<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hey,This response is seen in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-asa-radius-invalid-response-received-from-server/m-p/2439362#M90421</link>
    <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;This response is seen when the response had something which the ASA did not like:&lt;/P&gt;&lt;P&gt;"Invalid response received from server"&lt;BR /&gt;I think you are using NPS, do you have detailed logs from there?&lt;/P&gt;&lt;P&gt;Rate if Useful &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Sharing knowledge makes you Immortal.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ed&lt;/P&gt;</description>
    <pubDate>Wed, 21 May 2014 06:48:57 GMT</pubDate>
    <dc:creator>edwardcollins7</dc:creator>
    <dc:date>2014-05-21T06:48:57Z</dc:date>
    <item>
      <title>Cisco ASA - Radius - Invalid response received from server</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-asa-radius-invalid-response-received-from-server/m-p/2439361#M90418</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We have run into an issue with Radius Authentication with one set of Cisco ASA Firewalls.&lt;/P&gt;&lt;P&gt;The issues is as follows:&lt;BR /&gt;&lt;BR /&gt;Initially, the radius preshared key was not configured for our primary radius server. This was noticed and corrected immediately. However, upon correcting this, we started receiving the following error:&lt;/P&gt;&lt;P&gt;ERROR: Authentication Error: Invalid response received from server&lt;/P&gt;&lt;P&gt;I looked at the radius server and it reports that the user was successfully authenticated. The output of the debug aaa-server authentication is as follows:&lt;/P&gt;&lt;P&gt;ASA# test aaa-server authentication la-radius-group&lt;BR /&gt;Server IP Address or name: &amp;lt;RADIUS&amp;gt;&lt;BR /&gt;Username: &amp;lt;USERNAME&amp;gt;&lt;BR /&gt;Password: *********&lt;BR /&gt;INFO: Attempting Authentication test to IP address &amp;lt;RADIUS&amp;gt; (timeout: 10 seconds)&lt;BR /&gt;radius mkreq: 0x1fa&lt;BR /&gt;alloc_rip 0x00007ffecc0b3f48&lt;BR /&gt;&amp;nbsp; &amp;nbsp; new request 0x1fa --&amp;gt; 14 (0x00007ffecc0b3f48)&lt;BR /&gt;got user 'username'&lt;BR /&gt;got password&lt;BR /&gt;add_req 0x00007ffecc0b3f48 session 0x1fa id 14&lt;BR /&gt;RADIUS_REQUEST&lt;BR /&gt;radius.c: rad_mkpkt&lt;/P&gt;&lt;P&gt;RADIUS packet decode (authentication request)&lt;/P&gt;&lt;P&gt;--------------------------------------&lt;BR /&gt;Raw packet data (length = 65).....&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;| &amp;nbsp;.&lt;/P&gt;&lt;P&gt;Parsed packet data.....&lt;BR /&gt;Radius: Code = 1 (0x01)&lt;BR /&gt;Radius: Identifier = 14 (0x0E)&lt;BR /&gt;Radius: Length = 65 (0x0041)&lt;BR /&gt;Radius: Vector: E27330A92ECF5C653AEB48E106C7F41D&lt;BR /&gt;Radius: Type = 1 (0x01) User-Name&lt;BR /&gt;Radius: Length = 9 (0x09)&lt;BR /&gt;Radius: Value (String) =&lt;BR /&gt;Radius: Type = 2 (0x02) User-Password&lt;BR /&gt;Radius: Length = 18 (0x12)&lt;BR /&gt;Radius: Value (String) =&lt;BR /&gt;Radius: Type = 4 (0x04) NAS-IP-Address&lt;BR /&gt;Radius: Length = 6 (0x06)&lt;BR /&gt;Radius: Value (IP Address) = &amp;lt;ASA&amp;gt; (0xD04A88FD)&lt;BR /&gt;Radius: Type = 5 (0x05) NAS-Port&lt;BR /&gt;Radius: Length = 6 (0x06)&lt;BR /&gt;Radius: Value (Hex) = 0xE&lt;BR /&gt;Radius: Type = 61 (0x3D) NAS-Port-Type&lt;BR /&gt;Radius: Length = 6 (0x06)&lt;BR /&gt;Radius: Value (Hex) = 0x5&lt;BR /&gt;send pkt &amp;lt;RADIUS&amp;gt;/1645&lt;BR /&gt;rip 0x00007ffecc0b3f48 state 7 id 14&lt;BR /&gt;rad_vrfy() : response message verified&lt;BR /&gt;rip 0x00007ffecc0b3f48&lt;BR /&gt;&amp;nbsp;: chall_state ''&lt;BR /&gt;&amp;nbsp;: state 0x7&lt;BR /&gt;&amp;nbsp;: reqauth:&lt;BR /&gt;&amp;nbsp;: info 0x00007ffecc0b4088&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;session_id 0x1fa&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;request_id 0xe&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;user '&amp;lt;USERNAME&amp;gt;'&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;response '***'&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;app 0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;reason 0&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;skey '&amp;lt;KEY&amp;gt;'&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;sip &amp;lt;RADIUS&amp;gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;type 1&lt;/P&gt;&lt;P&gt;RADIUS packet decode (response)&lt;/P&gt;&lt;P&gt;--------------------------------------&lt;BR /&gt;Raw packet data (length = 78).....