 s-tacacs01 tac_plus[4668]: startup (version 201509121904)Oct 5 14:25:21 s-tacacs01 tac_plus[4669]: Terminating, no longer needed.Oct 5 14:25:21 s-tacacs01 tac_plus[4726]: epoll event notification mechanism is being usedOct 5 14:25:21 s-tacacs01 tac_plus[4726]: bind to [::]:49 succeededOct 5 14:25:21 s-tacacs01 tac_plus[4727]: Version 201509121904 initializedOct 5 14:25:21 s-tacacs01 tac_plus[4727]: epoll event notification mechanism is being usedOct 5 14:25:48 s-tacacs01 tac_plus[4727]: 10.20.0.15: shell login for 'domainuser' from 10.0.0.10 on tty322 succeeded
2015-10-05 14:25:50 +0700 10.20.0.15 tty322 10.0.0.10 stop task_id=6 timezone=KRAST service=shell disc-cause=9 disc-cause-ext=38 pre-session-time=5 elapsed_time=0 stop_time=1444032558Oct 5 14:30:22 s-tacacs01 tac_plus[4727]: 10.20.0.15: shell login for 'domainuser' from async on tty0 succeededOct 5 14:31:03 s-tacacs01 tac_plus[4727]: 10.20.0.15: enable 15 for 'domainuser' from async on tty0 succeeded2015-10-05 14:30:22 +0700 10.20.0.15 domainuser tty0 async start task_id=7 timezone=KRAST service=shell
*Oct 5 16:01:07: AAA/BIND(00000003): Bind i/f*Oct 5 16:05:51: AAA/BIND(00000005): Bind i/f*Oct 5 16:05:51: AAA/AUTHEN/LOGIN (00000005): Pick method list 'default'*Oct 5 16:05:51: TPLUS: Queuing AAA Authentication request 5 for processing*Oct 5 16:05:51: TPLUS: processing authentication start request id 5*Oct 5 16:05:51: TPLUS: Authentication start packet created for 5(domainuser)*Oct 5 16:05:51: TPLUS: Using server 10.10.0.20*Oct 5 16:05:51: TPLUS(00000005)/1/NB_WAIT/45F1CB58: Started 5 sec timeout*Oct 5 16:05:51: TPLUS(00000005)/1/NB_WAIT: socket event 2*Oct 5 16:05:51: TPLUS(00000005)/1/NB_WAIT: wrote entire 53 bytes request*Oct 5 16:05:51: TPLUS(00000005)/1/READ: socket event 1*Oct 5 16:05:51: TPLUS(00000005)/1/READ: Would block while reading*Oct 5 16:05:51: TPLUS(00000005)/1/READ: socket event 1*Oct 5 16:05:51: TPLUS(00000005)/1/READ: read entire 12 header bytes (expect 68 bytes data)*Oct 5 16:05:51: TPLUS(00000005)/1/READ: socket event 1*Oct 5 16:05:51: TPLUS(00000005)/1/READ: read entire 80 bytes response*Oct 5 16:05:51: TPLUS(00000005)/1/45F1CB58: Processing the reply packet*Oct 5 16:05:51: TPLUS: Received authen response status GET_PASSWORD (8)*Oct 5 16:05:54: TPLUS: Queuing AAA Authentication request 5 for processing*Oct 5 16:05:54: TPLUS: processing authentication continue request id 5*Oct 5 16:05:54: TPLUS: Authentication continue packet generated for 5*Oct 5 16:05:54: TPLUS(00000005)/1/WRITE/45F1CB58: Started 5 sec timeout*Oct 5 16:05:54: TPLUS(00000005)/1/WRITE: wrote entire 27 bytes request*Oct 5 16:05:54: TPLUS(00000005)/1/READ: socket event 1*Oct 5 16:05:54: TPLUS(00000005)/1/READ: read entire 12 header bytes (expect 26 bytes