Cisco AAA/Identity/Nac :: ASA 5520 / Username Does Not Show In CLI And ACS Logs

Aug 3, 2011

Why my asa5520 brings out:

sh curpriv
Username : enable_15
Current privilege level : 15
Current Mode/s : P_PRIV
 
while i am logging in with my username which is XXXX. And in my ACS accounting logs I cannot see which user did what.

View 2 Replies


ADVERTISEMENT

Cisco :: LMS 4.0.1 / UTLite Script Doesn't Show Username

Sep 7, 2011

I Have installed LMS 4.0.1 for my client. I have also installed UTLite script on the domain controller as per instruction from cisco. When i look at the utlite.log i'm seeing message displayed below:
 
Failed to create Tables. Transaction Rolled back
Failed to create Tables. Transaction Rolled back
: com.sybase.jdbc2.jdbc.SybSQLException: SQL Anywhere Error -110: Item 'getAuthenticatedUsers_ACS' already exists
Intializing the Controler 9 = skt Pkg = com.cisco.nm.cm.ut.ctrlplane.ctrls.SocketCtrl
2011/08/25 14:59:14 main utlite INFO SocketListener: Socket Listener : Port : 16236
Started Socket Listener

[code]....

View 2 Replies View Related

Cisco Switching/Routing :: 2950 Getting Error Messages In Show Logs

Aug 15, 2011

I m getting below error messages in show logs -
 
Aug 12  15:30:57.127 IST: %ENVIRONMENT-3-RPS_FAILED: Faulty internal power supply  detected  
Aug 12 15:31:02.175  IST: %ENVIRONMENT-3-RPS_FAILED: Faulty internal power supply detected  
Aug  12 15:31:08.219 IST: %ENVIRONMENT-3-RPS_FAILED: Faulty internal power supply  detected  
Aug 12 15:31:10.239  IST: %ENVIRONMENT-3-RPS_FAILED: Faulty internal power supply detected 
 
there is no error messages related to PSU in "show env all " log  .
 
here is show version -
------------------ show version ------------------
 
Cisco Internetwork Operating System Software
IOS (tm) C2950 Software (C2950-I6K2L2Q4-M), Version 12.1(22)EA13, RELEASE SOFTWARE (fc2)
Technical Support: [URL]
Copyright (c) 1986-2009 by cisco Systems, Inc.
[Code] ....

View 8 Replies View Related

Cisco Wireless :: 7.0.220 / Apple Clients Authenticated But Show No Username In WLC

Aug 1, 2012

Running 7.0.220. There are several 'unknown' users every day reported in WCS. Investigating the connections on the WLC I find the clients are in a run state and passing traffic but there is no username listed on the client detail. (hence the unknown on WCS)
 
(mcm-189jsoc-wlc1) >show client detail 60:c5:47:07:b6:5a
Client MAC Address............................... 60:c5:47:07:b6:5a
Client Username ................................. N/A
AP MAC Address................................... 00:1e:13:42:16:a0
AP Name.......................................... mcm-208dorm-wap1

[code].....
 
Clients in this state are usually Apple products. From initial investigation it looks like the do authenticate with the ACS. r debugs to run, or fixes on the WLC? Perhaps there's a bug on this behavior?

View 11 Replies View Related

Cisco WAN :: ASA 5520 How To Get Old Logs From Router

Nov 4, 2012

I am running two ASA 5520 routers synched up with eachother. I had a massive connectivity issue this weekend that I am investigating. Now I have figured out how to get the live logging but I need to know how to get the old logs from my router.

View 4 Replies View Related

Cisco Firewall :: 5520 ASDM 6.4 And ASA Not Showing Logs

Feb 27, 2011

We’ve got lot of ASA appliances (around 30, 5505/5510/5520) and we never had this problem since the use of the new image software ASA 8.4(1) and ASDM 6.4(1). So, my problem is located on two ASA 5520 with active/passive failover with ASA image 8.4(1) and ASDM image 6.4(1).
 
My problem is that our appliance doesn’t show any logs when an ACL deny a packet, even if when I specify a specific “deny ACL” with a specific logging condition, asdm and ssh buffer logging are empty but the counters of the ACL increment.

