<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to configure Radius failover in ACS 5.1 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789160#M242030</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well if you have a TAC case ...&lt;/P&gt;&lt;P&gt;He logically spent time working on it and possibly checked cases affected by that bug.&lt;/P&gt;&lt;P&gt;As this is a forum, I'm rarely working more than a few minutes for each reply I give, so I would trust that answer over mine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, the bug is still Assigned and not marked as resolved yet. It was marked to be fixed for 5.3 but if it's not resolved yet, it won't be fixed in 5.3 release that comes out in 2 months &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 09 Sep 2011 12:21:37 GMT</pubDate>
    <dc:creator>Nicolas Darchis</dc:creator>
    <dc:date>2011-09-09T12:21:37Z</dc:date>
    <item>
      <title>How to configure Radius failover in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789149#M242007</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to configure the ACS 5.1 to meet the following requirement :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. ACS 5.1 will point to a RSA SecurID as the first authentication mechanism for the validation of user credential&lt;/P&gt;&lt;P&gt;2. In the event that RSA SecurID is not reachable, the ACS 5.1 shall point to its local user database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had no problem configuring for Point (1), but I am not able to let it failover to the local user database. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can any expert out there advise on the configuration portion?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:20:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789149#M242007</guid>
      <dc:creator>kianhowtan</dc:creator>
      <dc:date>2019-03-11T01:20:31Z</dc:date>
    </item>
    <item>
      <title>How to configure Radius failover in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789150#M242009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the users and identity menu, click on "identity store sequence".&lt;/P&gt;&lt;P&gt;Create a new sequence that will be composed of your RSA and then the internal store.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your service policy, instead of pointing the identity store to the RSA server, point it to the sequence you created.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Nicolas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Aug 2011 09:36:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789150#M242009</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-08-22T09:36:11Z</dc:date>
    </item>
    <item>
      <title>How to configure Radius failover in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789151#M242010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nicolas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks of the help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried out your method. But I am still encounting the "same" problem.&lt;/P&gt;&lt;P&gt;When I bring down the RSA server, my internal account is still not able to login successfully.&lt;/P&gt;&lt;P&gt;From the logging, the failure is due to the "invalid account" in my RSA server (so apparently it did not roll over to the internal store for the next authentication sequence).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is what i configured:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I defined "Authentication_Sequence" under the "identity store sequence".&lt;/P&gt;&lt;P&gt;&amp;gt; RSA&lt;/P&gt;&lt;P&gt;&amp;gt; Internal Hosts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then under Access Policy (Default Network Access),&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I selected "Authentication_Sequence" under the identity field.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not too sure where i missed out&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Aug 2011 12:42:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789151#M242010</guid>
      <dc:creator>kianhowtan</dc:creator>
      <dc:date>2011-08-25T12:42:09Z</dc:date>
    </item>
    <item>
      <title>How to configure Radius failover in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789152#M242011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the configuration seems correct. However it would seem that ACS doesn't realize that the RSA is down. How did you turn the RSA down ? off completely ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Aug 2011 12:50:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789152#M242011</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-08-25T12:50:11Z</dc:date>
    </item>
    <item>
      <title>How to configure Radius failover in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789153#M242014</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just simply disconnect the RSA server from the network so that ACS will not be able to reach RSA&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Aug 2011 13:29:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789153#M242014</guid>
      <dc:creator>kianhowtan</dc:creator>
      <dc:date>2011-08-25T13:29:54Z</dc:date>
    </item>
    <item>
      <title>How to configure Radius failover in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789154#M242015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To add on, the error is saying that the authentication failure is due to&amp;nbsp; ' ACS is not able to establish a connection to the RSA server'&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Aug 2011 05:59:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789154#M242015</guid>
      <dc:creator>kianhowtan</dc:creator>