&lt;/P&gt;&lt;P&gt;Parsed packet data.....&lt;BR /&gt;Radius: Code = 2 (0x02)&lt;BR /&gt;Radius: Identifier = 14 (0x0E)&lt;BR /&gt;Radius: Length = 78 (0x004E)&lt;BR /&gt;Radius: Vector: 206B152DB5DD5C7996E4F1DD650F96A9&lt;BR /&gt;Radius: Type = 26 (0x1A) Vendor-Specific&lt;BR /&gt;Radius: Length = 6 (0x06)&lt;BR /&gt;Radius: Vendor ID = 9 (0x00000009)&lt;BR /&gt;Radius: Type = 6 (0x06) Unknown&lt;BR /&gt;Radius: Length = 6 (0x06)&lt;BR /&gt;Radius: Type = 6 (0x06) Service-Type&lt;BR /&gt;Radius: Length = 6 (0x06)&lt;BR /&gt;Radius: Value (Hex) = 0x1&lt;BR /&gt;Radius: Type = 25 (0x19) Class&lt;BR /&gt;Radius: Length = 46 (0x2E)&lt;BR /&gt;Radius: Value (String) =&lt;BR /&gt;rad_procpkt: ACCEPT&lt;BR /&gt;RADIUS_DELETE&lt;BR /&gt;remove_req 0x00007ffecc0b3f48 session 0x1fa id 14&lt;BR /&gt;free_rip 0x00007ffecc0b3f48&lt;BR /&gt;radius: send queue empty&lt;BR /&gt;ERROR: Authentication Error: Invalid response received from server&lt;/P&gt;&lt;P&gt;When looking at the logs on the Radius Server, I receive the following entry:&lt;/P&gt;&lt;P&gt;"Network Policy Server granted access to a user."&lt;/P&gt;&lt;P&gt;We have cleared the configuration, rebooted the ASA, and re-applied the radius configuration and the issue persisted.&lt;/P&gt;&lt;P&gt;We have multiple Cisco Devices that connect to this RADIUS server and this is the only device that has an issue.&lt;/P&gt;&lt;P&gt;Has anyone seen this before? I have not seen any articles stating an issue like this.&lt;/P&gt;&lt;P&gt;Thank you for any help.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:43:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-asa-radius-invalid-response-received-from-server/m-p/2439361#M90418</guid>
      <dc:creator>scott.ackley</dc:creator>
      <dc:date>2019-03-11T04:43:59Z</dc:date>
    </item>
    <item>
      <title>Hey,This response is seen</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-asa-radius-invalid-response-received-from-server/m-p/2439362#M90421</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;This response is seen when the response had something which the ASA did not like:&lt;/P&gt;&lt;P&gt;"Invalid response received from server"&lt;BR /&gt;I think you are using NPS, do you have detailed logs from there?&lt;/P&gt;&lt;P&gt;Rate if Useful &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Sharing knowledge makes you Immortal.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ed&lt;/P&gt;</description>
      <pubDate>Wed, 21 May 2014 06:48:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-asa-radius-invalid-response-received-from-server/m-p/2439362#M90421</guid>
      <dc:creator>edwardcollins7</dc:creator>
      <dc:date>2014-05-21T06:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA - Radius - Invalid response received from server</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-asa-radius-invalid-response-received-from-server/m-p/4682370#M577130</link>
      <description>&lt;P&gt;I resolved this problem by following this guide when using NPS. You need to create a separate Connection Request and Network Policy sepcifically for ASA.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.petenetlive.com/KB/Article/0000685" target="_blank"&gt;https://www.petenetlive.com/KB/Article/0000685&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Crister&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"Pay it forward."&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2022 02:42:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-asa-radius-invalid-response-received-from-server/m-p/4682370#M577130</guid>
      <dc:creator>crister</dc:creator>
      <dc:date>2022-09-07T02:42:44Z</dc:date>
    </item>
  </channel>
</rss>