View 6 Replies View Related

Cisco VPN :: 5520 - Incorrect TCP Session Logs For Remote VPN Users On ASA

Oct 29, 2012

I have a problem on a Cisco ASA5520 version 8.2(5). A customer has set up a syslog to keep tracks of tcp sessions made by vpn users. On the syslog we filter %ASA-6-302013 and %ASA-6-302014 log messages, respectively: Built inbound TCP connection and Teardown TCP connection. When the connection is made by a vpn user, at the end of the log line you see the vpn username which should be the same in both the messages for the same connection. I have verified that when a user, let's say UserA, disconnects from the vpn, their tcp sessions are not properly closed; if another user, let's say UserB, establish a VPN immeditaely after and gets the same IP address previously assigned to UserA, the log sessions are recored with UserA in the %ASA-6-302013 message and UserB in the %ASA-6-302014 message. I presume this is due to the fact the tcp sessions are not tore down when the first user disconnects and it looks like a bug to me but I didn't find it referenced anywhere. Is there a way to have all tcp session tore down when a user disconnects the VPN connection?

View 2 Replies View Related

Cisco Firewall :: ASA 5520 Logs In RealTime Viewer Delayed

Jul 11, 2011

I have a newish instance of 5520 running.  I am seeing some odd logging issues in that the logs are significantly delayed showing up in the real time viewer.  I'll try to connect, say on remote desktop, and will not see the traffic in the viewer for up to 20 seconds or so after I'm already connected to the server.  I have not seen this before. 

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Unable To Use ACS 5.2 With Logs?

Sep 6, 2011

I have 3 ACS servers placed throughout N. America. I it set up so that ACS01 is primary and ACS02 and ACS03 are secondary. When i look at the logs for passed/failed authentications in radius or tacacs I cannot see anything from ACS03 logging. This is weird because just a few weeks ago it worked perfectly. In fact, ACS03 is the most active server since this site is using it for wireless phones and tacacs and the other 2 are just using ACS for wireless networking. I went through the log settings and every server is set up the same as the others (except the primary) so it should be logging ACS03 the exact same as 01 and 02.Anyway it seems like a small problem but i need the logs to work correctly to properly administrate security.

View 1 Replies View Related

Cisco VPN :: ASA-5520 Logs 713201 Duplicate Phase 2 Packet Detected

Feb 8, 2012

Got a classical remote access vpn with Cisco VPN Client and ASA-5520, Some weeks ago I noticed in my ASA logs this severity 5 Message. Group = xyz, Username = abc, IP = 84.n.n.n, Duplicate Phase 2  packet detected. No last packet to retransmit. This message comes with every connect, but then connections works fine.

Remark: See ASA ADSM:

- 1. Duplicated Phase II (!!)
- 2. Phase I
- 3. Phase II

View 4 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Logs Are Not Showing MAC Address?

May 10, 2012

We recently had to rebuild our ACS server.  Now when we have an 802.1x authentication failure and look at the RADIUS logs for the specific user, it does not show us the MAC address of the device the user tried to login with.  We use this all the time because users have PDAs and other mobile devices that they save their passwords on.  Then when they change their domain password on their laptop, they don't change it on their PDA which then tries to authenticate them using the wrong password and eventually locks them out.  We need to see the MAC address so we can pinpoint which device is causing the lockout.  The report I am generating is when you go to this location: Monitoring & Reports > ... > Reports > Catalog > User > User_Authentication_Summary

View 4 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 Tacacs Authorization Logs?

Jan 15, 2012

Noticed tacacs authorization logs when you change password for a user ?? in authorization logs I can see the new password but same I can not see in accounting logs ? is it a normal behaviour ?? or do we need to do something to hide the password in authorization logs ?
  
For example if i type command username xyz priv 15 secret cisco 123
 
I see this command in accounting logs as uername xyz oriv 15 secret *** where as in tacacs authorization logs it shows username xyz priv 15 secret cisco 123

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Manipulating Username In ACS 5.3

Aug 26, 2012

Does ACS 5.3 has a feature to allow you to change or otherwise manipulate a user-name value within ACS as an authentication request comes into the system.
 
We want to use ACS to authenticate users to a particular device, but the device does not allow us to have username's in the format that we require, and the rest of our systems allow and require.
 
We want a way of manipulating the user ID of someone logging into the system, so that when the authentication request hits the ACS their username is massaged into the format we require, before being further processed against identity policies etc.

View 5 Replies View Related

AAA/Identity/Nac :: Cisco ACS 4.2 - Historic Logs For Passed Authentications

Mar 23, 2012

I have cisco ACS 4.2 (1) build 15 working fine, but it can save historic logs for Passed Authentications, Failed attempts. etc.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: 1120 - Error Opening Acs Logs

Mar 6, 2013

I have problem with ACS 5.0 on reporting.  On "Monitoring and Report" page  in  Faverite Reports when i clicking on "Authentications - RADIUS - Today", My browser displays error "Error while reading skin-access.config. Please make sure the file exists and conforms to the schema specified"
 
I must also mention that I never upgraded the version of ACS from 5.0 also from command line all the acs services are running. It is running on CISCO 1120 Secure Access Controll Server apliance.
 
