<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Every 6 hours RADIUS_DEAD - not responding in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/every-6-hours-radius-dead-not-responding/m-p/4183222#M563793</link>
    <description>&lt;P&gt;Every 6 hours on some devices we see in logs RADIUS_DEAD not responding with all three radius servers.&amp;nbsp; Other parts of the network it happenes even more frequently.&amp;nbsp; From debug it an accouting session initiates but soon after a tcp reset occurs due to NAS error (auth failed).&amp;nbsp; Between these six hours the radius servers comms are ok. No issues. We can access the device no problem but during RADIUS_DEAD were not able to access the host.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im trying to determine if the issue is with our local host that it has a parameters that the radius sever rejects or the issue is with the a misconfiguration at the radius server with local config is ok.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This particular device is C9300 but im seeing the same problem with 3650 and Nexus 9k all running their Cisco suggested IOS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is the full configuration and attached debug.&amp;nbsp; Appreciate people assistance in this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa group server radius X-RADIUS&lt;BR /&gt;server name X-RADIUS-1&lt;BR /&gt;server name X-RADIUS-2&lt;BR /&gt;server name X-RADIUS-3&lt;BR /&gt;ip radius source-interface VLANX&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa authentication login default group X-RADIUS local&lt;BR /&gt;aaa authentication login vty group X-RADIUS local&lt;BR /&gt;aaa authentication login con group X-RADIUS local&lt;BR /&gt;aaa authentication enable default line group X-RADIUS enable&lt;BR /&gt;aaa accounting send stop-record authentication failure&lt;BR /&gt;aaa accounting exec net-supp start-stop group X-RADIUS&lt;BR /&gt;aaa accounting connection net-supp start-stop group X-RADIUS&lt;BR /&gt;aaa authorization exec net-supp group X-RADIUS local&lt;BR /&gt;aaa authorization commands 1 net-supp group X-RADIUS local&lt;BR /&gt;aaa authorization commands 15 net-supp group X-RADIUS local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;radius server X-RADIUS-1&lt;BR /&gt;address ipv4 10.X.X.X auth-port 1812 acct-port 1813&lt;BR /&gt;key 1234abcd&lt;BR /&gt;radius server X-RADIUS-2&lt;BR /&gt;address ipv4 10.X.X.X auth-port 1812 acct-port 1813&lt;BR /&gt;key 1234abcd&lt;BR /&gt;radius server X-RADIUS-3&lt;BR /&gt;address ipv4 10.X.X.X auth-port 1812 acct-port 1813&lt;BR /&gt;key 1234abcd&lt;BR /&gt;!&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;line vty 0 15&lt;BR /&gt;password JGHGGS1&lt;BR /&gt;login authentication vty&lt;BR /&gt;accounting connection net-supp&lt;BR /&gt;accounting exec net-supp&lt;BR /&gt;transport input ssh&lt;BR /&gt;transport output none&lt;BR /&gt;exec-timeout 9 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Nov 2020 07:52:03 GMT</pubDate>
    <dc:creator>Barry Landon</dc:creator>
    <dc:date>2020-11-13T07:52:03Z</dc:date>
    <item>
      <title>Every 6 hours RADIUS_DEAD - not responding</title>
      <link>https://community.cisco.com/t5/network-access-control/every-6-hours-radius-dead-not-responding/m-p/4183222#M563793</link>
      <description>&lt;P&gt;Every 6 hours on some devices we see in logs RADIUS_DEAD not responding with all three radius servers.&amp;nbsp; Other parts of the network it happenes even more frequently.&amp;nbsp; From debug it an accouting session initiates but soon after a tcp reset occurs due to NAS error (auth failed).&amp;nbsp; Between these six hours the radius servers comms are ok. No issues. We can access the device no problem but during RADIUS_DEAD were not able to access the host.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im trying to determine if the issue is with our local host that it has a parameters that the radius sever rejects or the issue is with the a misconfiguration at the radius server with local config is ok.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This particular device is C9300 but im seeing the same problem with 3650 and Nexus 9k all running their Cisco suggested IOS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is the full configuration and attached debug.&amp;nbsp; Appreciate people assistance in this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa group server radius X-RADIUS&lt;BR /&gt;server name X-RADIUS-1&lt;BR /&gt;server name X-RADIUS-2&lt;BR /&gt;server name X-RADIUS-3&lt;BR /&gt;ip radius source-interface VLANX&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa authentication login default group X-RADIUS local&lt;BR /&gt;aaa authentication login vty group X-RADIUS local&lt;BR /&gt;aaa authentication login con group X-RADIUS local&lt;BR /&gt;aaa authentication enable default line group X-RADIUS enable&lt;BR /&gt;aaa accounting send stop-record authentication failure&lt;BR /&gt;aaa accounting exec net-supp start-stop group X-RADIUS&lt;BR /&gt;aaa accounting connection net-supp start-stop group X-RADIUS&lt;BR /&gt;aaa authorization exec net-supp group X-RADIUS local&lt;BR /&gt;aaa authorization commands 1 net-supp group X-RADIUS local&lt;BR /&gt;aaa authorization commands 15 net-supp group X-RADIUS local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;radius server X-RADIUS-1&lt;BR /&gt;address ipv4 10.X.X.X auth-port 1812 acct-port 1813&lt;BR /&gt;key 1234abcd&lt;BR /&gt;radius server X-RADIUS-2&lt;BR /&gt;address ipv4 10.X.X.X auth-port 1812 acct-port 1813&lt;BR /&gt;key 1234abcd&lt;BR /&gt;radius server X-RADIUS-3&lt;BR /&gt;address ipv4 10.X.X.X auth-port 1812 acct-port 1813&lt;BR /&gt;key 1234abcd&lt;BR /&gt;!&lt;BR /&gt;exit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;line vty 0 15&lt;BR /&gt;password JGHGGS1&lt;BR /&gt;login authentication vty&lt;BR /&gt;accounting connection net-supp&lt;BR /&gt;accounting exec net-supp&lt;BR /&gt;transport input ssh&lt;BR /&gt;transport output none&lt;BR /&gt;exec-timeout 9 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2020 07:52:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/every-6-hours-radius-dead-not-responding/m-p/4183222#M563793</guid>