      <dc:date>2011-08-26T05:59:17Z</dc:date>
    </item>
    <item>
      <title>How to configure Radius failover in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789155#M242017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Strange ...&lt;/P&gt;&lt;P&gt;I didn't play much with RSA server failover. It should fail over to my opinion but ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Aug 2011 07:52:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789155#M242017</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-08-26T07:52:03Z</dc:date>
    </item>
    <item>
      <title>How to configure Radius failover in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789156#M242019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is indeed quite strange.&lt;/P&gt;&lt;P&gt;I found one old thread that was quite similar to my problem :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/thread/2052480"&gt;https://supportforums.cisco.com/thread/2052480&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried out the setting, but the problem still persist. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Besides the sequence setting, Is there any setting that indicate the timeout value for a authentication store to declare "failure" and failover to the second store?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Aug 2011 15:58:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789156#M242019</guid>
      <dc:creator>kianhowtan</dc:creator>
      <dc:date>2011-08-26T15:58:31Z</dc:date>
    </item>
    <item>
      <title>How to configure Radius failover in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789157#M242020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you aware of this bug :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtl05416"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtl05416&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which could be relared to my problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Sep 2011 11:50:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789157#M242020</guid>
      <dc:creator>kianhowtan</dc:creator>
      <dc:date>2011-09-09T11:50:14Z</dc:date>
    </item>
    <item>
      <title>How to configure Radius failover in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789158#M242023</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That bug is not related. It's about Active Directory. Your problem is RSA ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Sep 2011 12:06:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789158#M242023</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-09-09T12:06:31Z</dc:date>
    </item>
    <item>
      <title>How to configure Radius failover in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789159#M242027</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is the reply from the TAC engineer, &lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;&amp;gt; I believe that you are hitting this bug: &lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&lt;A href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method" target="_blank" title="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; =fetchBugDetails&amp;amp;bugId=CSCtl05416 &lt;/P&gt;&lt;P&gt;&amp;gt; While the notes for this&amp;nbsp; bug talk about problems with AD, the same &lt;/P&gt;&lt;P&gt;&amp;gt; problem applies to _any_&amp;nbsp; identity sequence that you create. &lt;/P&gt;&lt;P&gt;&amp;gt; For example, if you create an&amp;nbsp; Identity Store Sequence with the Identity &lt;/P&gt;&lt;P&gt;&amp;gt; Stores A and B, the ACS will&amp;nbsp; _not_ go to Identity B if Identity Store A &lt;/P&gt;&lt;P&gt;&amp;gt; is not available. It does&amp;nbsp; not matter what the order of identity stores &lt;/P&gt;&lt;P&gt;&amp;gt; is in the sequence. This&amp;nbsp; is a known issue with ACS 5.2 and there is no &lt;/P&gt;&lt;P&gt;&amp;gt; work around. &lt;/P&gt;&lt;P&gt;&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;gt; This problem will be resolved in the next release of ACS, which will be &lt;/P&gt;&lt;P&gt;&amp;gt; ACS 5.3. The 5.3 release will allow you to select what action is to&amp;nbsp; take &lt;/P&gt;&lt;P&gt;&amp;gt; place is an Identity Store becomes unavailable. &lt;/P&gt;&lt;P&gt;&amp;gt; "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So would like to seek your opinion. In addition, also found this article.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://blog.pbmit.com/digipass2"&gt;http://blog.pbmit.com/digipass2&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Sep 2011 12:15:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789159#M242027</guid>
      <dc:creator>kianhowtan</dc:creator>
      <dc:date>2011-09-09T12:15:24Z</dc:date>
    </item>
    <item>
      <title>How to configure Radius failover in ACS 5.1</title>
      <link>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789160#M242030</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well if you have a TAC case ...&lt;/P&gt;&lt;P&gt;He logically spent time working on it and possibly checked cases affected by that bug.&lt;/P&gt;&lt;P&gt;As this is a forum, I'm rarely working more than a few minutes for each reply I give, so I would trust that answer over mine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, the bug is still Assigned and not marked as resolved yet. It was marked to be fixed for 5.3 but if it's not resolved yet, it won't be fixed in 5.3 release that comes out in 2 months &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Sep 2011 12:21:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-to-configure-radius-failover-in-acs-5-1/m-p/1789160#M242030</guid>
      <dc:creator>Nicolas Darchis</dc:creator>
      <dc:date>2011-09-09T12:21:37Z</dc:date>
    </item>
  </channel>
</rss>

