<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radius authentication failed on Cisco 6509 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/radius-authentication-failed-on-cisco-6509/m-p/1825087#M222439</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which specific event is the NPS generating for the 6509 authentication attempt?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, if you enable "debug aaa authentication" and "debug radius" would be able to share the outputs after recreating the authenticaation failure?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 31 Jan 2012 01:05:36 GMT</pubDate>
    <dc:creator>camejia</dc:creator>
    <dc:date>2012-01-31T01:05:36Z</dc:date>
    <item>
      <title>Radius authentication failed on Cisco 6509</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-failed-on-cisco-6509/m-p/1825086#M222423</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured Radius authentication on Windows 2008 server (NPS)&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following configuration is working perfectly on Cisco Switch 3560.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;aaa authentication login default group radius local&lt;/P&gt;&lt;P&gt;radius-server host 10.40.34.8 auth-port 1645 acct-port 1646 key XXX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But, the same configuration is not working on Cisco Catlyst Switch 6509 (C3560-IPBASEK9-M), Version 12.2(46)SE, RELEASE SOFTWARE (fc2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your help would be very much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yoosaf Lulu&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:46:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-failed-on-cisco-6509/m-p/1825086#M222423</guid>
      <dc:creator>yoosaflulu</dc:creator>
      <dc:date>2019-03-11T01:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication failed on Cisco 6509</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-failed-on-cisco-6509/m-p/1825087#M222439</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which specific event is the NPS generating for the 6509 authentication attempt?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, if you enable "debug aaa authentication" and "debug radius" would be able to share the outputs after recreating the authenticaation failure?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jan 2012 01:05:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-failed-on-cisco-6509/m-p/1825087#M222439</guid>
      <dc:creator>camejia</dc:creator>
      <dc:date>2012-01-31T01:05:36Z</dc:date>
    </item>
    <item>
      <title>Radius authentication failed on Cisco 6509</title>
      <link>https://community.cisco.com/t5/network-access-control/radius-authentication-failed-on-cisco-6509/m-p/1825088#M222448</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Carlos,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have rectified the issue.&lt;/P&gt;&lt;P&gt;Pls find the bug details associated with the existing running image in the Cisco 6509&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp;&amp;nbsp; Bug id:-CSCsv14886&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cause: - Failure to send RADIUS state attribute&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Symptom:-Switch using RADIUS for dot1x authentication is not sending RADIUS state attribute to ACS server. &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The ACS server discards these packets and the switch marks the server as down.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Conditions: Cat6500 running 12.2(33)SXH2a using RADIUS for dot1x authentication&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Workaround: None &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1st Fixed in Version: - 12.2(33)SXH5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;&amp;nbsp; Bud id :- CSCir00551&lt;/P&gt;&lt;P&gt;Cause: - Misleading radius debug message&lt;/P&gt;&lt;P&gt;Symptom:- The "%RADIUS-4-RADIUS_ALIVE: RADIUS server 172.27.66.89:2295,2296 has returned."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; is a little misleading. It is not saying that the server has returned, in the&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Sense of being heard from. It is only saying that RADIUS has marked the server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; as being alive because the deadtime timer has expired, and RADIUS is willing to&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; re-send messages to this server again.&lt;/P&gt;&lt;P&gt;Conditions: - None&lt;/P&gt;&lt;P&gt;Workaround: None&lt;/P&gt;&lt;P&gt;12.2(33)SXH4 is included in the affected version&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above 2 bugs associated with the radius issue in the existing image may be the cause of Radius not working with the cores witch, As we tested TACACS+ works correctly without any issues, would recommend you to configure TACACS+ for both the core switches and also for other devices, as TACACS+ is more secure than Radius .You can Use TACACS+ with Cisco ACS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 May 2012 10:32:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/radius-authentication-failed-on-cisco-6509/m-p/1825088#M222448</guid>
      <dc:creator>yoosaflulu</dc:creator>
      <dc:date>2012-05-01T10:32:23Z</dc:date>
    </item>
  </channel>
</rss>