data)*Oct 5 16:05:54: TPLUS(00000005)/1/READ: socket event 1*Oct 5 16:05:54: TPLUS(00000005)/1/READ: read entire 38 bytes response*Oct 5 16:05:54: TPLUS(00000005)/1/45F1CB58: Processing the reply packet*Oct 5 16:05:54: TPLUS: Received authen response status FAIL (3)*Oct 5 16:05:56: %SEC_LOGIN-4-LOGIN_FAILED: Login failed [user: domainuser] [Source: 10.0.0.10] [localport: 22] [Reason: Login Authentication Failed] at 16:05:56 KRAST Mon Oct 5 2015*Oct 5 16:05:56: AAA/AUTHEN/LOGIN (00000005): Pick method list 'default'*Oct 5 16:05:56: TPLUS: Queuing AAA Authentication request 5 for processing*Oct 5 16:05:56: TPLUS: processing authentication start request id 5*Oct 5 16:05:56: TPLUS: Authentication start packet created for 5(domainuser)*Oct 5 16:05:56: TPLUS: Using server 10.10.0.20*Oct 5 16:05:56: TPLUS(00000005)/1/NB_WAIT/45F1CB58: Started 5 sec timeout*Oct 5 16:05:56: TPLUS(00000005)/1/NB_WAIT: socket event 2*Oct 5 16:05:56: TPLUS(00000005)/1/NB_WAIT: wrote entire 53 bytes request*Oct 5 16:05:56: TPLUS(00000005)/1/READ: socket event 1*Oct 5 16:05:56: TPLUS(00000005)/1/READ: Would block while reading*Oct 5 16:05:56: TPLUS(00000005)/1/READ: socket event 1*Oct 5 16:05:56: TPLUS(00000005)/1/READ: read entire 12 header bytes (expect 68 bytes data)*Oct 5 16:05:56: TPLUS(00000005)/1/READ: socket event 1*Oct 5 16:05:56: TPLUS(00000005)/1/READ: read entire 80 bytes response*Oct 5 16:05:56: TPLUS(00000005)/1/45F1CB58: Processing the reply packet*Oct 5 16:05:56: TPLUS: Received authen response status GET_PASSWORD (8)*Oct 5 16:16:38: AAA/BIND(00000008): Bind i/f*Oct 5 16:16:38: AAA/AUTHEN/LOGIN (00000008): Pick method list 'default'*Oct 5 16:16:38: TPLUS: Queuing AAA Authentication request 8 for processing*Oct 5 16:16:38: TPLUS: processing authentication start request id 8*Oct 5 16:16:38: TPLUS: Authentication start packet created for 8()*Oct 5 16:16:38: TPLUS: Using server 10.10.0.20*Oct 5 16:16:38: TPLUS(00000008)/0/NB_WAIT/45E792C8: Started 5 sec timeout*Oct 5 16:16:38: TPLUS(00000008)/0/NB_WAIT: socket event 2*Oct 5 16:16:38: TPLUS(00000008)/0/NB_WAIT: wrote entire 39 bytes request*Oct 5 16:16:38: TPLUS(00000008)/0/READ: socket event 1*Oct 5 16:16:38: TPLUS(00000008)/0/READ: Would block while reading*Oct 5 16:16:38: TPLUS(00000008)/0/READ: socket event 1*Oct 5 16:16:38: TPLUS(00000008)/0/READ: read entire 12 header bytes (expect 68 bytes data)*Oct 5 16:16:38: TPLUS(00000008)/0/READ: socket event 1*Oct 5 16:16:38: TPLUS(00000008)/0/READ: read entire 80 bytes response*Oct 5 16:16:38: TPLUS(00000008)/0/45E792C8: Processing the reply packet*Oct 5 16:16:38: TPLUS: Received authen response status GET_USER (7)*Oct 5 16:16:43: TPLUS: Queuing AAA Authentication request 8 for processing*Oct 5 16:16:43: TPLUS: processing