Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Varun142463
Explorer

TACACS+ Administrator Login: CLICMD0361 Failure setting current vrfid to 0 when transitioning to Exp

Issue Summary: When logging into a Check Point VSX Gateway using an external TACACS+ administrator account, attempting to switch from clish to the expert shell fails. Although the shell outputs the warning message, the context drops back to clish instead of opening the expert mode prompt, accompanied by a CLICMD0361 error.

expert
Enter expert password:

Warning! All configurations should be done through clish
You are in expert mode now.

CLICMD0361 Failure setting current vrfid to 0.

Background & Context:

  • This behavior only impacts external TACACS+ users mapped via AAA/RBA profiles (which inherently default to a non-zero UID).

  • Local super-users (uid=0) do not encounter this restriction.

  • Based on internal troubleshooting, this correlates closely with known limitations documented in sk115221 / sk184846 regarding non-root UIDs failing namespace/context handoffs in multi-context VSX setups.

Request for Support: Please advise on the recommended workaround or hotfix for external TACACS+ administrative accounts to successfully pass the VRF/VSID namespace boundary into Expert mode on VSX gateways, without dropping back to a non-root clish session. Specifically, is there a global TACACS+ UID mapping flag or specific attribute we should inject via our AAA server profile?

0 Kudos
0 Replies

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events