2.4.6.5 Troubleshooting

Perform the following steps in case TACACS+ (Terminal Access Controller Access-Control System Plus) configuration fails or the TACACS+ user logins are rejected on any DSR server:
  1. Review configuration logs.
    1. On the active NOAM server, inspect /var/TKLC/log/tacacsAuthentication.log to verify any issues with the script invocation.
    2. If a host is marked as failed in the above log file, SSH into the node and verify /var/TKLC/log/tacacs/tacacsAdm.log for detailed error information.
  2. On the server where TACACS+ login fails, review the /var/log/secure file for TACACS+ related messages.
  3. From the affected DSR server, verify basic connectivity to each configured TACACS+ server running the following command:
    ping <tacacs_IP>