04-21-2011 03:55 PM - edited 03-11-2019 01:24 PM
Hello Folks
when i issue the command the sh aaa-server MYACS,I Noted the below msg for server status,how to troubleshoot and fix this issue?
Server Group: MYACS
Server Protocol: radius
Server Address: 192.168.100.100
Server port: 1645(authentication), 1646(accounting)
Server status: FAILED, Server disabled at
04-21-2011 06:26 PM
Hi,
PIX/ASA lost connectivity to radius server. Make sure network path is available and the ASA IP/name and node key correctly configured on Radius server.
You can test the server authentication from ASA using command - test aaa-server authentication
hth
MS
04-21-2011 06:30 PM
When the AAA server is in FAILED state, you can check to ensure that you have connectivity to the AAA server by trying to ping it.
Once confirm that connectivity between the ASA and the AAA server is up, you can re-activate the server with the following command:
aaa-server active host 192.168.100.100
If you check the status again:
show aaa-server MYACS host 192.168.100.100
it should say it's ACTIVE now.
Hope this helps.
04-22-2011 01:44 AM
Hi
i have 3 acs in the group MYACS,both r okay but the third one gave the failed status so when you use this command aaa-server active host 192.168.100.100 ,r u sure this dosnt affect the first acs(192.168.100.101) who is active and serve the vpn users
thanks
04-22-2011 07:52 AM
The default aaa-server reactivation mechanism is depletion. This means that failed servers only reactivate after all of the servers in the group are inactive. The command given to you will manually reactivate the sever, but it will not affect existing servers.
Command Reference link:
http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/a1.html#wp1558160
Thanks,
Brendan
04-22-2011 08:03 AM
With reference to postring about 3 servers in the group.. just a note , on ASA you do not need to add all the 3 servers if they are Master/replica. The master is enough and ASA will get all the info from the master and will look for replica/backup incase Master is not available.
Thx
MS
PS: I mentioned this as I added all the servers on my prod ASA and later realised that was not required. Everything works great with all the servers status 'OK'.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide