<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ACS 5.2: unknown network device or AAA client in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566714#M346110</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, and this does seem to work fine. Any changes done on primary are quickly replicated to the secondary. But they do not take effect there either...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 16 Dec 2010 08:16:04 GMT</pubDate>
    <dc:creator>staalebotnen</dc:creator>
    <dc:date>2010-12-16T08:16:04Z</dc:date>
    <item>
      <title>Cisco ACS 5.2: unknown network device or AAA client</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566708#M346051</link>
      <description>&lt;P&gt;We have recently started testing Cisco ACS 5.2, but we are hitting an issue when we try to register a Wireless LAN Controller. Even when the device is registered on the ACS under "Network Devices and AAA Clients" we are getting the following error message in the logs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"11017 Received TACACS+ packet from unknown Network device or AAA client"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have deleted and recreated the object, restarted the ACS, verified IP address and netmask, still no luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone experienced something similiar? I'm begining to think we are hitting a bug, but I see there are several post from people who have successfully setup authentication beweeen a ACS 5.2 and WLC 6...&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:39:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566708#M346051</guid>
      <dc:creator>staalebotnen</dc:creator>
      <dc:date>2019-03-11T00:39:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.2: unknown network device or AAA client</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566709#M346062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What kind of authentication are we talking about?&lt;/P&gt;&lt;P&gt;Clients or the WLC admin users?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is clients, then the protocol should be RADIUS...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the error message the acs is receiving a TACACS+ packet...so i would say that you are trying to authenticate admin users...is it correct?&lt;/P&gt;&lt;P&gt;Now, is it possible that you have defined the WLC as a RADIUS device and what you want to do is TACACS device (WLC) authentication?&lt;/P&gt;&lt;P&gt;If yes, then i would review the aaa client config to match the protocol.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;BR /&gt;Tiago&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Dec 2010 19:41:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566709#M346062</guid>
      <dc:creator>Tiago Antunes</dc:creator>
      <dc:date>2010-12-14T19:41:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.2: unknown network device or AAA client</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566710#M346068</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Both TACACS+ and RADIUS authentication of Admin users. The definitions on the object are correct (tried both as a RADIUS and a TACACS+ object).&lt;/P&gt;&lt;P&gt;I have done some more testing and it turns out that any changes that we do in the "Network Devices or AAA Clients" have no effect, the changes get updated in the GUI but never seem to get activated for real. I tested this by deleting an object, and even when the object is gone I can authenticate with the ACS from that NAS device... So it would seem that we are hitting some bug/corruption. I have created a TAC case with Cisco, this will be the third case since we started implementing the new 5.x version..and we are still in testing phace..&lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Dec 2010 06:50:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566710#M346068</guid>
      <dc:creator>staalebotnen</dc:creator>
      <dc:date>2010-12-16T06:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.2: unknown network device or AAA client</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566711#M346078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could it be that you have another ACS and the authentications are going there?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Tiago&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Dec 2010 07:30:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566711#M346078</guid>
      <dc:creator>Tiago Antunes</dc:creator>
      <dc:date>2010-12-16T07:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.2: unknown network device or AAA client</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566712#M346092</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We do have two ACSs (Primary/Secondary), authentications go to both of these (we see this in the logs). Both ACSs experience the same issue. So we are currently unable to register any new devices or change exsting ones. Currently waiting for the TAC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Dec 2010 08:03:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566712#M346092</guid>
      <dc:creator>staalebotnen</dc:creator>
      <dc:date>2010-12-16T08:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.2: unknown network device or AAA client</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566713#M346097</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please note that changes can only be done on the Primary ACS, and then these changes are mirrored to the other ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;BR /&gt;Tiago&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Dec 2010 08:07:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566713#M346097</guid>
      <dc:creator>Tiago Antunes</dc:creator>
      <dc:date>2010-12-16T08:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.2: unknown network device or AAA client</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566714#M346110</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, and this does seem to work fine. Any changes done on primary are quickly replicated to the secondary. But they do not take effect there either...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Dec 2010 08:16:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566714#M346110</guid>
      <dc:creator>staalebotnen</dc:creator>
      <dc:date>2010-12-16T08:16:04Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.2: unknown network device or AAA client</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566715#M346135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you look at the details of the failed authentication, is the IP address shown the same as it is listed for the AAA client?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Dec 2010 13:57:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566715#M346135</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2010-12-16T13:57:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.2: unknown network device or AAA client</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566716#M346142</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, the IP address is identical. Another issue we detected now is that this is not only affecting "Network Devices and AAA Clients", but our "Service Selection Rules" as well. We can disable rules, but the counters still increment and the rules still triggers. I'm hoping that we have just been unlucky with our configuration/appliance and that this is not the general state of the product...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On a side note, adding/deleting/modifying users work...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Dec 2010 14:04:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566716#M346142</guid>
      <dc:creator>staalebotnen</dc:creator>
      <dc:date>2010-12-16T14:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.2: unknown network device or AAA client</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566717#M346155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is a general issue. While the database is replicating OK - you will see u&lt;SPAN style="background-color: #f8fafd;"&gt;pdated config data on the GUI on the servers - the piece that updates the protocol component with the new config has stopped and so no updated configuration will be processed. This will affect all configuraiton items; the only exception is the internal user data which is read directly from the database.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;You said you have opened a TAC case so they will need to troubleshoot. Only other comments/suggestions:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;A stop/start on the server "may" recover things&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;worth checking whether there are any system alarms that relate to this issue&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Dec 2010 14:23:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566717#M346155</guid>
      <dc:creator>jrabinow</dc:creator>
      <dc:date>2010-12-16T14:23:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.2: unknown network device or AAA client</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566718#M346203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi just for curiosity,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What browser are you using to browse the ACS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you try with IE to see if the config changes are taken into account?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;BR /&gt;Tiago&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;If&amp;nbsp; this helps you and/or answers your question please mark the question as&amp;nbsp; "answered" and/or rate it, so other users can easily find it.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 16 Dec 2010 14:25:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-2-unknown-network-device-or-aaa-client/m-p/1566718#M346203</guid>
      <dc:creator>Tiago Antunes</dc:creator>
      <dc:date>2010-12-16T14:25:49Z</dc:date>
    </item>
  </channel>
</rss>

