<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA / RADIUS / ACS Problem ? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/asa-radius-acs-problem/m-p/661202#M422319</link>
    <description>&lt;P&gt;Good Morning Folks;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the output from the show aaa-servers from my asa5540. Notice the status "failed". When the status is thus (on both aaa servers) noone can login the the VPN on the ASA5540. I've checked the duplex / speed etc on the ports feeding the AAA servers and the ASA5540. no errors, no duplex problems..... Also&lt;/P&gt;&lt;P&gt;the AAA servers are used by other systems WITHOUT this problem. Also the ASA and the AAA machines are on the same local LAN segment....After approximately 10 minutes the status will go back to active.......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACS is version 3.3 the ASA is running 7.2(1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm tring to findout exactly why the radius client on the ASA5540 is detecting this problem and exactly what it means and how to resolve it......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any help would be terrific.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server Group:    infinity&lt;/P&gt;&lt;P&gt;Server Protocol: radius&lt;/P&gt;&lt;P&gt;Server Address:  192.168.1.23&lt;/P&gt;&lt;P&gt;Server port:     1645(authentication), 1646(accounting)&lt;/P&gt;&lt;P&gt;Server status:   FAILED, Server disabled at 18:53:58 EDT Mon Nov 20 2006&lt;/P&gt;&lt;P&gt;Number of pending requests              0&lt;/P&gt;&lt;P&gt;Average round trip time                 30ms&lt;/P&gt;&lt;P&gt;Number of authentication requests       61&lt;/P&gt;&lt;P&gt;Number of authorization requests        0&lt;/P&gt;&lt;P&gt;Number of accounting requests           0&lt;/P&gt;&lt;P&gt;Number of retransmissions               46&lt;/P&gt;&lt;P&gt;Number of accepts                       28&lt;/P&gt;&lt;P&gt;Number of rejects                       5&lt;/P&gt;&lt;P&gt;Number of challenges                    25&lt;/P&gt;&lt;P&gt;Number of malformed responses           0&lt;/P&gt;&lt;P&gt;Number of bad authenticators            0&lt;/P&gt;&lt;P&gt;Number of timeouts                      28&lt;/P&gt;&lt;P&gt;Number of unrecognized responses        0&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Server Group:    infinity&lt;/P&gt;&lt;P&gt;Server Protocol: radius&lt;/P&gt;&lt;P&gt;Server Address:  192.168.1.2&lt;/P&gt;&lt;P&gt;Server port:     1645(authentication), 1646(accounting)&lt;/P&gt;&lt;P&gt;Server status:   FAILED, Server disabled at 18:53:57 EDT Mon Nov 20 2006&lt;/P&gt;&lt;P&gt;Number of pending requests              0&lt;/P&gt;&lt;P&gt;Average round trip time                 0ms&lt;/P&gt;&lt;P&gt;Number of authentication requests       5&lt;/P&gt;&lt;P&gt;Number of authorization requests        0&lt;/P&gt;&lt;P&gt;Number of accounting requests           0&lt;/P&gt;&lt;P&gt;Number of retransmissions               0&lt;/P&gt;&lt;P&gt;Number of accepts                       0&lt;/P&gt;&lt;P&gt;Number of rejects                       0&lt;/P&gt;&lt;P&gt;Number of challenges                    0&lt;/P&gt;&lt;P&gt;Number of malformed responses           0&lt;/P&gt;&lt;P&gt;Number of bad authenticators            0&lt;/P&gt;&lt;P&gt;Number of timeouts                      5&lt;/P&gt;&lt;P&gt;Number of unrecognized responses        0&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;pierce(config)# show aaa-server &lt;/P&gt;&lt;P&gt;Server Group:    LOCAL&lt;/P&gt;&lt;P&gt;Server Protocol: Local database&lt;/P&gt;&lt;P&gt;Server Address:  None&lt;/P&gt;&lt;P&gt;Server port:     None&lt;/P&gt;&lt;P&gt;Server status:   ACTIVE, Last transaction at 18:58:46 EDT Mon Nov 20 2006&lt;/P&gt;&lt;P&gt;Number of pending requests              0&lt;/P&gt;&lt;P&gt;Average round trip time                 0ms&lt;/P&gt;&lt;P&gt;Number of authentication requests       154&lt;/P&gt;&lt;P&gt;Number of authorization requests        0&lt;/P&gt;&lt;P&gt;Number of accounting requests           0&lt;/P&gt;&lt;P&gt;Number of retransmissions               0&lt;/P&gt;&lt;P&gt;Number of accepts                       0&lt;/P&gt;&lt;P&gt;Number of rejects                       154&lt;/P&gt;&lt;P&gt;Number of challenges                    0&lt;/P&gt;&lt;P&gt;Number of malformed responses           0&lt;/P&gt;&lt;P&gt;Number of bad authenticators            0&lt;/P&gt;&lt;P&gt;Number of timeouts                      0&lt;/P&gt;&lt;P&gt;Number of unrecognized responses        0&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Server Group:    infinity&lt;/P&gt;&lt;P&gt;Server Protocol: radius&lt;/P&gt;&lt;P&gt;pierce(config)# show aaa-server &lt;/P&gt;&lt;P&gt;Server Group:    LOCAL&lt;/P&gt;&lt;P&gt;Server Protocol: