<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA server IAS first authentication failed in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-server-ias-first-authentication-failed/m-p/1668794#M561217</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;The problem I have is that after more than 24hours of unutilization, when i try to log in, my authentication failed the first time and then the other tries work fine as long as I use it in a period of 24hours.﻿&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which authentication is failing? Is it the AD authentication or the Radius w/ security token? Prior to the failure, what is the status of the servers? You can run "show aaa-server" to find out. Also, what is your reactivation-mode set to?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, I would check the debugs to see why the authentication is failing. You can also check the logs on the server to see if the server is rejecting the connection. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;Is there a tool/option in the ASA to check connectivity with the radius every 1h for example.&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No. You could setup a script to login and use the "test aaa-server authentication" command periodically. But this should not be necessary. I would recommend troubleshooting the root cause rather than trying to mask the problem with workarounds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Brendan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 06 Jun 2011 14:57:52 GMT</pubDate>
    <dc:creator>brquinn</dc:creator>
    <dc:date>2011-06-06T14:57:52Z</dc:date>
    <item>
      <title>ASA server IAS first authentication failed</title>
      <link>https://community.cisco.com/t5/network-security/asa-server-ias-first-authentication-failed/m-p/1668793#M561215</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a little problem with my ASA 5510 version 8.2(1) with a IAS server RADIUS for strong authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured a double authentication for my client to access SSL portal:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;First authentication: AD server&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;Secondary authentication: IAS for my token SAFENET ALADDIN&lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The server IAS is declared on a W2K3﻿ and it's standard.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem I have is that after more than 24hours of unutilization, when i try to log in, my authentication failed the first time and then the other tries work fine as long as I use it in a period of 24hours.﻿&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I first thought about the timeout so i tried to put a "timeout" of 15seconds for AD and IAS servers and a "retry intervall" of 3 seconds, it doesn't change much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have an idea? Is there a tool/option in the ASA to check connectivity with the radius every 1h for example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:42:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-server-ias-first-authentication-failed/m-p/1668793#M561215</guid>
      <dc:creator>alexandre.sitbon</dc:creator>
      <dc:date>2019-03-11T20:42:33Z</dc:date>
    </item>
    <item>
      <title>ASA server IAS first authentication failed</title>
      <link>https://community.cisco.com/t5/network-security/asa-server-ias-first-authentication-failed/m-p/1668794#M561217</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;The problem I have is that after more than 24hours of unutilization, when i try to log in, my authentication failed the first time and then the other tries work fine as long as I use it in a period of 24hours.﻿&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which authentication is failing? Is it the AD authentication or the Radius w/ security token? Prior to the failure, what is the status of the servers? You can run "show aaa-server" to find out. Also, what is your reactivation-mode set to?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, I would check the debugs to see why the authentication is failing. You can also check the logs on the server to see if the server is rejecting the connection. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;Is there a tool/option in the ASA to check connectivity with the radius every 1h for example.&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No. You could setup a script to login and use the "test aaa-server authentication" command periodically. But this should not be necessary. I would recommend troubleshooting the root cause rather than trying to mask the problem with workarounds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Brendan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jun 2011 14:57:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-server-ias-first-authentication-failed/m-p/1668794#M561217</guid>
      <dc:creator>brquinn</dc:creator>
      <dc:date>2011-06-06T14:57:52Z</dc:date>
    </item>
    <item>
      <title>ASA server IAS first authentication failed</title>