authentication continue request id 8*Oct 5 16:16:43: TPLUS: Authentication continue packet generated for 8*Oct 5 16:16:43: TPLUS(00000008)/0/WRITE/45FC1260: Started 5 sec timeout*Oct 5 16:16:43: TPLUS(00000008)/0/WRITE: wrote entire 31 bytes request*Oct 5 16:16:43: TPLUS(00000008)/0/READ: socket event 1*Oct 5 16:16:43: TPLUS(00000008)/0/READ: read entire 12 header bytes (expect 16 bytes data)*Oct 5 16:16:43: TPLUS(00000008)/0/READ: socket event 1*Oct 5 16:16:43: TPLUS(00000008)/0/READ: read entire 28 bytes response*Oct 5 16:16:43: TPLUS(00000008)/0/45FC1260: Processing the reply packet*Oct 5 16:16:43: TPLUS: Received authen response status GET_PASSWORD (8)*Oct 5 16:16:46: TPLUS: Queuing AAA Authentication request 8 for processing*Oct 5 16:16:46: TPLUS: processing authentication continue request id 8*Oct 5 16:16:46: TPLUS: Authentication continue packet generated for 8*Oct 5 16:16:46: TPLUS(00000008)/0/WRITE/45FC1260: Started 5 sec timeout*Oct 5 16:16:46: TPLUS(00000008)/0/WRITE: wrote entire 28 bytes request*Oct 5 16:16:46: TPLUS(00000008)/0/READ: socket event 1*Oct 5 16:16:46: TPLUS(00000008)/0/READ: read entire 12 header bytes (expect 6 bytes data)*Oct 5 16:16:46: TPLUS(00000008)/0/READ: socket event 1*Oct 5 16:16:46: TPLUS(00000008)/0/READ: read entire 18 bytes response*Oct 5 16:16:46: TPLUS(00000008)/0/45FC1260: Processing the reply packet*Oct 5 16:16:46: TPLUS: Received authen response status PASS (2)*Oct 5 16:16:46: %SEC_LOGIN-5-LOGIN_SUCCESS: Login Success [user: domainuser] [Source: 10.0.0.10] [localport: 23] at 16:16:46 KRAST Mon Oct 5 2015*Oct 5 16:16:46: AAA/AUTHOR (0x8): Pick method list 'default'*Oct 5 16:16:46: TPLUS: Queuing AAA Authorization request 8 for processing*Oct 5 16:16:46: TPLUS: processing authorization request id 8*Oct 5 16:16:46: TPLUS: Protocol set to None .....Skipping*Oct 5 16:16:46: TPLUS: Sending AV service=shell*Oct 5 16:16:46: TPLUS: Sending AV cmd**Oct 5 16:16:46: TPLUS: Authorization request created for 8(domainuser)*Oct 5 16:16:46: TPLUS: using previously set server 10.10.0.20 from group TACSERVICE*Oct 5 16:16:46: TPLUS(00000008)/0/NB_WAIT/45FC1260: Started 5 sec timeout*Oct 5 16:16:46: TPLUS(00000008)/0/NB_WAIT: socket event 2*Oct 5 16:16:46: TPLUS(00000008)/0/NB_WAIT: wrote entire 72 bytes request*Oct 5 16:16:46: TPLUS(00000008)/0/READ: socket event 1*Oct 5 16:16:46: TPLUS(00000008)/0/READ: Would block while reading*Oct 5 16:16:46: TPLUS(00000008)/0/READ: socket event 1*Oct 5 16:16:46: TPLUS(00000008)/0/READ: read entire 12 header bytes (expect 6 bytes data)*Oct 5 16:16:46: TPLUS(00000008)/0/READ: socket event 1*Oct 5 16:16:46: TPLUS(00000008)/0/READ: read entire 18 bytes response*Oct 5 16:16:46: TPLUS(00000008)/0/45FC1260: Processing the reply packet*Oct 5 