<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Radius Automated Test in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/radius-automated-test/m-p/2216397#M126326</link>
    <description>&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have performed the following configuration on one of my switch to test periodically the availability of ISE servers : &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;radius server ISE-1&lt;/P&gt;&lt;P&gt; address ipv4 1.2.3.4 auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt; key 0 toto123&lt;/P&gt;&lt;P&gt;automate-tester username radius-test idle-time 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username radius-test password toto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And on the ISE server I can see authentication failed with code &lt;/P&gt;&lt;P&gt; Authentication failed &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: &lt;/P&gt;&lt;P&gt; &lt;SPAN style="color: red; margin-top: 0pt;"&gt;22040 Wrong password or invalid shared secret&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sure about the shared secret because when I try test aaa group ....from the same switch it is ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the automated test expect a valid access accept response ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 26 Mar 2019 00:30:34 GMT</pubDate>
    <dc:creator>lionel.dupont</dc:creator>
    <dc:date>2019-03-26T00:30:34Z</dc:date>
    <item>
      <title>Radius Automated Test</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-automated-test/m-p/2216397#M126326</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have performed the following configuration on one of my switch to test periodically the availability of ISE servers : &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;radius server ISE-1&lt;/P&gt;&lt;P&gt; address ipv4 1.2.3.4 auth-port 1645 acct-port 1646&lt;/P&gt;&lt;P&gt; key 0 toto123&lt;/P&gt;&lt;P&gt;automate-tester username radius-test idle-time 10&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username radius-test password toto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And on the ISE server I can see authentication failed with code &lt;/P&gt;&lt;P&gt; Authentication failed &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;: &lt;/P&gt;&lt;P&gt; &lt;SPAN style="color: red; margin-top: 0pt;"&gt;22040 Wrong password or invalid shared secret&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sure about the shared secret because when I try test aaa group ....from the same switch it is ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does the automated test expect a valid access accept response ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:30:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-automated-test/m-p/2216397#M126326</guid>
      <dc:creator>lionel.dupont</dc:creator>
      <dc:date>2019-03-26T00:30:34Z</dc:date>
    </item>
    <item>
      <title>Radius Automated Test</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-automated-test/m-p/2216398#M126328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it is expect a valid access accept response. That is the reason due to which you are getting error.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jun 2013 15:47:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-automated-test/m-p/2216398#M126328</guid>
      <dc:creator>Ravi Singh</dc:creator>
      <dc:date>2013-06-25T15:47:53Z</dc:date>
    </item>
    <item>
      <title>Radius Automated Test</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-automated-test/m-p/2216399#M126331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's an IOS platform specific behavior. I observed the same behaviour on different switches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;See the following thread &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/thread/2170907"&gt;https://supportforums.cisco.com/thread/2170907&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The NAD does not expect accept accept response to consider ISE alive. Any type of answer means that ISE is alive.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jun 2013 19:18:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-automated-test/m-p/2216399#M126331</guid>
      <dc:creator>Octavian Szolga</dc:creator>
      <dc:date>2013-06-25T19:18:37Z</dc:date>
    </item>
    <item>
      <title>Radius Automated Test</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-automated-test/m-p/2216400#M126333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tested this on 15.0(2)SE2 and got it working with the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;'service password-encryption' is configured&lt;/P&gt;&lt;P&gt;I use the password option in the radius-test username (Not secret)&lt;/P&gt;&lt;P&gt;The password I configure on the ISE is the encrypted password (Same as what you would see in a 'show run')&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps in some way. I haven't tested with the 'secret' option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The question I really have is whether I really need to configure the "RADIUS automated tester" feature at all.&lt;/P&gt;&lt;P&gt;And whether I need to load balance to my ISE PSNs. My logs are full of radius-test user entires.&lt;/P&gt;&lt;P&gt;I have searched for guidence on this without any success.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 10:36:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-automated-test/m-p/2216400#M126333</guid>
      <dc:creator>bbosch4210</dc:creator>
      <dc:date>2013-06-26T10:36:12Z</dc:date>
    </item>
    <item>
      <title>Radius Automated Test</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-automated-test/m-p/2216401#M126335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Use the automate-tester command to enable automatic testing on the RADIUS server accounting and authentication UDP ports for RADIUS server load balancing. The username could be any username.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/ios-xml/ios/security/a1/sec-cr-a3.html#wp6780179500"&gt;http://www.cisco.com/en/US/docs/ios-xml/ios/security/a1/sec-cr-a3.html#wp6780179500&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I agree with Octavian that NAD doesn't necessarily expect radius-accept to consider ISE active.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin&lt;/P&gt;&lt;P&gt;*Do rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jun 2013 16:59:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-automated-test/m-p/2216401#M126335</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-06-26T16:59:54Z</dc:date>
    </item>
  </channel>
</rss>

