
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-11-2013 03:07 PM - edited 03-10-2019 08:53 PM
Hello,
I am trying to configure radius authentication on cisco ACS but running into issue. When i configure my Network Device Group in AAA Client setup to be one of radius device groups, my authentications are failing with authentication failure code as "
CS password invalid" but when i change my Network Device Group to "Not Assigned", everything starts working.
On my AAA client, when authentication are failing, i am seeing
packet from RADIUS server <ip address> fails verification:
Please note that AAA client is a non cisco device.
Any suggestions?
Solved! Go to Solution.
- Labels:
-
AAA
Accepted Solutions

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-12-2013 02:34 AM
It seems you're running ACS 4.x. You're facing this issues because the key defined on the NDG level (XYZ network device group in your case) over-rides the key at the AAA client level. Please make sure that you don't have different secret key on the AAA client inside the NDG and on the NDG itself.
Not assigned is working because there is no key defined in that NDG.
"Each device that is assigned to the Network Device Group will use the shared key that you enter here. The key that was assigned to the device when it was added to the system is ignored. If the key entry is null, the AAA client key is used."
~BR
Jatin Katyal
**Do rate helpful posts**
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-11-2013 09:30 PM
Which ACS version you are using?
ACS 4.0 is having this problem, If you are using the same, please update and try.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-12-2013 06:39 AM
Hi Nkumarsr,
It is infact ACS v4.0. Is there any cisco bug/document related to this issue?
Thanks

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-12-2013 02:34 AM
It seems you're running ACS 4.x. You're facing this issues because the key defined on the NDG level (XYZ network device group in your case) over-rides the key at the AAA client level. Please make sure that you don't have different secret key on the AAA client inside the NDG and on the NDG itself.
Not assigned is working because there is no key defined in that NDG.
"Each device that is assigned to the Network Device Group will use the shared key that you enter here. The key that was assigned to the device when it was added to the system is ignored. If the key entry is null, the AAA client key is used."
~BR
Jatin Katyal
**Do rate helpful posts**

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-12-2013 06:48 AM
Hi Jatin,
Thanks, that was the issue. When i first created the NDG, it did not pay attention to the field.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-12-2013 01:35 PM
Glad to know zafar.
~BR
Jatin Katyal
**Do rate helpful posts**
