There are two RADIUS servers - Cisco ACS and some freeradius. Both servers are proxy servers for each other - we have on our distribution table their RADIUS as proxy, and they have ours. Problem - we can authenticate to their RADIUS with their username and password thru our ACS as proxy, but users which are stored in our Cisco ACS db cannot authenticate from their RADIUS - log message "CS password invalid", but for 100% the password is entered correctly.