16:16:46: TPLUS: received authorization response for 8: FAIL*Oct 5 16:16:46: AAA/AUTHOR/EXEC(00000008): Authorization FAILED*Oct 5 16:16:48: TPLUS: Queuing AAA Accounting request 8 for processing*Oct 5 16:16:48: TPLUS: processing accounting request id 8*Oct 5 16:16:48: TPLUS: Sending AV task_id=13*Oct 5 16:16:48: TPLUS: Sending AV timezone=KRAST*Oct 5 16:16:48: TPLUS: Sending AV service=shell*Oct 5 16:16:48: TPLUS: Sending AV disc-cause=9*Oct 5 16:16:48: TPLUS: Sending AV disc-cause-ext=38*Oct 5 16:16:48: TPLUS: Sending AV pre-session-time=9*Oct 5 16:16:48: TPLUS: Sending AV elapsed_time=0*Oct 5 16:16:48: TPLUS: Sending AV stop_time=1444036608*Oct 5 16:16:48: TPLUS: Accounting request created for 8()*Oct 5 16:16:48: TPLUS: using previously set server 10.10.0.20 from group TACSERVICE*Oct 5 16:16:48: TPLUS(00000008)/0/NB_WAIT/45FC1260: Started 5 sec timeout*Oct 5 16:16:48: TPLUS(00000008)/0/NB_WAIT: socket event 2*Oct 5 16:16:48: TPLUS(00000008)/0/NB_WAIT: wrote entire 166 bytes request*Oct 5 16:16:48: TPLUS(00000008)/0/READ: socket event 1*Oct 5 16:16:48: TPLUS(00000008)/0/READ: Would block while reading*Oct 5 16:16:48: TPLUS(00000008)/0/READ: socket event 1*Oct 5 16:16:48: TPLUS(00000008)/0/READ: read entire 12 header bytes (expect 5 bytes data)*Oct 5 16:16:48: TPLUS(00000008)/0/READ: socket event 1*Oct 5 16:16:48: TPLUS(00000008)/0/READ: read entire 17 bytes response*Oct 5 16:16:48: TPLUS(00000008)/0/45FC1260: Processing the reply packet*Oct 5 16:16:48: TPLUS: Received accounting response with status PASS*Oct 5 16:21:30: AAA/BIND(0000000B): Bind i/f*Oct 5 16:21:30: AAA/AUTHEN/LOGIN (0000000B): Pick method list 'default'*Oct 5 16:21:30: TPLUS: Queuing AAA Authentication request 11 for processing*Oct 5 16:21:30: TPLUS: processing authentication start request id 11*Oct 5 16:21:30: TPLUS: Authentication start packet created for 11()*Oct 5 16:21:30: TPLUS: Using server 10.10.0.20*Oct 5 16:21:30: TPLUS(0000000B)/0/NB_WAIT/45E792C8: Started 5 sec timeout*Oct 5 16:21:30: TPLUS(0000000B)/0/NB_WAIT: socket event 2*Oct 5 16:21:30: TPLUS(0000000B)/0/NB_WAIT: wrote entire 39 bytes request*Oct 5 16:21:30: TPLUS(0000000B)/0/READ: socket event 1*Oct 5 16:21:30: TPLUS(0000000B)/0/READ: Would block while reading*Oct 5 16:21:30: TPLUS(0000000B)/0/READ: socket event 1*Oct 5 16:21:30: TPLUS(0000000B)/0/READ: read entire 12 header bytes (expect 68 bytes data)*Oct 5 16:21:30: TPLUS(0000000B)/0/READ: socket event 1*Oct 5 16:21:30: TPLUS(0000000B)/0/READ: read entire 80 bytes response*Oct 5 16:21:30: TPLUS(0000000B)/0/45E792C8: Processing the reply packet*Oct 5 16:21:30: TPLUS: Received authen response status GET_USER (7)*Oct 5 16:21:34: TPLUS: Queuing AAA Authentication request 11 for processing*Oct 5 16:21:34: TPLUS: