cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1296
Views
0
Helpful
3
Replies

Authentication fails on Standby ASA

ajay chauhan
Level 7
Level 7

Hi All,

I have 2 ASA box in failover mode auth on active work fine ..i do get ssh or telnet access for standby but that fails.

The floting IP is mentioned in ACS.

Any suggestions.

Thanks

Ajay

3 Replies 3

mirober2
Cisco Employee
Cisco Employee

Hi Ajay,

A couple of things you can try:

1. First make sure the AAA configuration was correctly replicated to the standby unit (check 'show run aaa' and 'show run aaa-server' to make sure the output matches on both units).
2. Try to ping the ACS server from the Standby unit. If this fails and ACS should reply to pings, troubleshoot the network to find out why communication is failing.
3. Run 'test aaa-server authentication ' on the Standby unit and check what the reason for the failure is.
4. Enable 'debug aaa authentication' on the Standby unit and watch the output when you try to authenticate.

Hope that helps.

-Mike

If the secondary IP Address isn't in ACS then ACS will not authentication the standby unit.

Treat the standby ASA as a regular device when it comes to this since the source address will be the standby IP not the Floating IP.

thanks TJ IT Worked for me......

Review Cisco Networking for a $25 gift card