<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ACS Problem in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-acs-problem/m-p/390048#M433508</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mentioned that this only happens at "certain period of time". Check your backup/database replication schedule(s) and see if they coincide. The ACS system can become temporarily unavailable during the times that it is performing these procedures. If that is the cause, you might consider changing your backup/replication schedules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-=Phil=-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 05 Dec 2004 08:00:49 GMT</pubDate>
    <dc:creator>p-dolbow</dc:creator>
    <dc:date>2004-12-05T08:00:49Z</dc:date>
    <item>
      <title>Cisco ACS Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-problem/m-p/390046#M433506</link>
      <description>&lt;P&gt;I recently have some problem with the Cisco ACS server, which is the login authentication server for my switches and routers.  Everyday at a certain period of time, I just can't login to the gears; or I can login, but after dozens of attempts.  A "debug tacacs" shows the following error messages:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-ERROR 1-&lt;/P&gt;&lt;P&gt;Sep 25 08:58:09.638 EST: TAC+: 192.168.100.100 (1005873793) AUTHEN/CONT -- TIMED OUT&lt;/P&gt;&lt;P&gt;Sep 25 08:58:09.638 EST: TAC+: (1005873793) AUTHEN/CONT processed&lt;/P&gt;&lt;P&gt;Sep 25 08:58:09.638 EST: TAC+: Error sending continue packet.&lt;/P&gt;&lt;P&gt;Sep 25 08:58:09.638 EST: TAC+: Closing TCP/IP 0x1D1A608 connection to 192.168.100.100/49&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-ERROR 2-&lt;/P&gt;&lt;P&gt;Sep 25 09:09:49.397 EST: TAC+: 192.168.100.100 (1396526313) AUTHEN/CONT -- TIMED OUT&lt;/P&gt;&lt;P&gt;Sep 25 09:09:49.397 EST: TAC+: (1396526313) AUTHEN/CONT processed&lt;/P&gt;&lt;P&gt;Sep 25 09:09:49.397 EST: TAC+: received bad AUTHEN packet: type = 0, expected 1&lt;/P&gt;&lt;P&gt;Sep 25 09:09:49.397 EST: TAC+: received corrupt data from server.&lt;/P&gt;&lt;P&gt;Sep 25 09:09:49.397 EST: TAC+: Closing TCP/IP 0x77D128 connection to 192.168.100.100/49&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-ERROR 3-&lt;/P&gt;&lt;P&gt;Sep 25 09:10:15.148 EST: TAC+: send AUTHEN/CONT packet id=3826363357&lt;/P&gt;&lt;P&gt;Sep 25 09:10:15.148 EST: TAC+: 192.168.100.100 (3826363357) AUTHEN/CONT queued&lt;/P&gt;&lt;P&gt;Sep 25 09:10:15.247 EST: TAC+: (3826363357) AUTHEN/CONT processed&lt;/P&gt;&lt;P&gt;Sep 25 09:10:15.247 EST: TAC+: received bad AUTHEN packet: session id = 13965263&lt;/P&gt;&lt;P&gt;13, expected 3826363357&lt;/P&gt;&lt;P&gt;Sep 25 09:10:15.250 EST: TAC+: received corrupt data from server.&lt;/P&gt;&lt;P&gt;Sep 25 09:10:15.250 EST: TAC+: Closing TCP/IP 0x76EC68 connection to 192.168.100.100/49&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apparently, I don't always get the same error when I failed to login.  I checked the activity reports on the ACS server, and found that, for all those failed attempts, the server actually has passed my authentication and replied to the gear.  No password errors or other failure records on the server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anyone has similar experience?  Or could anyone explain the possible reason for those errors in the debug output?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 20:49:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-problem/m-p/390046#M433506</guid>
      <dc:creator>josephqiu</dc:creator>
      <dc:date>2019-03-10T20:49:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-problem/m-p/390047#M433507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am also seeing the exact same error after the ACS has been up and running fine for about 6 weeks.  I haven't found any resolution, but count me as someone having a "similar experience"...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Dec 2004 21:05:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-problem/m-p/390047#M433507</guid>
      <dc:creator>psmith</dc:creator>
      <dc:date>2004-12-03T21:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-problem/m-p/390048#M433508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mentioned that this only happens at "certain period of time". Check your backup/database replication schedule(s) and see if they coincide. The ACS system can become temporarily unavailable during the times that it is performing these procedures. If that is the cause, you might consider changing your backup/replication schedules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-=Phil=-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Dec 2004 08:00:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-problem/m-p/390048#M433508</guid>
      <dc:creator>p-dolbow</dc:creator>
      <dc:date>2004-12-05T08:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-problem/m-p/390049#M433509</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Phil.  I'm glad to see my question got a reply after 4 months.  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;  Also, I'm not alone...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually, I was also thinking it's a problem just happens when database replication is undergoing.  However, I checked all my ACS servers, none of them has replication scheduled at the time the problem normally happens.  In other words, for my case, database replication should not be the cause.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, thanks a lot for your input.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Dec 2004 05:45:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-problem/m-p/390049#M433509</guid>
      <dc:creator>josephqiu</dc:creator>
      <dc:date>2004-12-09T05:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-problem/m-p/390050#M433512</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, I opened a TAC case for our problem and it turns out this is related to timeout issues with logging and the remote agent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're using the ACS appliance (not the software) and had configured remote logging on the agent.  When remote logging is disabled there are no more timeouts and TACACS authentication works correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our authentication problems were not intermittent, they occurred all the time, so this may not be the same as your issue.  But this may be a bug related to the remote agent - if you have remote logging enabled try disabling it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Dec 2004 16:30:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-problem/m-p/390050#M433512</guid>
      <dc:creator>psmith</dc:creator>
      <dc:date>2004-12-20T16:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-problem/m-p/390051#M433514</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have ACS installed on dedicated server, but not Cisco appliance.  I don't have remote logging enabled.  My problem is intermittent - probably is caused by network performance.  I will further investigate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, thank you for sharing the information!  Merry X'mas!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Dec 2004 19:13:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-problem/m-p/390051#M433514</guid>
      <dc:creator>josephqiu</dc:creator>
      <dc:date>2004-12-21T19:13:56Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-problem/m-p/390052#M433515</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like the forums have come to my help again.&lt;/P&gt;&lt;P&gt;I have been having this exact issue. TACACS authentication works fine, but as soon as Remote Logging is turned on, TACACS authentication does not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone know if this issues has been resolved.&lt;/P&gt;&lt;P&gt;I am using Cisco ACS Solution Engine v4.0.1.42 and the Remote Agent is running on a Windows 2000 server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Cam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Oct 2006 00:14:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-problem/m-p/390052#M433515</guid>
      <dc:creator>cammaher</dc:creator>
      <dc:date>2006-10-18T00:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS Problem</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-problem/m-p/390053#M433518</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For an alternative to remote logging, take a look at &lt;A class="jive-link-custom" href="http://www.extraxi.com/utils.htm" target="_blank"&gt;www.extraxi.com/utils.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a ACS specific utility to collect CSV logs over HTTP(S) called csvsync. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It can be scheduled, works with ALL versions and types of ACS, collects from ANY number of ACSs and can be scheduled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Oct 2006 09:46:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-problem/m-p/390053#M433518</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2006-10-18T09:46:32Z</dc:date>
    </item>
  </channel>
</rss>