processing authentication continue request id 11*Oct 5 16:21:34: TPLUS: Authentication continue packet generated for 11*Oct 5 16:21:34: TPLUS(0000000B)/0/WRITE/45FD835C: Started 5 sec timeout*Oct 5 16:21:34: TPLUS(0000000B)/0/WRITE: wrote entire 31 bytes request*Oct 5 16:21:34: TPLUS(0000000B)/0/READ: socket event 1*Oct 5 16:21:34: TPLUS(0000000B)/0/READ: read entire 12 header bytes (expect 16 bytes data)*Oct 5 16:21:34: TPLUS(0000000B)/0/READ: socket event 1*Oct 5 16:21:34: TPLUS(0000000B)/0/READ: read entire 28 bytes response*Oct 5 16:21:34: TPLUS(0000000B)/0/45FD835C: Processing the reply packet*Oct 5 16:21:34: TPLUS: Received authen response status GET_PASSWORD (8)*Oct 5 16:21:36: TPLUS: Queuing AAA Authentication request 11 for processing*Oct 5 16:21:36: TPLUS: processing authentication continue request id 11*Oct 5 16:21:36: TPLUS: Authentication continue packet generated for 11*Oct 5 16:21:36: TPLUS(0000000B)/0/WRITE/45FD835C: Started 5 sec timeout*Oct 5 16:21:36: TPLUS(0000000B)/0/WRITE: wrote entire 26 bytes request*Oct 5 16:21:36: TPLUS(0000000B)/0/READ: socket event 1*Oct 5 16:21:36: TPLUS(0000000B)/0/READ: read entire 12 header bytes (expect 26 bytes data)*Oct 5 16:21:36: TPLUS(0000000B)/0/READ: socket event 1*Oct 5 16:21:36: TPLUS(0000000B)/0/READ: read entire 38 bytes response*Oct 5 16:21:36: TPLUS(0000000B)/0/45FD835C: Processing the reply packet*Oct 5 16:21:36: TPLUS: Received authen response status FAIL (3)*Oct 5 16:21:38: %SEC_LOGIN-4-LOGIN_FAILED: Login failed [user: ] [Source: 10.0.0.10] [localport: 23] [Reason: Login Authentication Failed] at 16:21:38 KRAST Mon Oct 5 2015*Oct 5 16:21:38: AAA/AUTHEN/LOGIN (0000000B): Pick method list 'default'*Oct 5 16:21:38: TPLUS: Queuing AAA Authentication request 11 for processing*Oct 5 16:21:38: TPLUS: processing authentication start request id 11*Oct 5 16:21:38: TPLUS: Authentication start packet created for 11()*Oct 5 16:21:38: TPLUS: Using server 10.10.0.20*Oct 5 16:21:38: TPLUS(0000000B)/0/NB_WAIT/45FD835C: Started 5 sec timeout*Oct 5 16:21:38: TPLUS(0000000B)/0/NB_WAIT: socket event 2*Oct 5 16:21:38: TPLUS(0000000B)/0/NB_WAIT: wrote entire 39 bytes request*Oct 5 16:21:38: TPLUS(0000000B)/0/READ: socket event 1*Oct 5 16:21:38: TPLUS(0000000B)/0/READ: Would block while reading*Oct 5 16:21:38: TPLUS(0000000B)/0/READ: socket event 1*Oct 5 16:21:38: TPLUS(0000000B)/0/READ: read entire 12 header bytes (expect 68 bytes data)*Oct 5 16:21:38: TPLUS(0000000B)/0/READ: socket event 1*Oct 5 16:21:38: TPLUS(0000000B)/0/READ: read entire 80 bytes response*Oct 5 16:21:38: TPLUS(0000000B)/0/45FD835C: Processing the reply packet*Oct 5 16:21:38: TPLUS: Received authen response status GET_USER (7)I would try adding
aaa authorization console
I would try adding