03-29-2013 02:33 AM - edited 03-10-2019 08:14 PM
Hello.
I'm using ACS 5.4p2 within distributed systems: one primary and one secondary instance.
For now, primary instance is acting as Log Collector server and I can see any AAA audit logs.
When the primary instance fails I can authenticate successfully using the secondary instance.
However, when primary instance comes back, I'm not able to see any audit logs operated by secondary.
Please, can someone help me?
I'm trying different configuration without success!
Thanks.
Regards.
Andrea
Solved! Go to Solution.
04-02-2013 01:20 PM
Amjad, Minakshi,
many thanks for your help and patience.
I have found my mistake.
For the recovering Log Messages feature to work as desired, you must enable the Log to Local Target option for the relevant logging categories in ACS under System Administration > Configuration > Log Configuration > Logging Categories > Global.
And passed authentication is not enabled for this.
This solves my issue.
Regards.
Andrea
03-29-2013 04:19 AM
Hello Andrea,
You mean that after the primary come back up it handles ALL auth requests?
Or you mean you are sure some auth requests are being handled by the secondary but you don't see the corresponding logs in the log collector (the primary)?
Sent from Cisco Technical Support iPad App
03-29-2013 04:32 AM
Hello and many thanks for your help.
The second one. When primary fails, all authentications are operated by secondary.
When primary come back all authentications are operated by primary but I do not see the audit logs operated from secondary during the fault, in the log collector (the primary instance).
Regards.
03-29-2013 05:08 AM
Are you sure the secondary receives and handles auth requests?
I would suggest that you configure the radius server on one device to be the secondary only (remove the primary) and then check if you get the requests logged or not.
Regards,
Amjad
Sent from Cisco Technical Support iPad App
03-29-2013 06:36 AM
Yes Amjad.
The secondary instance works fine. When primary and secondary are running I can authenticate on both and see all AAA audit logs using the Monitoring & Report.
So, when primary fails, I continue to authenticate successfully on secondary.
When primary come back I do not see audit logs for authentications operated from secondary during the fault.
I believe something is wrong on my configuration (default)!
Regards.
Andrea
03-30-2013 12:49 AM
Thanks Andrea.
That is a strange issue. I would say if you are sure that all primary/secondary config is fine and the logging collector is fine that needs possibly needs to contact TAC.
But from my understanding to the ACS operation, the issue seems so weird and I think we are missing a point here.
If you search by ACS instance
If you try from the ACS view to query:
Reports -> Catalog -> AAA Protocol. choose "Radius_Authentication" and from the "RUN" button down extend the list by pressing the button and choose "Query and Run".
In the issue that appear choose the field "ACS instance", press "Select" button then from the new window press "Search" button. Choose only one instance (the secondary) and apply.
Then press "Run" button from the previous page.
This way, do you still miss the logs from the secondary?
Rating useful replies is more useful than saying "Thank you"
04-02-2013 06:34 AM
Yes, it is strange. I'm thinking I'm missing something on my configuration.
This morning, I'm started with a fresh ACS 5.4 installation, install license, create one AAA client and one user. Then add the secondary instance an wait it to be updated.
Log collector runs on primary and logs AAA audit correctly from primary and secondary instances.
Log recovery is enabled: run every 10 minutes.
When the primary instance is down I can auhenticate on secondary one without any problems.
When the primary instance come back I'm able to see only failed AAA log coming from secondary during the primary fault.
Any ideas?
Yes, it is strange. I'm thinking I'm missing something on my configuration.
This morning, I'm started with a fresh ACS 5.4 installation, install license, create one AAA client and one user. Then add the secondary instance an wait it to be updated.
Log collector runs on primary and logs AAA audit correctly from primary and secondary instance.
Log recovery is enabled.
When the primary instance is down I can auhenticate on secondary instance without any problem.
When the primary instance come back I'm able to see only failed AAA log coming from secondary during the primary fault.
Any ideas?
04-02-2013 10:42 AM
Hi
Did you run debugs on teh device and checked whetehr the request is even reaching to primary ACS?
- Which device are you using for authentication like switch/ASA/Router.
- Also when you get the login failures, can you check on the failed attempts of the ACS, which ACS instance is being used?
Regards
Minakshi (do Rate the helpful posts)
04-02-2013 01:20 PM
Amjad, Minakshi,
many thanks for your help and patience.
I have found my mistake.
For the recovering Log Messages feature to work as desired, you must enable the Log to Local Target option for the relevant logging categories in ACS under System Administration > Configuration > Log Configuration > Logging Categories > Global.
And passed authentication is not enabled for this.
This solves my issue.
Regards.
Andrea
04-02-2013 10:23 PM
Andrea,
+5 for resolving your own issue.
Thank you for your explanation.
I just now read above that you can see only failed attempts but not passed auth attempts.
I think I need to read more carefully in the future.
Thank you again and let's see you around.
Amjad
Rating useful replies is more useful than saying "Thank you"
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide