<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TACACS authentication with Cisco ISE not working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/tacacs-authentication-with-cisco-ise-not-working/m-p/1229171#M124307</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/373635923"&gt;@fhassan&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Are these firewalls independent or part of an active/passive setup? If part of an active/passive pair, do you utilize the MGMT interface or do you have a service route configured to utilize a dataplane interface? &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If these are standalone make sure that ISE is actually accepting connections. Your error message indicates you aren't getting a return; I'm pretty sure that ISE won't respond to requests if the source address isn't included as a network device, so you'd want to check that the ISE side of this configuration is actually correct. &lt;/P&gt;</description>
    <pubDate>Thu, 15 May 2025 17:02:55 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2025-05-15T17:02:55Z</dc:date>
    <item>
      <title>TACACS authentication with Cisco ISE not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tacacs-authentication-with-cisco-ise-not-working/m-p/1229114#M124297</link>
      <description>&lt;P&gt;Hello, I would like to ask currently I have two firewall that needs to be configure TACACS. One of the firewall is working fine and I'm able to login using my credentials from ISE. However, another firewall is not working for the TACACS authentication. I have followed the same steps based on the working firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below here is the error I got when doing the test command:&lt;/P&gt;
&lt;P&gt;xx@Txx&amp;gt; test authentication authentication-profile Tacacs_auth_profile username xxxx password&lt;BR /&gt;Enter password :&lt;/P&gt;
&lt;P&gt;Target vsys is not specified, user "xxxx" is assumed to be configured with a shared auth profile.&lt;/P&gt;
&lt;P&gt;Do allow list check before sending out authentication request...&lt;BR /&gt;name "xxxx" has exact match in allow list&lt;/P&gt;
&lt;P&gt;Authentication to TACACS+ server at '10.x.x.x' for user 'xxxx'&lt;BR /&gt;Server port: 49, timeout: 5, flag: 0&lt;BR /&gt;Egress: 10.x.x.x&lt;BR /&gt;Attempting CHAP authentication ...&lt;BR /&gt;CHAP authentication request is created&lt;BR /&gt;Sending credential: xxxxxx&lt;BR /&gt;&lt;STRONG&gt;Failed to send CHAP authentication request: connect: timed out&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Returned status: -1&lt;/STRONG&gt;&lt;BR /&gt;Authentication/authorization failed against TACACS+ server at 10.x.x.x for user Axxx&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Appreciate the help on how I can troubleshoot this issue.&lt;/P&gt;</description>
      <pubDate>Thu, 15 May 2025 02:27:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tacacs-authentication-with-cisco-ise-not-working/m-p/1229114#M124297</guid>
      <dc:creator>fhassan</dc:creator>
      <dc:date>2025-05-15T02:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS authentication with Cisco ISE not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tacacs-authentication-with-cisco-ise-not-working/m-p/1229171#M124307</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/373635923"&gt;@fhassan&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Are these firewalls independent or part of an active/passive setup? If part of an active/passive pair, do you utilize the MGMT interface or do you have a service route configured to utilize a dataplane interface? &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If these are standalone make sure that ISE is actually accepting connections. Your error message indicates you aren't getting a return; I'm pretty sure that ISE won't respond to requests if the source address isn't included as a network device, so you'd want to check that the ISE side of this configuration is actually correct. &lt;/P&gt;</description>
      <pubDate>Thu, 15 May 2025 17:02:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tacacs-authentication-with-cisco-ise-not-working/m-p/1229171#M124307</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2025-05-15T17:02:55Z</dc:date>
    </item>
  </channel>
</rss>

