On Wednesday 18 November 2009 06:40:39 pm Daniska, Tomas wrote: > Which one that was? We've been hit by a bug when using > TAC+ out of a VRF. Initial user authentication is OK, but > the subsequent enable auth outgoing packets do not have > the proper VRF set and go out the GRT instead. Funny > enough, the return packet returns via the VRF and the box > eats it.
In our case, using TACACS+ also, initial user authentications works fine, but the switch refuses to authenticate against the regular enable password and instead chooses the fallback password. In all honesty, we didn't debug this for too long because we only have 4 units in operation (core), were too busy with other stuff, and we could just work around it by adjusting RANCID's .cloginrc details (which were the most important). The issue is fixed in SXI2a (perhaps even earlier, in later versions post SXH3), and we didn't do anything to our TACACS+ backend. Cheers, Mark.
signature.asc
Description: This is a digitally signed message part.
_______________________________________________ cisco-nsp mailing list [email protected] https://puck.nether.net/mailman/listinfo/cisco-nsp archive at http://puck.nether.net/pipermail/cisco-nsp/
