Friday, March 4, 2011

Nexus 7000 CMP TACACS+ Login Failure

Problem Symptom:
When AAA authentication through TACACS+ is enabled upon the remote access to the Nexus 7000 Control Processor (CP), login to the CMP (Connectivity Management Processor) via Telnet using a valid TACACS+ username and password failed with the error message "User not known to the underlying authentication module".
Cisco Bug ID: CSCte25626

C:\>telnet 192.168.1.1

Linux 2.6.10_mvl401-pc_targetpspos (n7k-core-sw01-cmp6) (0)

n7k-core-sw01-cmp6 login: user1
Password:

User not known to the underlying authentication module


Connection to host lost.

C:\>

Resolution:
Reboot the CMPs using the reload cmp module slot privileged command on the CP.

Continuous ping to the management IP addresses of the CMPs will timeout for a short period. After the management IP addresses start replying to ICMP Echo Requests, login to the CMP using a valid TACACS+ account is then successful.

Linux 2.6.10_mvl401-pc_targetpspos (n7k-core-sw01-cmp6) (0)

n7k-core-sw01-cmp6 login: user1
Password:
n7k-core-sw01-cmp6#
n7k-core-sw01-cmp6# sh version
CMP Software:
  CMP BIOS version:        02.01.05
  CMP Image version:       4.2(1) [build 4.2(1)]
  CMP BIOS compile time:   7/13/2008 19:44:27
  CMP Image compile time:  1/5/2010 1:00:00
n7k-core-sw01-cmp6#

No comments:

Post a Comment