Network Management

last person joined: yesterday 

Keep an informative eye on your network with HPE Aruba Networking network management solutions
Expand all | Collapse all

Troubleshooting TACACS+ on Airwave

This thread has been viewed 12 times
  • 1.  Troubleshooting TACACS+ on Airwave

    Posted Jan 27, 2015 10:49 AM

    I'm struggling to get Airwave integrated with our TACACS+ service (tac_plus from shrubbery networks) and I can't seem to find where Airwave is logging the TACACS+ communication so I can see why it is failing.  I see the requests on the server side but the client (AIrwave) isn't handling what my server is giving it properly.

     

    Does anyone know where the authentication is logged and if there is a debug option to run?

     

    I'm running AMP 8.0.5 if it matters.



  • 2.  RE: Troubleshooting TACACS+ on Airwave



  • 3.  RE: Troubleshooting TACACS+ on Airwave

    Posted Jan 27, 2015 11:09 AM

    I believe I am,  as I can confirm from my other devices that I have configured to use TACACS to send the role=Admin or the other roles I have configured.  But I can't find a way to put the tacacs service into debug mode in Airwave so that I can confirm see what the actual problem is.

     

    I am not using Cisco's ACS (as per your linked article) I am using the OSS implementation of tacacs developed by shrubbery networks.



  • 4.  RE: Troubleshooting TACACS+ on Airwave

    EMPLOYEE
    Posted Jan 27, 2015 01:47 PM

    From the AMP side, try looking in:

    /var/log/httpd/access_log

    This is the log of all inbound GUI access requests.

     

    Most GUI related errors typically show up in /var/log/httpd/error_log.

    If it's silent (UI hangs/no response), then possible /var/log/amp_events or messages



  • 5.  RE: Troubleshooting TACACS+ on Airwave

    Posted Jan 28, 2015 09:21 AM

    Nothing is logged in any of the below files during a failed tacacs log in.  What I included below is the only thing that is logged during a successful local login.

     

    access_log.2015-01-28

    --------------------------------

    [28/Jan/2015:09:18:56 -0500] "POST /LOGIN HTTP/1.1" 503 395

     

    error_log.2015-01-28

    --------------------------------

     

    amp_events

    --------------------------------

     

     



  • 6.  RE: Troubleshooting TACACS+ on Airwave

    EMPLOYEE
    Posted Jan 28, 2015 02:56 PM

    Hm...

    Try /var/log/pound.  Pound is the first hit before apache, so it's possible that the log may show something.

     

    If there's still nothing helpful in the log, then it's worth opening up a support case to try getting help tackling this.