Forum Discussion
Lock out from Big IP after setting up Tacacs+
Is their any way to remove tacacs+ configuration from single user mode or roll back to local authentication mode.
We have lost root as well as admin access to the devices immediately after configuring tacacs+. The config synced to the standby pair and locked us out completely. We have attempted to reset the root password using single user mode but in vain.
We don't even see any hits on Cisco ACS from F5. We are using version 11.6.0.
Any ideas and advice is appreciated.
- mohammed_124031Nimbostratus
This procedure resolved the issue
sol12304: The TACACS+ secret key must not contain the pound sign () http://support.f5.com/kb/en-us/solutions/public/12000/300/sol12304.htmlp1
- Kevin_Davies_40Nacreous
Well according to that article you need to reboot into single user mode (SOL4178). Update /config/bigip.conf, replace tacacs with the word local.
system { auth source type tacacs }
Save and remove binary versions with
rm /var/db/mcpdb.*
Now reboot.
When the system comes up, verify you can login using admin user on the GUI. Push the config to the standby device.
- mohammed_124031NimbostratusWe think we hit the following bug sol12304. Attempting to carry out the recovery procedure.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com