Showing results for 
Search instead for 
Did you mean: 
Cisco Community November 2020 Spotlight Award Winners

Unable to delete multiple AAA server entries with same IP address on Cisco Secure access control server, and database replication fails


Core issue

In this issue, after you upgrade Cisco Secure ACS, multiple Authentication, Authorization, Accounting (AAA) server entries for same IP address but different name appear under Network Configuration. This issue causes replication to fail. ACS does not allow to delete the entry or reset the keys.

For example:



Complete these steps in order to resolve this issue:

  1. In order to keep and delete the entry, choose Network Configuration > Proxy Distribution Table > (Default) and make sure that you have the [FQDN-name-of-server] entry in the Forward To column. All other entries should be in AAA Server.

  2. Return to the Network Configuration section, and click the [name-of-server] entry. Change the IP address of the [name-of-server] entry and then choose Submit + Apply. For both entries [name-of-server] and [FQDN-name-of-server], only these three options appear:

    • Submit

    • Submit + Apply

    • Cancel

  3. Now restart the CSAdmin service. Note that it cannot be restarted from System Configuration > Service Control > Restart. You must open Services.msc on the Microsoft Windows server where ACS is installed, and then restart the CSAdmin service.

  4. Once CSAdmin service is backed up, log into the ACS GUI page.

  5. Check the [name-of-server] entry in the Network Configuration section, The options to Delete and Delete + Apply now appears this time.

  6. Choose Delete + Apply.

  7. Complete these steps on the Primary and Secondary ACS server.

  8. Try the replication again and it should work now.

Features & Tasks

Authentication, Authorization, Accounting (AAA)

Database Replication

Content for Community-Ad