My second question is can I upgrade the version of ACS to 5.4 with Cisco Secure ACS 5 Base License?

View 4 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 Has Stopped Authentication Logs After Reboot?

Dec 28, 2011

I have saved the running configuration to startup first and rebooted the ACS 5.1. Since then it has stopped Authentication logs, though I can login to the network devices using Tacacs login, but I am not getting Tacacs authentication logs ?

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS Version 5.2.0.26 / Failed MAB Authentication Logs

Jan 8, 2013

Having an issue where a user will plug a PC into a switch.  The switch does a MAB authenticaiton and the MAC is not located in the ACS server.  It logs the failed attempt, but when the PC is removed from the switch, the failed attempts keep getting logged until the port is bounced.  Any way to keep the attemps from happening after the PC is removed?  If not, any way to make it stop without bouncing the port?
 
running ACS version 5.2.0.26
 
switch port config: 
interface GigabitEthernet1/0/2
sw access vlan 2 sw mode access
authentication control-direction in
authenticaion host-mode multi-auth
authentication port-control auto
mab
spanning-tree portfast

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS V5.2 / Can Configure User Authentication Logs To Be Viewed On WCS

Jul 18, 2011

I have some queries regarding on the report generation for on Cisco ACS v5.2.
 
1) Can we schedule to run a customized report on ACS and then email the report to the user?
 
2) Can we run a users authentication trend report based on the AD directory group rather than individual user.
 
3) Can we configure user authentication logs to be viewed on WCS.

View 6 Replies View Related

Cisco AAA/Identity/Nac :: CiscoSecure ACS V4.2 RADIUS Logs Upload To FTP Server

Apr 24, 2013

I am using CiscoSecure ACS v4.2 appliance, in there any way that RADIUS logs upload to FTP server because it has limitation to store RADIUS logs.

View 15 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5. 2 Secondary Server Is Not Collecting Logs From Primary

Nov 2, 2011

Cisco ACS 5.2 secondary  server is configured as a log collector for both primary and secondary server .Now i am facing problem in log collection from primary server .ACS secondary server is not collecting any logs from primary .

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.4 - Audit Logs Operated By Secondary Instance?

Mar 28, 2013

I'm using ACS 5.4p2 within distributed systems: one primary and one secondary instance.For now, primary instance is acting as Log Collector server and I can see any AAA audit logs.

When the primary instance fails I can authenticate successfully using the secondary instance.However, when primary instance comes back, I'm not able to see any audit logs operated by secondary.

View 9 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 - External Proxy Service User Logs?

Apr 11, 2012

We are currently using Cisco ACS 5.3.0.40.2. One of the Services Selection Policy it hosts is:
 
Receive Authentication request from a wireless controller for a wireless userIf the wireless user's username contains a particular domain suffix, the request is proxied to an external proxy server using an External Proxy service (configured for both local/remote accounting)On receiving an Acccess-Accept from the external proxy, the user is given access and ACS 5 will start logging account packets for the username (nothing appears in the RADIUS authentication logs - ACS 5 it seems doesn't log proxied authentication requests) The above setup works fine in most instances. We start to have problems when an external proxy server strips the domain suffix off the username in the Access-Accept packet e.g.
 
ACS 5 proxies an Access-Request to an external proxy server (with Username = someuser@somwhere.com)The external proxy replies with an Access-Accept (with Username = someuser)The user 'someuser' is given access but subsequent accounting attempts fail because their username (without the domain suffix) doesn't match the Service Selection PolicyIs there any way to get ACS 5.3 to log proxied authentication requests? If not, can I configure ACS 5.3 to use the username in the Access-Request packet (rather than the username in the Access-Accept packet) for accounting?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 - Delete Accounting / Authorization Reports Or Logs?

Oct 5, 2011

How to delete the accounting/authorization Reports or logs ?

View 2 Replies View Related

AAA/Identity/Nac :: ACS V5.1 View Not Showing Full Admin Logs?

