Thanks for the info... we have allowed any network from 172.16.0.0/12 to be able to pass traffic through the ASA on port 49. I belive we have a license big enough to pass tcp traffic through I will check.
I have used Wireshark and this is what I got this
lines 3, 5, 6, 10, and 13 are the IP addresse of the tacacs source loopback so it is getting there picture is above
when I do term mon and debug tacacs packets this is what I get
so here is what I got by doing that
this comes up as soon as I try to connect to the host
IT_LAB-TACACS+#term mon
IT_LAB-TACACS+#debug tacacs packet
TACACS+ packets debugging is on
IT_LAB-TACACS+#
IT_LAB-TACACS+#
*Apr 11 18:55:17.531: T+: Version 192 (0xC0), type 1, seq 1, encryption 1
*Apr 11 18:55:17.531: T+: session_id 974847808 (0x3A1AFF40), dlen 26 (0x1A)
*Apr 11 18:55:17.531: T+: type:AUTHEN/START, priv_lvl:1 action:LOGIN ascii
*Apr 11 18:55:17.531: T+: svc:LOGIN user_len:0 port_len:6 (0x6) raddr_len:12 (0xC) data_len:0
*Apr 11 18:55:17.531: T+: user:
*Apr 11 18:55:17.531: T+: port: tty194
*Apr 11 18:55:17.531: T+: rem_addr: 172.18.36.64
*Apr 11 18:55:17.531: T+: data:
*Apr 11 18:55:17.531: T+: End Packet
IT_LAB-TACACS+#
This comes up when I try to use my tacacs username and pw
CODE --> =
*Apr 11 18:55:38.139: T+: Version 192 (0xC0), type 1, seq 1, encryption 1
*Apr 11 18:55:38.139: T+: session_id 493164964 (0x1D6519A4), dlen 26 (0x1A)
*Apr 11 18:55:38.139: T+: type:AUTHEN/START, priv_lvl:1 action:LOGIN ascii
*Apr 11 18:55:38.139: T+: svc:LOGIN user_len:0 port_len:6 (0x6) raddr_len:12 (0xC) data_len:0
*Apr 11 18:55:38.139: T+: user:
*Apr 11 18:55:38.139: T+: port: tty194
*Apr 11 18:55:38.139: T+: rem_addr: 172.18.36.64
*Apr 11 18:55:38.139: T+: data:
*Apr 11 18:55:38.139: T+: End Packet
IT_LAB-TACACS+#
IT_LAB-TACACS+#sh tacacs
Tacacs+ Server : 172.30.1.61/49
Socket opens: 14
Socket closes: 14
Socket aborts: 0
Socket errors: 0
Socket Timeouts: 2
Failed Connect Attempts: 0
Total Packets Sent: 13
Total Packets Recv: 0
IT_LAB-TACACS+#
On this router I am running DMVPN config.. any ideas?