<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA on 4503 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-on-4503/m-p/552829#M426896</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hector, I forgot to say that when I configured TACACS, the authentication worked fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got solution. Tomorrow at night I did the IOS upgrade of switch. I changed the version cat4000-i9s-mz.122-25.EWA4.bin per version cat4000-i9s-mz.122-25.EWA6.bin and RADIUS authentication worked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Jul 2006 10:37:20 GMT</pubDate>
    <dc:creator>rdamaso</dc:creator>
    <dc:date>2006-07-13T10:37:20Z</dc:date>
    <item>
      <title>AAA on 4503</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-on-4503/m-p/552827#M426892</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a curious problem about radius authentication. I have a 4503 with radius enabled authenticating on ACS 4.0. For while I don?t enabled dot1x. I?m testing authentication throught telnet. I have a ACS 3.3 and a 4.0 and the problem happens with both.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My config is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group radius local&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group radius local&lt;/P&gt;&lt;P&gt;aaa authorization network default group radius local&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;radius-server host 192.168.1.13 auth-port 1812 acct-port 1813 key 7 141F1E0C2C052938&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured ACS correctly as the follow url: &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/switches/ps700/products_tech_note09186a00801d11a4.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/switches/ps700/products_tech_note09186a00801d11a4.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried change the radius ports to 1645 and 1646 and the problem remained.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I put the 3550 with the same config, it works fine with the two ACS servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The conectivity between ACSs and 4503 is perfect, they are and the same network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Look the results of debug radius and debug aaa authentication on the file attached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:39:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-on-4503/m-p/552827#M426892</guid>
      <dc:creator>rdamaso</dc:creator>
      <dc:date>2019-03-10T21:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: AAA on 4503</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-on-4503/m-p/552828#M426894</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the debug output, it sounds like connectivity problem to 192.168.1.13.  Can the 4506s  ping 192.168.1.13?  Do you see failed attempts on the ACSs logs coming from the 4503s(if not that means that the access-request packet is not getting to ACS)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!  If so, please rate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Jul 12 14:52:16: RADIUS: Retransmit to (192.168.1.13:1812,1813) for id 21645/78&lt;/P&gt;&lt;P&gt;*Jul 12 14:52:16: RADIUS: acct-delay-time for 17B1C9CC (at 17B1CA33) now 10&lt;/P&gt;&lt;P&gt;HT4503#&lt;/P&gt;&lt;P&gt;*Jul 12 14:52:19: RADIUS: Retransmit to (192.168.1.13:1812,1813) for id 21645/79&lt;/P&gt;&lt;P&gt;HT4503#&lt;/P&gt;&lt;P&gt;*Jul 12 14:52:21: RADIUS: Retransmit to (192.168.1.13:1812,1813) for id 21645/78&lt;/P&gt;&lt;P&gt;*Jul 12 14:52:21: RADIUS: acct-delay-time for 17B1C9CC (at 17B1CA33) now 15&lt;/P&gt;&lt;P&gt;HT4503#&lt;/P&gt;&lt;P&gt;*Jul 12 14:52:25: RADIUS: Retransmit to (192.168.1.13:1812,1813) for id 21645/79&lt;/P&gt;&lt;P&gt;HT4503#&lt;/P&gt;&lt;P&gt;*Jul 12 14:52:27: RADIUS: Tried all servers.&lt;/P&gt;&lt;P&gt;*Jul 12 14:52:27: RADIUS: No valid server found. Trying any viable server&lt;/P&gt;&lt;P&gt;*Jul 12 14:52:27: RADIUS: Tried all servers.&lt;/P&gt;&lt;P&gt;*Jul 12 14:52:27: RADIUS: No response from (192.168.1.13:1812,1813) for id 21645/78&lt;/P&gt;&lt;P&gt;*Jul 12 14:52:27: AAA/MEMORY: free_user (0x175ABDD8) user='halogica' ruser='NULL' port='tty2' rem_addr='192.168.1.194' authen_type=ASCII service=LOGIN priv=1&lt;/P&gt;&lt;P&gt;HT4503#&lt;/P&gt;&lt;P&gt;*Jul 12 14:52:31: RADIUS: Retransmit to (192.168.1.13:1812,1813) for id 21645/79&lt;/P&gt;&lt;P&gt;HT4503#&lt;/P&gt;&lt;P&gt;*Jul 12 14:52:36: RADIUS: Tried all servers.&lt;/P&gt;&lt;P&gt;*Jul 12 14:52:36: RADIUS: No valid server found. Trying any viable server&lt;/P&gt;&lt;P&gt;*Jul 12 14:52:36: RADIUS: Tried all servers.&lt;/P&gt;&lt;P&gt;*Jul 12 14:52:36: RADIUS: No response from (192.168.1.13:1812,1813) for id 21645/79&lt;/P&gt;&lt;P&gt;*Jul 12 14:52:36: RADIUS: No response from server&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Jul 2006 21:57:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-on-4503/m-p/552828#M426894</guid>
      <dc:creator>hemendoz</dc:creator>
      <dc:date>2006-07-12T21:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: AAA on 4503</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-on-4503/m-p/552829#M426896</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hector, I forgot to say that when I configured TACACS, the authentication worked fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got solution. Tomorrow at night I did the IOS upgrade of switch. I changed the version cat4000-i9s-mz.122-25.EWA4.bin per version cat4000-i9s-mz.122-25.EWA6.bin and RADIUS authentication worked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jul 2006 10:37:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-on-4503/m-p/552829#M426896</guid>
      <dc:creator>rdamaso</dc:creator>
      <dc:date>2006-07-13T10:37:20Z</dc:date>
    </item>
  </channel>
</rss>