      <link>https://community.cisco.com/t5/network-security/asa-server-ias-first-authentication-failed/m-p/1668795#M561219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's the RADIUS that failed on the first authentication.&lt;/P&gt;&lt;P&gt;My radius and AD servers are in two different aaa-server-group.&lt;/P&gt;&lt;P&gt;My RADIUS server has a reactivation mode: depletion&lt;BR /&gt;Dead time: 10 minutes&lt;BR /&gt;Timeout: 15s&lt;BR /&gt;Retry intervall: 5s&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;My RADIUS SERVER:&lt;/P&gt;&lt;P&gt;Server port:&amp;nbsp; 1645(authentication), 1646(accounting)&lt;BR /&gt;Number of pending requests&amp;nbsp; 0&lt;BR /&gt;Average round trip time&amp;nbsp;&amp;nbsp; 1897ms&lt;BR /&gt;Number of authentication requests 24&lt;BR /&gt;Number of authorization requests 0&lt;BR /&gt;Number of accounting requests&amp;nbsp; 0&lt;BR /&gt;Number of retransmissions&amp;nbsp; 11&lt;BR /&gt;Number of accepts&amp;nbsp;&amp;nbsp; 12&lt;BR /&gt;Number of rejects&amp;nbsp;&amp;nbsp; 8&lt;BR /&gt;Number of challenges&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;Number of malformed responses&amp;nbsp; 0&lt;BR /&gt;Number of bad authenticators&amp;nbsp; 0&lt;BR /&gt;Number of timeouts&amp;nbsp;&amp;nbsp; 4&lt;BR /&gt;Number of unrecognized responses 0&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;My AD SERVER:&lt;/P&gt;&lt;P&gt;Server port:&amp;nbsp; 0&lt;BR /&gt;Number of pending requests&amp;nbsp; 0&lt;BR /&gt;Average round trip time&amp;nbsp;&amp;nbsp; 0ms&lt;BR /&gt;Number of authentication requests 1779&lt;BR /&gt;Number of authorization requests 0&lt;BR /&gt;Number of accounting requests&amp;nbsp; 0&lt;BR /&gt;Number of retransmissions&amp;nbsp; 0&lt;BR /&gt;Number of accepts&amp;nbsp;&amp;nbsp; 1682&lt;BR /&gt;Number of rejects&amp;nbsp;&amp;nbsp; 97&lt;BR /&gt;Number of challenges&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;Number of malformed responses&amp;nbsp; 0&lt;BR /&gt;Number of bad authenticators&amp;nbsp; 0&lt;BR /&gt;Number of timeouts&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;Number of unrecognized responses 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the logs it's the same message as authentication failed. It does the same thing when a bad password is inserted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is another RADIUS SERVER in an another group that uses the same port 1645(authentication), 1646(accounting), can it causes problem? (this server is not used).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll check test aaa-server authentication tomorrow.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;THanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jun 2011 15:21:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-server-ias-first-authentication-failed/m-p/1668795#M561219</guid>
      <dc:creator>alexandre.sitbon</dc:creator>
      <dc:date>2011-06-06T15:21:25Z</dc:date>
    </item>
    <item>
      <title>ASA server IAS first authentication failed</title>
      <link>https://community.cisco.com/t5/network-security/asa-server-ias-first-authentication-failed/m-p/1668796#M561220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;On the logs it's the same message as authentication failed. It does the same thing when a bad password is inserted.&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which logs? The ASA logs or the Radius server logs? If the Server is failing the authentication, then we need to know why. I'd run a packet capture on the server and make sure the token is being sent correctly. Wireshark should be able to decode the radius packets if you use the shared secret key.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;There is another RADIUS SERVER in an another group that uses the same port 1645(authentication), 1646(accounting), can it causes problem? (this server is not used).&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the other server is in a different aaa group, then that configuration shouldn't be relevant. You should see in the 'show aaa-server' output that no auth requests are being sent to that server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Brendan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jun 2011 16:58:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-server-ias-first-authentication-failed/m-p/1668796#M561220</guid>
      <dc:creator>brquinn</dc:creator>
      <dc:date>2011-06-06T16:58:33Z</dc:date>
    </item>
    <item>
      <title>ASA server IAS first authentication failed</title>
      <link>https://community.cisco.com/t5/network-security/asa-server-ias-first-authentication-failed/m-p/1668797#M561221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; It's on the Radius Server Logs that i've seen that the authentication failed. What is the command CLI or in ASDM to see the log RADIUS on the ASA? By the way my RADIUS server is on VMWARE, do you think that might cause a problem? (maybe when you don't share any data for a while, VMWARE does something...)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The idea of Wireshark is good, I'll try that as soon as I can.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jun 2011 13:26:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-server-ias-first-authentication-failed/m-p/1668797#M561221</guid>
      <dc:creator>alexandre.sitbon</dc:creator>
      <dc:date>2011-06-07T13:26:58Z</dc:date>
    </item>
  </channel>
</rss>

