<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA server repeatedly down in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-server-repeatedly-down/m-p/5167182#M591487</link>
    <description>&lt;P&gt;We are trying to do enforcement through 802.1X. Switch is configure as SNMP and CLI.&lt;/P&gt;</description>
    <pubDate>Wed, 28 Aug 2024 14:47:27 GMT</pubDate>
    <dc:creator>LY YIHEANG</dc:creator>
    <dc:date>2024-08-28T14:47:27Z</dc:date>
    <item>
      <title>AAA server repeatedly down</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-server-repeatedly-down/m-p/5167150#M591475</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We have Cisco Switch Configured with RADIUS Server (FortiNAC). We noticed that AAA Server down more frequently after multiple RADIUS request. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Example: Two Endpoints authenticated with RADIUS (FortiNAC) Port 1 and Port 2. If one of the port restart. RADIUS Server become down. After deadtime expired (10minutes). AAA become up again and it is able to authenticate but if one of the port restart, AAA come down again. The issue repeatedly happen. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What i have troubleshooting: - Connection to radius server up and running - Connection Radius port 1812-1813, CoA is reachable in bidirection connection between Switch and Radius Server&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Note: We have only 1 Radius Server&lt;/P&gt;
&lt;P&gt;Is there anyone having same issue, please share resolution&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank You&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 13:41:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-server-repeatedly-down/m-p/5167150#M591475</guid>
      <dc:creator>LY YIHEANG</dc:creator>
      <dc:date>2024-08-28T13:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: AAA server repeatedly down</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-server-repeatedly-down/m-p/5167159#M591476</link>
      <description>&lt;P&gt;try use&amp;nbsp;&lt;/P&gt;
&lt;P&gt;automate-tester username radius-test idle-time 10&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 14:06:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-server-repeatedly-down/m-p/5167159#M591476</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-08-28T14:06:18Z</dc:date>
    </item>
    <item>
      <title>Re: AAA server repeatedly down</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-server-repeatedly-down/m-p/5167163#M591479</link>
      <description>&lt;P&gt;I have tried it. It bring RADIUS up after dead-time expired (10 minutes) but Client will get into critical VLAN before RADIUS is up back. Anyway, Can you explain how it detect RADIUS down? it is based on Authentication or Accounting?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 14:11:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-server-repeatedly-down/m-p/5167163#M591479</guid>
      <dc:creator>LY YIHEANG</dc:creator>
      <dc:date>2024-08-28T14:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: AAA server repeatedly down</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-server-repeatedly-down/m-p/5167166#M591481</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Client will get into critical VLAN &amp;lt;&amp;lt;- this very good point&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Config timeout under server to make SW little longer wait the aaa server reply&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;MHM&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 14:19:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-server-repeatedly-down/m-p/5167166#M591481</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-08-28T14:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: AAA server repeatedly down</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-server-repeatedly-down/m-p/5167171#M591484</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I have put inside the dead-criteria already? Can you explain the different between global dead-criteria and timeout under individual server?&lt;/P&gt;
&lt;P&gt;Thank You&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 14:26:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-server-repeatedly-down/m-p/5167171#M591484</guid>
      <dc:creator>LY YIHEANG</dc:creator>
      <dc:date>2024-08-28T14:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: AAA server repeatedly down</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-server-repeatedly-down/m-p/5167180#M591486</link>
      <description>&lt;P&gt;What is the path from the switch to FortiNAC?&amp;nbsp; What is the use-case for RADIUS on FortiNAC?&amp;nbsp; FortiNAC has a VERY limited EAP service.&amp;nbsp; How are you doing enforcement from FortiNAC?&amp;nbsp; CLI?&amp;nbsp; SNMP?&amp;nbsp; Something else?&amp;nbsp; Is the switch properly discovered and added into FortiNAC with valid CLI and SNMP credentials?&amp;nbsp; What role is CoA playing here?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 14:45:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-server-repeatedly-down/m-p/5167180#M591486</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-08-28T14:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: AAA server repeatedly down</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-server-repeatedly-down/m-p/5167182#M591487</link>
      <description>&lt;P&gt;We are trying to do enforcement through 802.1X. Switch is configure as SNMP and CLI.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 14:47:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-server-repeatedly-down/m-p/5167182#M591487</guid>
      <dc:creator>LY YIHEANG</dc:creator>
      <dc:date>2024-08-28T14:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: AAA server repeatedly down</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-server-repeatedly-down/m-p/5167189#M591488</link>
      <description>&lt;P&gt;Radius-server dead criteria time &amp;lt;make this longer&amp;gt; tries &lt;span class="lia-unicode-emoji" title=":red_heart:"&gt;❤️&lt;/span&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":red_heart:"&gt;❤️&lt;/span&gt;is good&amp;gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Radius-server deadtime &amp;lt;make this time shorter&amp;gt;&lt;/P&gt;
&lt;P&gt;The issue is SW send to aaa server but not receive reply in dead criteria time×3 this make SW mark aaa server as dead and authz port with critical vlan&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 14:57:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-server-repeatedly-down/m-p/5167189#M591488</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-08-28T14:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: AAA server repeatedly down</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-server-repeatedly-down/m-p/5167224#M591492</link>
      <description>&lt;P&gt;So something is wrong between the switch and FortiNAC. Is the FortiNAC RADIUS/EAP service enabled?&amp;nbsp; What is your EAP type?&amp;nbsp; What is the path from the switch to FortiNAC?&amp;nbsp; Are your RADIUS keys correct?&amp;nbsp; What do the FortiNAC logs say?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 16:24:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-server-repeatedly-down/m-p/5167224#M591492</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-08-28T16:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: AAA server repeatedly down</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-server-repeatedly-down/m-p/5167269#M591496</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1360304"&gt;@LY YIHEANG&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Try this "automate-tester username fnac-user&amp;nbsp;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;ignore-acct-port&lt;/FONT&gt;&lt;/STRONG&gt; idle-time 1"&lt;/P&gt;&lt;P&gt;Regards!&lt;/P&gt;&lt;P&gt;Don't forget to rate helpful posts!&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 18:19:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-server-repeatedly-down/m-p/5167269#M591496</guid>
      <dc:creator>Amine ZAKARIA</dc:creator>
      <dc:date>2024-08-28T18:19:09Z</dc:date>
    </item>
  </channel>
</rss>

