<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with MS IAS and AAA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/problem-with-ms-ias-and-aaa/m-p/1148482#M363613</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can see in the event viewer that the group policy is not working and looks like it has crashed and because of that i cant access shares . &lt;/P&gt;&lt;P&gt;the error says:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Windows cannot query for the list of Group Policy objects. Check the event log for possible messages previously logged by the policy engine that describes the reason for this."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this Radius stuff when authenticating with Active Directory requires Group Policy ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 22 Apr 2009 04:15:26 GMT</pubDate>
    <dc:creator>communication.boy</dc:creator>
    <dc:date>2009-04-22T04:15:26Z</dc:date>
    <item>
      <title>Problem with MS IAS and AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-ms-ias-and-aaa/m-p/1148479#M363599</link>
      <description>&lt;P&gt;I am configuring AAA . I am configuring a Router so that when users will access it using line vty they should be authenticated by the Active Directory . I have configured AAA on the Router and IAS on Microsoft Windows Server 2003 .But when i type " test aaa group AUTH Administrator xxxxxxx legacy " it gives the following error&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attempting authentication test to server-group AUTH using radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Mar  1 01:01:04.991: AAA: parse name=&amp;lt;no string&amp;gt; idb type=-1 tty=-1&lt;/P&gt;&lt;P&gt;*Mar  1 01:01:04.991: AAA/MEMORY: create_user (0x6417FF80) user='Administrator' ruser='NULL' ds0=0 port='' rem_addr='NULL' authen_type=ASCII service=LOGIN priv=1 initial_task_id='0', vrf= (id=0)No authoritative response from any server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RTR#&lt;/P&gt;&lt;P&gt;*Mar  1 01:01:23.647: %RADIUS-4-RADIUS_DEAD: RADIUS server 172.16.1.243:1812,1813 is not responding.&lt;/P&gt;&lt;P&gt;*Mar  1 01:01:23.655: AAA/MEMORY: free_user (0x6417FF80) user='Administrator' ruser='NULL' port='' rem_addr='NULL' authen_type=ASCII service=LOGIN priv=1 vrf= (id=0)&lt;/P&gt;&lt;P&gt;*Mar  1 01:01:23.655: %RADIUS-4-RADIUS_ALIVE: RADIUS server 172.16.1.243:1812,1813 is being marked alive.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also used the default ports for authentication but still no use. I am able to ping radius server from router and can ping router from radius server.&lt;/P&gt;&lt;P&gt;The Radius server in installed on VMWARE and the Router is being emulated in Dynampis.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following is the configuration of the router&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RTR#sh run&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current configuration : 863 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;version 12.4&lt;/P&gt;&lt;P&gt;service timestamps debug datetime msec&lt;/P&gt;&lt;P&gt;service timestamps log datetime msec&lt;/P&gt;&lt;P&gt;no service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname RTR&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot-start-marker&lt;/P&gt;&lt;P&gt;boot-end-marker&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius AUTH&lt;/P&gt;&lt;P&gt; server 172.16.1.243 auth-port 1812 acct-port 1813&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login AUTH group radius&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;memory-size iomem 5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip cef&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Loopback1&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0/0&lt;/P&gt;&lt;P&gt; ip address 172.16.1.241 255.255.255.0&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;no ip http secure-server&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 172.16.1.1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip radius source-interface FastEthernet0/0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;radius-server host 172.16.1.243 auth-port 1812 acct-port 1813 key xxxxx&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;control-plane&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; login authentication AUTH&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:27:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-ms-ias-and-aaa/m-p/1148479#M363599</guid>
      <dc:creator>communication.boy</dc:creator>
      <dc:date>2019-03-10T23:27:05Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with MS IAS and AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-ms-ias-and-aaa/m-p/1148480#M363600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you see any hits on 2003 event logs? If no then request is not reaching the radius. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember Dynampis  some time shows abnormal behavior. Since you are able to ping then connectivity seems to be fine here. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the shared secret key and make sure radius ports are open , check if there is any firewall in between.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~JG&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Apr 2009 17:49:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-ms-ias-and-aaa/m-p/1148480#M363600</guid>
      <dc:creator>Jagdeep Gambhir</dc:creator>
      <dc:date>2009-04-21T17:49:54Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with MS IAS and AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-ms-ias-and-aaa/m-p/1148481#M363605</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The shared key is working fine , I checked out the Event Manager and it shows a Success of Radius in the Security Section . When I telnet into the router it asks for Username and password and after that it says Authentication Failed . Still I can see new Security logs of Radius ( success ) but from telnet it says authentication failed &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Apr 2009 03:16:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-ms-ias-and-aaa/m-p/1148481#M363605</guid>
      <dc:creator>communication.boy</dc:creator>
      <dc:date>2009-04-22T03:16:24Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with MS IAS and AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-ms-ias-and-aaa/m-p/1148482#M363613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can see in the event viewer that the group policy is not working and looks like it has crashed and because of that i cant access shares . &lt;/P&gt;&lt;P&gt;the error says:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Windows cannot query for the list of Group Policy objects. Check the event log for possible messages previously logged by the policy engine that describes the reason for this."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this Radius stuff when authenticating with Active Directory requires Group Policy ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Apr 2009 04:15:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-ms-ias-and-aaa/m-p/1148482#M363613</guid>
      <dc:creator>communication.boy</dc:creator>
      <dc:date>2009-04-22T04:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with MS IAS and AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/problem-with-ms-ias-and-aaa/m-p/1148483#M363621</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I installed New Windows Server because the last Windows was having problem in GPO as it was showing in the event viewer that the GPO has sort of crashed and its perfectly working fine&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PROBLEM SOLVED !!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Apr 2009 06:35:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/problem-with-ms-ias-and-aaa/m-p/1148483#M363621</guid>
      <dc:creator>communication.boy</dc:creator>
      <dc:date>2009-04-22T06:35:22Z</dc:date>
    </item>
  </channel>
</rss>

