Security

Reply
MVP
Posts: 1,110
Registered: ‎10-11-2011

TACACS Authorization Fails - Big Cloud Fabric Controller

I setup a TACACS service to authenticate and authorize logins to a BCF controller.  The authentication  passes but I'm getting an alert about authorization is failing.  The alert error is "Tacacs service=shell:ip not enabled"; see attached pic for whole error.  Any thoughts?

=======================================
If a reply adequately addresses your issue, please click on the "Accept as Solution" and "Give Kudos" button so this information can benefit other users.
Guru Elite
Posts: 20,012
Registered: ‎03-29-2007

Re: TACACS Authorization Fails - Big Cloud Fabric Controller

Is authentication working without authorization?

Colin Joseph
Aruba Customer Engineering

Looking for an Answer? Search the Community Knowledge Base Here: Community Knowledge Base

Validated Reference Design Guides : http://community.arubanetworks.com/t5/Validated-Reference-Design/tkb-p/Aruba-VRDs
Aruba Employee
Posts: 10
Registered: ‎04-28-2009

Re: TACACS Authorization Fails - Big Cloud Fabric Controller

Navigate to the specific TACACS+ Enforcement profile in use and navigate to Services tab. Under Selected services, make sure 'Shell' is selected and try again. If this does not work, you may need to create and import a new TACACS dictionary(in xml) with the name 'shell:ip' that will have the attributes that Big Cloud Fabric controller is looking for. 

 

To import a TACACS dictionary, you may navigate to Administration --> Dictionaries --> Import. To get the xml tags, you may export any of the existing TACACS dictionary and replace its name and the attribute specific for this case.

 

 

 

 

MVP
Posts: 1,110
Registered: ‎10-11-2011

Re: TACACS Authorization Fails - Big Cloud Fabric Controller

That did the trick!  Thanks Vince.

 

In the "TacacsServiceDictionary" line, the name attribute was "BigSwitch".  I changed this to "shell:ip" and imported it.  Here's the whole thing for anyone that may have the same issue:

 

<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<TipsContents xmlns="http://www.avendasys.com/tipsapiDefs/1.0">
<TipsHeader exportTime="Wed Feb 10 21:15:00 CST 2016" version="1.0"/>
<TacacsServiceDictionaries>
<TacacsServiceDictionary dispName="Big Switch Networks" name="shell:ip">
<ServiceAttribute dataType="String" dispName="BSN User Role" name="BSN-User-Role"/>
</TacacsServiceDictionary>
</TacacsServiceDictionaries>
</TipsContents>

=======================================
If a reply adequately addresses your issue, please click on the "Accept as Solution" and "Give Kudos" button so this information can benefit other users.
Search Airheads
Showing results for 
Search instead for 
Did you mean: