<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No Response from the ACS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/no-response-from-the-acs/m-p/671970#M422719</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you look in the failed attempts report on the secondary ACS - does it say anything?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to know if the request is making to the secondary, if its getting there is it being ignored or is there a problem in processing it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Failed attempts is the first place to look&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Darran&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 09 Oct 2006 13:09:05 GMT</pubDate>
    <dc:creator>darpotter</dc:creator>
    <dc:date>2006-10-09T13:09:05Z</dc:date>
    <item>
      <title>No Response from the ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/no-response-from-the-acs/m-p/671967#M422714</link>
      <description>&lt;P&gt;Dear Group,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have Two ACS , the Primary ACS has the IP address 192.168.1.8 and the secondary ACS has the IP address 192.168.1.9&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to forward the authentication requests to the secondary ACS to make sure that we have no problem in case the primary fail  but the secondary  ACS did not respond to the requests sent from the AAA Client though  I have no problem with the primary ACS.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;The secondary ACS has the same configuration and feature set as the primary ACS, the primary ACS is configured to replicates its username, configuration, etc. every 60 minutes, the Secondary ACS is configured to receive those replication information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately the secondary ACS is not responding and is giving the following message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No response from (192.168.1.9:1645,1646)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RADIUS/ENCODE(00000019): dropping service type, "radius-server attribute 6 on-for-login-auth" is off&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will appreciate if someone can help me with diagnosing what?s going on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the complete debug while entering the username/password :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Username: testuser&lt;/P&gt;&lt;P&gt;*Mar 23 16:00:15.625: AAA/BIND(00000019): Bind i/f  &lt;/P&gt;&lt;P&gt;*Mar 23 16:00:15.625: AAA/AUTHEN/LOGIN (00000019): Pick method list 'VTY' &lt;/P&gt;&lt;P&gt;*Mar 23 16:00:15.625: RADIUS/ENCODE(00000019): ask "Username: "&lt;/P&gt;&lt;P&gt;*Mar 23 16:00:15.625: RADIUS/ENCODE(00000019): send packet; GET_USER&lt;/P&gt;&lt;P&gt;Password: &lt;/P&gt;&lt;P&gt;*Mar 23 16:00:22.037: RADIUS/ENCODE(00000019): ask "Password: "&lt;/P&gt;&lt;P&gt;*Mar 23 16:00:22.037: RADIUS/ENCODE(00000019): send packet; GET_PASSWORD&lt;/P&gt;&lt;P&gt;*Mar 23 16:00:28.201: RADIUS:  AAA Unsupported     [150] 6   &lt;/P&gt;&lt;P&gt;*Mar 23 16:00:28.201: RADIUS:   74 74 79 31                                      [tty1]&lt;/P&gt;&lt;P&gt;*Mar 23 16:00:28.201: RADIUS(00000019): Storing nasport 162 in rad_db&lt;/P&gt;&lt;P&gt;*Mar 23 16:00:28.201: RADIUS/ENCODE(00000019): dropping service type, "radius-server attribute 6 on-for-login-auth" is off&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Mar 23 16:00:28.201: RADIUS(00000019): Config NAS IP: 192.168.1.12&lt;/P&gt;&lt;P&gt;*Mar 23 16:00:28.201: RADIUS/ENCODE(00000019): acct_session_id: 22&lt;/P&gt;&lt;P&gt;*Mar 23 16:00:28.201: RADIUS(00000019): sending&lt;/P&gt;&lt;P&gt;*Mar 23 16:00:28.201: RADIUS(00000019): Send Access-Request to 192.168.1.9:1645 id 21645/14, len 79&lt;/P&gt;&lt;P&gt;*Mar 23 16:00:28.201: RADIUS:  authenticator 79 79 F3 E5 6F 89 69 EA - AA 87 44 E3 F7 93 47 6B&lt;/P&gt;&lt;P&gt;*Mar 23 16:00:28.201: RADIUS:  User-Name           [1]   9   "testuser"&lt;/P&gt;&lt;P&gt;*Mar 23 16:00:28.201: RADIUS:  User-Password       [2]   18  *&lt;/P&gt;&lt;P&gt;*Mar 23 16:00:28.201: RADIUS:  NAS-Port            [5]   6   162                       &lt;/P&gt;&lt;P&gt;*Mar 23 16:00:28.201: RADIUS:  NAS-Port-Type       [61]  6   Virtual                   [5]&lt;/P&gt;&lt;P&gt;*Mar 23 16:00:28.201: RADIUS:  Calling-Station-Id  [31]  14  "192.168.1.12"&lt;/P&gt;&lt;P&gt;*Mar 23 16:00:28.201: RADIUS:  NAS-IP-Address      [4]   6   192.168.1.12              &lt;/P&gt;&lt;P&gt;*Mar 23 16:00:33.201: RADIUS: Retransmit to (192.168.1.9:1645,1646) for id 21645/14&lt;/P&gt;&lt;P&gt;*Mar 23 16:00:38.201: RADIUS: Retransmit to (192.168.1.9:1645,1646) for id 21645/14&lt;/P&gt;&lt;P&gt;*Mar 23 16:00:43.201: RADIUS: Retransmit to (192.168.1.9:1645,1646) for id 21645/14&lt;/P&gt;&lt;P&gt;*Mar 23 16:00:48.201: RADIUS: No response from (192.168.1.9:1645,1646) for id 21645/14&lt;/P&gt;&lt;P&gt;*Mar 23 16:00:48.201: RADIUS/DECODE: parse response no app start; FAIL&lt;/P&gt;&lt;P&gt;*Mar 23 16:00:48.201: RADIUS/DECODE: parse response; FAIL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;% Authentication failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Mar 23 16:01:47.929: RADIUS: Retransmit to (192.168.1.9:1645,1646) for id 21645/15&lt;/P&gt;&lt;P&gt;*Mar 23 16:01:52.929: RADIUS: Retransmit to (192.168.1.9:1645,1646) for id 21645/15&lt;/P&gt;&lt;P&gt;*Mar 23 16:01:57.929: RADIUS: Retransmit to (192.168.1.9:1645,1646) for id 21645/15&lt;/P&gt;&lt;P&gt;*Mar 23 16:02:02.929: RADIUS: No response from (192.168.1.9:1645,1646) for id 21645/15&lt;/P&gt;&lt;P&gt;*Mar 23 16:02:02.929: RADIUS/DECODE: parse response no app start; FAIL&lt;/P&gt;&lt;P&gt;*Mar 23 16:02:02.929: RADIUS/DECODE: parse response; FAIL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;% Authentication failed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for helping me in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:46:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-response-from-the-acs/m-p/671967#M422714</guid>
      <dc:creator>conceptzone</dc:creator>
      <dc:date>2019-03-10T21:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: No Response from the ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/no-response-from-the-acs/m-p/671968#M422715</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you please post the configuration.!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Oct 2006 09:34:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-response-from-the-acs/m-p/671968#M422715</guid>
      <dc:creator>osamoz</dc:creator>
      <dc:date>2006-10-08T09:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: No Response from the ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/no-response-from-the-acs/m-p/671969#M422717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login VTY group radius local&lt;/P&gt;&lt;P&gt;aaa authentication login no_authentication non&lt;/P&gt;&lt;P&gt;aaa accounting exec default stop-only group radius&lt;/P&gt;&lt;P&gt;aaa accounting connection default start-stop group radius&lt;/P&gt;&lt;P&gt;aaa accounting system default start-stop group radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip radius source-interface Ethernet0/0&lt;/P&gt;&lt;P&gt;radius-server host 192.168.1.9 auth-port 1645 acct-port 1646 key lemon123&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt;ip address 192.168.1.12 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt; login authentication no_authentication&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; password cisco&lt;/P&gt;&lt;P&gt; login authentication VTY&lt;/P&gt;&lt;P&gt; transport input telnet&lt;/P&gt;&lt;P&gt;line vty 5 15&lt;/P&gt;&lt;P&gt; login authentication VTY&lt;/P&gt;&lt;P&gt; transport input telnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 08 Oct 2006 10:43:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-response-from-the-acs/m-p/671969#M422717</guid>
      <dc:creator>conceptzone</dc:creator>
      <dc:date>2006-10-08T10:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: No Response from the ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/no-response-from-the-acs/m-p/671970#M422719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you look in the failed attempts report on the secondary ACS - does it say anything?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to know if the request is making to the secondary, if its getting there is it being ignored or is there a problem in processing it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Failed attempts is the first place to look&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Darran&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Oct 2006 13:09:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-response-from-the-acs/m-p/671970#M422719</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2006-10-09T13:09:05Z</dc:date>
    </item>
    <item>
      <title>Re: No Response from the ACS</title>
      <link>https://community.cisco.com/t5/network-access-control/no-response-from-the-acs/m-p/671971#M422720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Daran,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately there are no any logs in the Secondary ACS, the only logs I can see is the commands I entered it on the AAA client, there is no failed attempts records.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Radius is dead, currently I bypassed this issue by installing a new ACS on a third server , the IT department is persistent to solve this issue from the root, they want me to analyze the problem and discover the reason behind this phenomenon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will dedicate a time next week to play very hard with this ACS to know what?s going on, meanwhile I will be glad if some one can tell me some methods to run a debug on the windows machine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Oct 2006 16:57:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-response-from-the-acs/m-p/671971#M422720</guid>
      <dc:creator>conceptzone</dc:creator>
      <dc:date>2006-10-10T16:57:00Z</dc:date>
    </item>
  </channel>
</rss>