Local database&lt;/P&gt;&lt;P&gt;Server Address:  None&lt;/P&gt;&lt;P&gt;Server port:     None&lt;/P&gt;&lt;P&gt;Server status:   ACTIVE, Last transaction at 19:03:52 EDT Mon Nov 20 2006&lt;/P&gt;&lt;P&gt;Number of pending requests              0&lt;/P&gt;&lt;P&gt;Average round trip time                 0ms&lt;/P&gt;&lt;P&gt;Number of authentication requests       163&lt;/P&gt;&lt;P&gt;Number of authorization requests        0&lt;/P&gt;&lt;P&gt;Number of accounting requests           0&lt;/P&gt;&lt;P&gt;Number of retransmissions               0&lt;/P&gt;&lt;P&gt;Number of accepts                       0&lt;/P&gt;&lt;P&gt;Number of rejects                       163&lt;/P&gt;&lt;P&gt;Number of challenges                    0&lt;/P&gt;&lt;P&gt;Number of malformed responses           0&lt;/P&gt;&lt;P&gt;Number of bad authenticators            0&lt;/P&gt;&lt;P&gt;Number of timeouts                      0&lt;/P&gt;&lt;P&gt;Number of unrecognized responses        0&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 21:52:10 GMT</pubDate>
    <dc:creator>jbigrow</dc:creator>
    <dc:date>2019-03-10T21:52:10Z</dc:date>
    <item>
      <title>ASA / RADIUS / ACS Problem ?</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-radius-acs-problem/m-p/661202#M422319</link>
      <description>&lt;P&gt;Good Morning Folks;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the output from the show aaa-servers from my asa5540. Notice the status "failed". When the status is thus (on both aaa servers) noone can login the the VPN on the ASA5540. I've checked the duplex / speed etc on the ports feeding the AAA servers and the ASA5540. no errors, no duplex problems..... Also&lt;/P&gt;&lt;P&gt;the AAA servers are used by other systems WITHOUT this problem. Also the ASA and the AAA machines are on the same local LAN segment....After approximately 10 minutes the status will go back to active.......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACS is version 3.3 the ASA is running 7.2(1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm tring to findout exactly why the radius client on the ASA5540 is detecting this problem and exactly what it means and how to resolve it......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any help would be terrific.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server Group:    infinity&lt;/P&gt;&lt;P&gt;Server Protocol: radius&lt;/P&gt;&lt;P&gt;Server Address:  192.168.1.23&lt;/P&gt;&lt;P&gt;Server port:     1645(authentication), 1646(accounting)&lt;/P&gt;&lt;P&gt;Server status:   FAILED, Server disabled at 18:53:58 EDT Mon Nov 20 2006&lt;/P&gt;&lt;P&gt;Number of pending requests              0&lt;/P&gt;&lt;P&gt;Average round trip time                 30ms&lt;/P&gt;&lt;P&gt;Number of authentication requests       61&lt;/P&gt;&lt;P&gt;Number of authorization requests        0&lt;/P&gt;&lt;P&gt;Number of accounting requests           0&lt;/P&gt;&lt;P&gt;Number of retransmissions               46&lt;/P&gt;&lt;P&gt;Number of accepts                       28&lt;/P&gt;&lt;P&gt;Number of rejects                       5&lt;/P&gt;&lt;P&gt;Number of challenges                    25&lt;/P&gt;&lt;P&gt;Number of malformed responses           0&lt;/P&gt;&lt;P&gt;Number of bad authenticators            0&lt;/P&gt;&lt;P&gt;Number of timeouts                      28&lt;/P&gt;&lt;P&gt;Number of unrecognized responses        0&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Server Group:    infinity&lt;/P&gt;&lt;P&gt;Server Protocol: radius&lt;/P&gt;&lt;P&gt;Server Address:  192.168.1.2&lt;/P&gt;&lt;P&gt;Server port:     1645(authentication), 1646(accounting)&lt;/P&gt;&lt;P&gt;Server status:   FAILED, Server disabled at 18:53:57 EDT Mon Nov 20 2006&lt;/P&gt;&lt;P&gt;Number of pending requests              0&lt;/P&gt;&lt;P&gt;Average round trip time                 0ms&lt;/P&gt;&lt;P&gt;Number of authentication requests       5&lt;/P&gt;&lt;P&gt;Number of authorization requests        0&lt;/P&gt;&lt;P&gt;Number of accounting requests           0&lt;/P&gt;&lt;P&gt;Number of retransmissions               0&lt;/P&gt;&lt;P&gt;Number of accepts                       0&lt;/P&gt;&lt;P&gt;Number of rejects                       0&lt;/P&gt;&lt;P&gt;Number of challenges                    0&lt;/P&gt;&lt;P&gt;Number of malformed responses           0&lt;/P&gt;&lt;P&gt;Number of bad authenticators            0&lt;/P&gt;&lt;P&gt;Number of timeouts                      5&lt;/P&gt;&lt;P&gt;Number of unrecognized responses        0&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;pierce(config)# show aaa-server &lt;/P&gt;&lt;P&gt;Server Group:    LOCAL&lt;/P&gt;&lt;P&gt;Server Protocol: Local database&lt;/P&gt;&lt;P&gt;Server Address:  None&lt;/P&gt;&lt;P&gt;Server port:     None&lt;/P&gt;&lt;P&gt;Server