Core issue
Protected Extensible Authentication Protocol (PEAP) authentication with CiscoSecure ACS version 3.3 for Windows, which uses an external Rivest, Shamir, and Adelman (RSA) database, temporarily fails at random intervals. Authentications resume, typically after 10 to 15 minutes, without any intervention. The authentication failure appears to rectify itself. No action is required.
During the authentication failure, the RDS log can display these errors:
- CSAuth client has lost connection to server
- No NAS response sent
The Failed Attempts log on the ACS can show this error:
External DB account Restriction
This issue occurs with CiscoSecure ACS for Windows versions 3.3(1.16) and 3.3(2.2). Cisco bug ID CSCeg51847 documents this issue. This issue does not occur on Cisco Secure ACS for Windows version 3.3.2.
Resolution
This bug is fixed in CiscoSecure ACS for Windows version 4.0(1.27). In order to download CiscoSecure ACS for Windows version 4.0(1.27), open a service request with the Cisco Technical Support.