<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS issue with ASA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-issue-with-asa/m-p/1721842#M273075</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration seems fine.&lt;/P&gt;&lt;P&gt;Are you saying that the issue is intermittent? If yes, I would ask you to check the failed attempts of the ACS server at the time it fails. If they are being updated then the issue is not with the ACS. If they are not being updated collect the package.cab in full logging mode and we will need to find a reason why it is behaving that way. Probability is that the TACACS service might be hanging hence authentication stalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Action plan:&lt;/P&gt;&lt;P&gt;1. make logging full i.e. system configuration &amp;gt; Service Control &amp;gt; level of logging &amp;gt; Full &amp;gt; Restart&lt;/P&gt;&lt;P&gt;2. check the failed attempts of the ACS when authentication fails. If updated,not an issue with ACS&lt;/P&gt;&lt;P&gt;3. If not updated collect package.cab and we will have to check the reason of the failure. i.e. System configuration &amp;gt; Support &amp;gt; Run support now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this post as answered if you feel your query is resolved. Do rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 01 Jun 2011 00:56:08 GMT</pubDate>
    <dc:creator>andamani</dc:creator>
    <dc:date>2011-06-01T00:56:08Z</dc:date>
    <item>
      <title>ACS issue with ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-issue-with-asa/m-p/1721841#M273074</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is regarding our Main internet ASA(5550) AAA login issue, We are facing some probelm like some time , we are not able to login with tacacs Username and password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Due to this issue, some time our daily configuration backup is droping, Client security consultant are making noise..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it work after I reload the primary ACS, We have 2 acs working as primary and secondary..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you guys suggest some solution..below is config template of ACS AAA configs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;name 192.168.1.X1 ACS1&lt;BR /&gt;name 192.168.1.Y2 ACS2&lt;BR /&gt;name 192.168.1.10 ACS ( This IP is ACE tacacs&amp;nbsp; loadbalance IP ), All client is request is reaching to this IP and ACE is doing the load balancing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server ACCT protocol tacacs+&lt;BR /&gt;aaa-server ACCT (inside) host ACS1&lt;BR /&gt; key *****&lt;BR /&gt;aaa-server ACCT (inside) host ACS2&lt;BR /&gt; key *****&lt;BR /&gt;aaa-server AUTH protocol tacacs+&lt;BR /&gt;aaa-server AUTH (inside) host ACS&lt;BR /&gt; key *****&lt;BR /&gt;aaa authentication telnet console AUTH LOCAL&lt;BR /&gt;aaa authentication ssh console AUTH LOCAL&lt;BR /&gt;aaa authentication http console AUTH LOCAL&lt;BR /&gt;aaa authentication serial console AUTH LOCAL&lt;BR /&gt;aaa authentication enable console AUTH LOCAL&lt;BR /&gt;aaa authorization command AUTH LOCAL&lt;BR /&gt;aaa accounting command AUTH&lt;BR /&gt;!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:07:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-issue-with-asa/m-p/1721841#M273074</guid>
      <dc:creator>sajism220</dc:creator>
      <dc:date>2019-03-11T01:07:32Z</dc:date>
    </item>
    <item>
      <title>Re: ACS issue with ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-issue-with-asa/m-p/1721842#M273075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration seems fine.&lt;/P&gt;&lt;P&gt;Are you saying that the issue is intermittent? If yes, I would ask you to check the failed attempts of the ACS server at the time it fails. If they are being updated then the issue is not with the ACS. If they are not being updated collect the package.cab in full logging mode and we will need to find a reason why it is behaving that way. Probability is that the TACACS service might be hanging hence authentication stalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Action plan:&lt;/P&gt;&lt;P&gt;1. make logging full i.e. system configuration &amp;gt; Service Control &amp;gt; level of logging &amp;gt; Full &amp;gt; Restart&lt;/P&gt;&lt;P&gt;2. check the failed attempts of the ACS when authentication fails. If updated,not an issue with ACS&lt;/P&gt;&lt;P&gt;3. If not updated collect package.cab and we will have to check the reason of the failure. i.e. System configuration &amp;gt; Support &amp;gt; Run support now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this post as answered if you feel your query is resolved. Do rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jun 2011 00:56:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-issue-with-asa/m-p/1721842#M273075</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-06-01T00:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: ACS issue with ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-issue-with-asa/m-p/1721843#M273076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Anisha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently I can log in to same, as I said before, this will not happen regularly, Any way I will wait for that moment again,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am attaching the current package.cab for your reference, Will sent the same agine one the issue comes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a look and advice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;-Saji&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jun 2011 11:42:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-issue-with-asa/m-p/1721843#M273076</guid>
      <dc:creator>sajism220</dc:creator>
      <dc:date>2011-06-02T11:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: ACS issue with ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-issue-with-asa/m-p/1721844#M273077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Saji,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is cool.. Please ensure that you give me a timestamo when the issue occurs as well. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Anisha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this post as answered if you feel your query is resolved. Do rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jun 2011 16:28:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-issue-with-asa/m-p/1721844#M273077</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-06-02T16:28:10Z</dc:date>
    </item>
  </channel>
</rss>