      <dc:creator>Barry Landon</dc:creator>
      <dc:date>2020-11-13T07:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: Every 6 hours RADIUS_DEAD - not responding</title>
      <link>https://community.cisco.com/t5/network-access-control/every-6-hours-radius-dead-not-responding/m-p/4183252#M563794</link>
      <description>&lt;P&gt;&amp;nbsp; &amp;gt;...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;EM&gt; &amp;gt;This particular device is C9300 but I m seeing the same problem with 3650 and Nexus 9k all running their Cisco suggested IOS.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; - Since different device types are involved I also suggest in analyzing network behavior and or traffic. Look for bursts, networking spikes , or&amp;nbsp; just traffic data from/to those devices at that time but also during normal operation. Also use&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;syslogging to a central syslog server, and the same for snmp-traps to a trap receiver.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;M.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2020 08:27:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/every-6-hours-radius-dead-not-responding/m-p/4183252#M563794</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2020-11-13T08:27:30Z</dc:date>
    </item>
    <item>
      <title>Re: Every 6 hours RADIUS_DEAD - not responding</title>
      <link>https://community.cisco.com/t5/network-access-control/every-6-hours-radius-dead-not-responding/m-p/4183456#M563808</link>
      <description>&lt;DIV class=" pExampleCMT"&gt;&lt;STRONG&gt;automate-tester username dummy&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class=" pExampleCMT"&gt;Try this which make NAS test aaa reach ability&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 13 Nov 2020 14:31:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/every-6-hours-radius-dead-not-responding/m-p/4183456#M563808</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2020-11-13T14:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: Every 6 hours RADIUS_DEAD - not responding</title>
      <link>https://community.cisco.com/t5/network-access-control/every-6-hours-radius-dead-not-responding/m-p/4183522#M563816</link>
      <description>&lt;P&gt;Does this test the connection to the radius server only at set intervals or sends probe once the radius is marked as dead?&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2020 15:59:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/every-6-hours-radius-dead-not-responding/m-p/4183522#M563816</guid>
      <dc:creator>Barry Landon</dc:creator>
      <dc:date>2020-11-13T15:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: Every 6 hours RADIUS_DEAD - not responding</title>
      <link>https://community.cisco.com/t5/network-access-control/every-6-hours-radius-dead-not-responding/m-p/4183660#M563824</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="mkmkmk.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/88505i6DEFB54D5F387BFD/image-size/large?v=v2&amp;amp;px=999" role="button" title="mkmkmk.png" alt="mkmkmk.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2020 20:01:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/every-6-hours-radius-dead-not-responding/m-p/4183660#M563824</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2020-11-13T20:01:41Z</dc:date>
    </item>
    <item>
      <title>Re: Every 6 hours RADIUS_DEAD - not responding</title>
      <link>https://community.cisco.com/t5/network-access-control/every-6-hours-radius-dead-not-responding/m-p/4183977#M563844</link>
      <description>&lt;P&gt;If such events always associated with the accounting stop requests following auth failures, then you might consider to remove this line&lt;/P&gt;
&lt;PRE&gt;aaa accounting send stop-record authentication failure&lt;/PRE&gt;
&lt;P&gt;Regarding the configuration command&amp;nbsp;&lt;STRONG&gt;automate-tester&lt;/STRONG&gt;, see&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-services/whitepaper_C11-731907.html" target="_self"&gt;Demystifying RADIUS Server Configurations&lt;/A&gt;&amp;nbsp;&amp;gt;&amp;nbsp;RADIUS Server Failure Handling&lt;/LI&gt;
&lt;LI&gt;&lt;A href="https://community.cisco.com/t5/security-documents/cisco-ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_self"&gt;ISE Secure Wired Access Prescriptive Deployment Guide&lt;/A&gt;&amp;nbsp;&amp;gt;&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-documents/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515#toc-hId--554168365" target="_blank" rel="nofollow noopener noreferrer"&gt;Preparing a Switch for Identity-Based Network Access&lt;/A&gt;&amp;nbsp;&amp;gt;&amp;nbsp;Best Practice Global Settings for Switch &amp;gt; RADIUS Server Failure Detection
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Sat, 14 Nov 2020 22:26:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/every-6-hours-radius-dead-not-responding/m-p/4183977#M563844</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2020-11-14T22:26:28Z</dc:date>
    </item>
    <item>
      <title>Re: Every 6 hours RADIUS_DEAD - not responding</title>
      <link>https://community.cisco.com/t5/network-access-control/every-6-hours-radius-dead-not-responding/m-p/4184004#M563846</link>
      <description>&lt;P&gt;at interval the client send test to RADIUS and check if the RADIUS response or not.&lt;/P&gt;</description>
      <pubDate>Sun, 15 Nov 2020 00:15:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/every-6-hours-radius-dead-not-responding/m-p/4184004#M563846</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2020-11-15T00:15:04Z</dc:date>
    </item>
  </channel>
</rss>

