cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1345
Views
0
Helpful
5
Replies

Nexus5K cannot update Radius config

the-lebowski
Level 4
Level 4

Hello

I am trying to update the radius configuration on our Nexus5K.  I simply need to add another radius host and remove the current one.  However when I attempt to add the new one I get this message:

When attempting to add the new host:

sw5K1(config)# radius host xx.xx.xx.xx key ########

Previous session start, abort or commit operation in progress

configuration for xx.xx.xx.xx could not be updated

Current config:

sw5K1(config)# show radius-server

retransmission count:1

timeout value:5

deadtime value:0

source interface:any available

total number of servers:1

following RADIUS servers are configured:

        uu.uu.uu.uu:

                available for authentication on port:1812

                available for accounting on port:1813

                RADIUS shared secret:********

For the life of me I dont know how to proceed.  I am logged in remotely via console with my domain (radius) account.  I thought I might be able to login locally via the console with a local u/p but it forces me to login via radius. 

Any ideas?

5 Replies 5

rwthorne
Level 1
Level 1

I had the same issue and discovered that it was because "TACACS  distribute" was enabled. Removed that and had no porblem updating servers.

As you already have a radius server on NX-OS so you first need to remove all the assosiated feature tied to the server group. It's would not be possible to update the config for a RADIUS server when there is an active AAA feature tied to the server group. Could you please paste the existing configuration of AAA on nexus here.

~BR
Jatin Katyal

**Do rate helpful posts**

~Jatin

Did you get a chance to look into the issue again?

~BR
Jatin Katyal

**Do rate helpful posts**

~Jatin

Its no longer an issue as that switch was repurposed.  But when I was troubleshooting this I ended up just configuring an incorrect radius key so it would fail on the first server and use the second one.  Not ideal but it worked. 

Good to know. thanks for sharing

~BR
Jatin Katyal

**Do rate helpful posts**

~Jatin