<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA RADIUS issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-radius-issue/m-p/2599526#M75899</link>
    <description>&lt;P&gt;Hello everybody.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I am having some trouble when lots of users try to connect via Anyconnect on my ASA (5545-X).&lt;/P&gt;&lt;P&gt;At the peak some users complaints they cannot authenticate and I see these messages flaping on logs:&lt;/P&gt;&lt;P&gt;%ASA-2-113022: AAA Marking RADIUS server 1.1.1.1 in aaa-server group SRV-RADIUS1 as FAILED&lt;BR /&gt;%ASA-2-113023: AAA Marking RADIUS server 1.1.1.1 in aaa-server group SRV-RADIUS1 as ACTIVE&lt;/P&gt;&lt;P&gt;After a while it get back working normaly and has no more message like that.&lt;/P&gt;&lt;P&gt;Changing the "timeout" parameter (default is 10) to a higher number is a good idea? Or the problem could be at Radius server?&lt;/P&gt;&lt;P&gt;aaa-server SRV-RADIUS1 protocol radius&lt;BR /&gt;aaa-server SRV-RADIUS1 (inside) host 1.1.1.1&lt;BR /&gt;&amp;nbsp;time-out 20&lt;/P&gt;&lt;P&gt;thnks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 05:12:44 GMT</pubDate>
    <dc:creator>Vitor Stefaneli</dc:creator>
    <dc:date>2019-03-11T05:12:44Z</dc:date>
    <item>
      <title>AAA RADIUS issue</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-radius-issue/m-p/2599526#M75899</link>
      <description>&lt;P&gt;Hello everybody.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I am having some trouble when lots of users try to connect via Anyconnect on my ASA (5545-X).&lt;/P&gt;&lt;P&gt;At the peak some users complaints they cannot authenticate and I see these messages flaping on logs:&lt;/P&gt;&lt;P&gt;%ASA-2-113022: AAA Marking RADIUS server 1.1.1.1 in aaa-server group SRV-RADIUS1 as FAILED&lt;BR /&gt;%ASA-2-113023: AAA Marking RADIUS server 1.1.1.1 in aaa-server group SRV-RADIUS1 as ACTIVE&lt;/P&gt;&lt;P&gt;After a while it get back working normaly and has no more message like that.&lt;/P&gt;&lt;P&gt;Changing the "timeout" parameter (default is 10) to a higher number is a good idea? Or the problem could be at Radius server?&lt;/P&gt;&lt;P&gt;aaa-server SRV-RADIUS1 protocol radius&lt;BR /&gt;aaa-server SRV-RADIUS1 (inside) host 1.1.1.1&lt;BR /&gt;&amp;nbsp;time-out 20&lt;/P&gt;&lt;P&gt;thnks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:12:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-radius-issue/m-p/2599526#M75899</guid>
      <dc:creator>Vitor Stefaneli</dc:creator>
      <dc:date>2019-03-11T05:12:44Z</dc:date>
    </item>
    <item>
      <title>Couple of questions:1. How</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-radius-issue/m-p/2599527#M75904</link>
      <description>&lt;P&gt;Couple of questions:&lt;/P&gt;&lt;P&gt;1. How many VPN users do you have concurrently authenticating against the Radius server&lt;/P&gt;&lt;P&gt;2. What type of Radius solution are you using&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Nov 2014 04:02:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-radius-issue/m-p/2599527#M75904</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-11-25T04:02:37Z</dc:date>
    </item>
    <item>
      <title>So, it is usually about of</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-radius-issue/m-p/2599528#M75909</link>
      <description>&lt;P&gt;So, it is usually about of 400 total users. I think that are not more than 10 users accessing the Radius at same time on peak hours. The Radius runs on a Windows 2003 platform.&lt;BR /&gt;I've changed the timeout and the problem appears stopped.&lt;/P&gt;&lt;P&gt;But I also noted that the ASA sends lots of attributes to Radius server.&lt;BR /&gt;Actually I need just two: user (1) and password (2).&lt;/P&gt;&lt;P&gt;I have a new question: Is it possible to change the number of attributes ASA sends out??? I mean, to do not include attrib (26) Vendor-Specific, for example.&lt;/P&gt;&lt;P&gt;Thks again&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;(sorry my english)&lt;/P&gt;</description>
      <pubDate>Tue, 25 Nov 2014 13:21:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-radius-issue/m-p/2599528#M75909</guid>
      <dc:creator>Vitor Stefaneli</dc:creator>
      <dc:date>2014-11-25T13:21:08Z</dc:date>
    </item>
    <item>
      <title>Hi Vitor and sorry for the</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-radius-issue/m-p/2599529#M75911</link>
      <description>&lt;P&gt;Hi Vitor and sorry for the delayed reply! Your English is just fine! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I am glad that changing the "timeout" value have solved the problem.&lt;/P&gt;&lt;P&gt;On your second question: I never had to filter any attributes out of the ASA and I am not sure if it is possible. With that being said, I don't think that the issue was/is with the ASA sending too much logging/Radius info. If you only had around 10 concurrent users during your peak hours then there is no way that they overwhelmed the Radius server &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; The fact that the issue went away after changing the "timeout" value leads me to believe that the problem is related to something else. For instance, RTT (round trip delay) between the aaa server and your ASA or link saturation that causes bandwidth starvation which cases the server to timeout in the ASA...just some ideas here &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I hope this helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Nov 2014 00:05:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-radius-issue/m-p/2599529#M75911</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-11-29T00:05:07Z</dc:date>
    </item>
    <item>
      <title>Hi @Neno, i guess you are</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-radius-issue/m-p/2599530#M75912</link>
      <description>&lt;P&gt;Hi @Neno, i guess you are right. It´s something other than some ASA problem.&lt;/P&gt;&lt;P&gt;Actually, after some working on that, we figured out that is caused probably by an application code/platform problem.&lt;/P&gt;&lt;P&gt;My ask about changing the RADIUS attribs that ASA sends, in fact is an 'help' to the application. Cause if it did not receive these attributes, it will not process that, and the RTT may decrease.&lt;/P&gt;&lt;P&gt;Anyway, now we are looking for the possibilities to change the application or improve the infrastructure.&lt;/P&gt;&lt;P&gt;Thank you for your attention.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Dec 2014 12:26:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-radius-issue/m-p/2599530#M75912</guid>
      <dc:creator>Vitor Stefaneli</dc:creator>
      <dc:date>2014-12-05T12:26:49Z</dc:date>
    </item>
    <item>
      <title>Filtering the attributes</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-radius-issue/m-p/2599531#M75913</link>
      <description>&lt;P&gt;Filtering the attributes would make sense if you could confirm that the server is being overwhelmed. For instance, check the CPU and memory utilization. If those are normal then the server is fine. You can also do a traceroute to the Radius server from a PC that is behind the ASA and see if there any loops or hops that have large RTT.&lt;/P&gt;&lt;P&gt;Either way, let us know what the solution is.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Dec 2014 18:45:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-radius-issue/m-p/2599531#M75913</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-12-06T18:45:43Z</dc:date>
    </item>
  </channel>
</rss>

