<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS LOG 11013 RADIUS packet already in the process in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-log-11013-radius-packet-already-in-the-process/m-p/2002773#M229296</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Marco,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. First we will have to see what the radius timeout values are set for on the network device. Also we need to identify if there is a relation to which network device(s) are generating this message and then try to increase the timeout values. For that device, if there is some latency some devices come with a default 5 second timer some up to 15.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. If you are using AD where are the domain controllers with respect to the ACS, is there a firewall or any policing polices that the ACS is subject to in its path to the DCs? If not, how many domain controllers do you have and how many are local to the ACS itself? Are your "sites" configured properly with the DC infrastructure so that when ACS queries the domain it is receving domain controllers that are located closest to it? Also what version of ACS are you running? if you are on ACS 5.3 then installing the latest patch will help fix some critical AD issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. How many authentications do you see on average when this issue occurs, what authentication mechanism are you using (eap-tls or peap), these authentication protocols are different in the way they operate and when it comes to authentications per second EAP-TLS does consume more processing power then the PEAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik admani&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 19 Jul 2012 15:47:39 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2012-07-19T15:47:39Z</dc:date>
    <item>
      <title>ACS LOG 11013 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-log-11013-radius-packet-already-in-the-process/m-p/2002770#M229254</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had got in my ACS 5.3 the following error message, do you kown wich could me the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/2/6/8/94862-red.PNG" alt="red.PNG" class="jive-image-thumbnail jive-image" onclick="" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regard,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marco.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:16:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-log-11013-radius-packet-already-in-the-process/m-p/2002770#M229254</guid>
      <dc:creator>mhuaynate</dc:creator>
      <dc:date>2019-03-11T02:16:21Z</dc:date>
    </item>
    <item>
      <title>ACS LOG 11013 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-log-11013-radius-packet-already-in-the-process/m-p/2002771#M229260</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Marco,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please use this as a reference:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps9911/products_tech_note09186a0080bb8100.shtml#radius11013"&gt;http://www.cisco.com/en/US/products/ps9911/products_tech_note09186a0080bb8100.shtml#radius11013&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;n an ACS 5.3 deployment, users fail dot1x&amp;nbsp; authentication. The database used is an Active Directory. The RADIUS&amp;nbsp; failure code is shown here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;TT&gt;RADIUS Request dropped: 11013 RADIUS packet already in the process&lt;/TT&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H3&gt;&lt;A name="sol31"&gt;Solution&lt;/A&gt;&lt;/H3&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACS has ignored this request because it is a duplicate of another&amp;nbsp; packet that is currently being processed. This can occur because of any&amp;nbsp; of these:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;The Average RADIUS Request Latency statistic is close to or exceeds the client RADIUS request timeout of the client.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;External identity store can be very slow.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The ACS has been overloaded.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perform these steps in order to resolve:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL type="1"&gt;&lt;LI&gt;&lt;P&gt;Increase the client RADIUS request timeout of the client.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Use a faster or additional external identity store.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Follow the ways to reduce the overload on ACS.&lt;/P&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Jul 2012 00:32:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-log-11013-radius-packet-already-in-the-process/m-p/2002771#M229260</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-07T00:32:07Z</dc:date>
    </item>
    <item>
      <title>ACS LOG 11013 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-log-11013-radius-packet-already-in-the-process/m-p/2002772#M229275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi tarik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how can i do that ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL start="1" type="1"&gt;&lt;LI&gt;&lt;P&gt;Increase the client RADIUS request timeout of the client.&lt;/P&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Use a faster or additional external identity store.&lt;/P&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Follow the ways to reduce the overload on ACS&lt;/P&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2012 15:22:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-log-11013-radius-packet-already-in-the-process/m-p/2002772#M229275</guid>
      <dc:creator>mhuaynate</dc:creator>
      <dc:date>2012-07-19T15:22:23Z</dc:date>
    </item>
    <item>
      <title>ACS LOG 11013 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-log-11013-radius-packet-already-in-the-process/m-p/2002773#M229296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Marco,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. First we will have to see what the radius timeout values are set for on the network device. Also we need to identify if there is a relation to which network device(s) are generating this message and then try to increase the timeout values. For that device, if there is some latency some devices come with a default 5 second timer some up to 15.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. If you are using AD where are the domain controllers with respect to the ACS, is there a firewall or any policing polices that the ACS is subject to in its path to the DCs? If not, how many domain controllers do you have and how many are local to the ACS itself? Are your "sites" configured properly with the DC infrastructure so that when ACS queries the domain it is receving domain controllers that are located closest to it? Also what version of ACS are you running? if you are on ACS 5.3 then installing the latest patch will help fix some critical AD issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. How many authentications do you see on average when this issue occurs, what authentication mechanism are you using (eap-tls or peap), these authentication protocols are different in the way they operate and when it comes to authentications per second EAP-TLS does consume more processing power then the PEAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik admani&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2012 15:47:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-log-11013-radius-packet-already-in-the-process/m-p/2002773#M229296</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-19T15:47:39Z</dc:date>
    </item>
    <item>
      <title>ACS LOG 11013 RADIUS packet already in the process</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-log-11013-radius-packet-already-in-the-process/m-p/2002774#M229349</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi tarik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is the port configuration in the switch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface FastEthernet0/12&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; switchport voice vlan 10&lt;/P&gt;&lt;P&gt; authentication port-control auto&lt;/P&gt;&lt;P&gt; authentication host-mode multi-domain&lt;/P&gt;&lt;P&gt; authentication violation protect&lt;/P&gt;&lt;P&gt; authentication event fail action authorize vlan 11&lt;/P&gt;&lt;P&gt; authentication event fail retry 2 action authorize vlan 11&lt;/P&gt;&lt;P&gt; authentication event no-response action authorize vlan 11&lt;/P&gt;&lt;P&gt; authentication periodic&lt;/P&gt;&lt;P&gt; authentication timer reauthenticate 60&lt;/P&gt;&lt;P&gt; mab&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; dot1x timeout tx-period 10&lt;/P&gt;&lt;P&gt; dot1x max-reauth-req 3&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;end&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2012 16:17:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-log-11013-radius-packet-already-in-the-process/m-p/2002774#M229349</guid>
      <dc:creator>mhuaynate</dc:creator>
      <dc:date>2012-07-19T16:17:15Z</dc:date>
    </item>
    <item>
      <title>aaa accounting update newinfo</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-log-11013-radius-packet-already-in-the-process/m-p/2002775#M229443</link>
      <description>&lt;P&gt;aaa accounting update newinfo&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2016 05:44:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-log-11013-radius-packet-already-in-the-process/m-p/2002775#M229443</guid>
      <dc:creator>vovanZM18</dc:creator>
      <dc:date>2016-03-25T05:44:03Z</dc:date>
    </item>
  </channel>
</rss>