status:   ACTIVE, Last transaction at 18:58:46 EDT Mon Nov 20 2006&lt;/P&gt;&lt;P&gt;Number of pending requests              0&lt;/P&gt;&lt;P&gt;Average round trip time                 0ms&lt;/P&gt;&lt;P&gt;Number of authentication requests       154&lt;/P&gt;&lt;P&gt;Number of authorization requests        0&lt;/P&gt;&lt;P&gt;Number of accounting requests           0&lt;/P&gt;&lt;P&gt;Number of retransmissions               0&lt;/P&gt;&lt;P&gt;Number of accepts                       0&lt;/P&gt;&lt;P&gt;Number of rejects                       154&lt;/P&gt;&lt;P&gt;Number of challenges                    0&lt;/P&gt;&lt;P&gt;Number of malformed responses           0&lt;/P&gt;&lt;P&gt;Number of bad authenticators            0&lt;/P&gt;&lt;P&gt;Number of timeouts                      0&lt;/P&gt;&lt;P&gt;Number of unrecognized responses        0&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Server Group:    infinity&lt;/P&gt;&lt;P&gt;Server Protocol: radius&lt;/P&gt;&lt;P&gt;pierce(config)# show aaa-server &lt;/P&gt;&lt;P&gt;Server Group:    LOCAL&lt;/P&gt;&lt;P&gt;Server Protocol: Local database&lt;/P&gt;&lt;P&gt;Server Address:  None&lt;/P&gt;&lt;P&gt;Server port:     None&lt;/P&gt;&lt;P&gt;Server status:   ACTIVE, Last transaction at 19:03:52 EDT Mon Nov 20 2006&lt;/P&gt;&lt;P&gt;Number of pending requests              0&lt;/P&gt;&lt;P&gt;Average round trip time                 0ms&lt;/P&gt;&lt;P&gt;Number of authentication requests       163&lt;/P&gt;&lt;P&gt;Number of authorization requests        0&lt;/P&gt;&lt;P&gt;Number of accounting requests           0&lt;/P&gt;&lt;P&gt;Number of retransmissions               0&lt;/P&gt;&lt;P&gt;Number of accepts                       0&lt;/P&gt;&lt;P&gt;Number of rejects                       163&lt;/P&gt;&lt;P&gt;Number of challenges                    0&lt;/P&gt;&lt;P&gt;Number of malformed responses           0&lt;/P&gt;&lt;P&gt;Number of bad authenticators            0&lt;/P&gt;&lt;P&gt;Number of timeouts                      0&lt;/P&gt;&lt;P&gt;Number of unrecognized responses        0&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:52:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-radius-acs-problem/m-p/661202#M422319</guid>
      <dc:creator>jbigrow</dc:creator>
      <dc:date>2019-03-10T21:52:10Z</dc:date>
    </item>
    <item>
      <title>Re: ASA / RADIUS / ACS Problem ?</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-radius-acs-problem/m-p/661203#M422320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like your ASA lost connection with ACS/AAA server. This might not necessarily network connection, but could be application communication level which may be due to wrong entry in ACS for the ASA (check in ACS for correct ASA IP Address, authentication protocol via radius).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On ASA, make sure you can ping ACS Server to verify that network level connection works fine. Check the 'aaa-server' command point to the right interface (normally inside intf) where the ACS server sits, as well as the ACS IP Address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Test the radius authentication with local user (create username/password in SA local dbase) to verify that ASA VPN-related config/services  is running fine before pointing the actual VPN user authentication to ACS via radius.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/partner/products/ps6120/products_configuration_guide_chapter09186a008063715a.html#wp1140273" target="_blank"&gt;http://www.cisco.com/en/US/partner/products/ps6120/products_configuration_guide_chapter09186a008063715a.html#wp1140273&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Dec 2006 16:02:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-radius-acs-problem/m-p/661203#M422320</guid>
      <dc:creator>a.kiprawih</dc:creator>
      <dc:date>2006-12-06T16:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: ASA / RADIUS / ACS Problem ?</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-radius-acs-problem/m-p/661204#M422321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for taking the time to reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I should have added that this problem is very intermittent. It will work for up to an hour&lt;/P&gt;&lt;P&gt;then the status failed will occur at which time the user community cannot login until the error condition automatically clears then everything works for a while again untill the ASA detects the "failed" status.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Dec 2006 18:44:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-radius-acs-problem/m-p/661204#M422321</guid>
      <dc:creator>jbigrow</dc:creator>
      <dc:date>2006-12-12T18:44:42Z</dc:date>
    </item>
  </channel>
</rss>