May 18, 2011

I am having trouble viewing all the Administration logs in ACS View. I have my Local Log Target set to a Maximum log retention period of 90 days. In ACS View I can display authentications that go back 90 days + However when I try and display the "ACS_Configuration_Audit" in View and perform a Custom query that goes back 90 days it will only display about 35 days of Admin logs.I know the logs are there because when I go into CLI and do a search like "show logging | i "ObjectType=Administrator Account" the Administration logs go back over a year.why ACS View cannot display all the Admin logs?The ACS is running v5.1.0.44 Patch 6 (Also experiencing this in a v5.2 ACS as well)

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ISG2000 AAA Sec01 Username With IP Binding

Apr 7, 2011

We're using AAA Sec4.1 and we need to bind the username with IP address for remote VPNs configured on Netscreen ISG2000 firewall. We want AAA should check two things against any user first IP address and second Username in order to authenticate the users.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Rename Existing Username On ACS 4.2 Application

Mar 22, 2011

how can we rename an existing username on ACS 4.2 Application.I don't want to rename the group just the username.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 - Turning Off Username Case Sensitivity?

Mar 27, 2011

we have a new ACS 5.2 server, and are having a problem with the case sensitivity of ACS. Basically, what is happening is that some users are capitalizing the first letter of their AD username, and it's causing ACS to deny their access due to the case of their username. For example:
 
Username yyy0h22 grants admin access to a device. However, Username Yyy0h22 denies access to a device.
 
Is there a way to make it so that no matter uppercase or lowercase, we are giving this person access? Without having to make a different rule for each permutation?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 - Exclude Reporting For Specific Username?

May 16, 2011

I'd like to know if there is a way to exclude passed authentications for a specific username from reporting in the Authentications-TACACS and Authentications-RADIUS reports?
 
We have a few usernames that are used in scheduled jobs.  We only need to know when they fail authentication, so we don't need to fill up the reports with every passed authentication from these accounts.  Can this be done?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.2 / Logs Are Lost Frequently In Remote Agent Server

May 2, 2013

ACS 4.2 and remote agent was working properly two months before. But in past two months we are facing weird issue in RA server.For Somedays we are missing logs from both ACS and RA server. Once we notice this we use to restart the services in ACS to give workaround. But due to this we loose our daily logs intermittently and facing risk in without having logs.This is not like communication between ACS and RA is not at all happening. It happens properly for a week or month, but again it is going bad without any config change. CSAgent.ini file is properly configured.Full version is 4.2.1.15 and patch is 10 in acs and ra.ACS and Remote Agent Major and Patch version are same.

View 5 Replies View Related

AAA/Identity/Nac :: ACS 5.41 Same Username With Two Different Group / Shell Profiles

Mar 23, 2013

In my ACS 5.4 I want to have same useranme to use two shell profiles. Here is the requirement.One shell profile with privelege 15 for IOS device admin and other one with different privelege for WCS admin.As there can't have two shell profiles on the same authroization profile, I created two different profiles, and match with the ACS local group name. However whenever user tries to access it always hits the 1st profiles.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: Change Username In Active Directory Configure In ACS 5.3?

Mar 15, 2012

I need to change the username and password ACS uses to connect to AD.   I do a "clear configuration" and reboot and am unable to join the ACS appliance back into my AD with a different username and password.  I am able to rejoin the ACS machine to the domain using the original username and pass. how to clear all of the AD config off of the appliance and start fresh and use a new account to join AD?

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ASA 5510 / SSH Local Database Username And Password Not Working?

Feb 28, 2012

I have a weird issue. I recently setup an ASA 5510 and had SSH working. To make it easier on my VPN users I then decided I wanted to setup a Windows 2008 Network Policy Server for RADIUS authentication. Ever since I added the RADIUS part to aaa authentication, when I use SSH to connect to the ASA it will not take the local user name and password I have setup. I can however get in using a Domain user name and password. Below is the SSH and AAA configuration. Am I missing something here? The username and password in the ASA is not on the domain and it's like the ASA is not even trying LOCAL when it tries to authenticate. I want it to use the local username and password if possible. I'm kind of new to ASA's..
 
On another note, I have never been able to SSH in on the internal interface. I always get a "The remote system refused the connection" error message. I can only use the outside interface.
 
Site-ASA# sh run | in ssh
aaa authentication ssh console SERVER_RADIUS LOCAL
ssh 0.0.0.0 0.0.0.0 outside
ssh 0.0.0.0 0.0.0.0 inside
ssh timeout 60

[code]....

View 2 Replies View Related

Cisco Firewall :: Show Active TCP Connections In ASA 5520?

Jun 5, 2013

how many active TCP sessions my ASA has but having a hard time finding this information.  When I do "show conn count" from the CLI it shows what I'm guessing is a sum of both TCP and UDP.  Is there any way to get just the TCP connections?

View 3 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved