RADIUS/TACACS+ not responding even on the same vlan

Unanswered Question
Mar 21st, 2008

Hi,

Have anyone encountered this problem before? My radius is at 192.168.1.10 and R1 is on 192.168.1.1. Both are connected to a switch and ping works perfect. ACS has been configured with R1 as the AAA client with a key. I'm baffled as to why this does not work. I've even changed the authentication to TACACS+ and still the same problem occurs.

R1#test aaa group radius cisco cisco legacy

Attempting authentication test to server-group radius using radius

No authoritative response from any server.

R1#ping 192.168.1.10

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 192.168.1.10, timeout is 2 seconds:

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/4 ms

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
steven.pw.lau Fri, 03/21/2008 - 02:32

debug radius authentication shows

*Mar 21 09:31:26.919: RADIUS: User-Name [1] 7 "cisco"

*Mar 21 09:31:26.919: RADIUS: User-Password [2] 18 *

*Mar 21 09:31:31.687: RADIUS: Retransmit to (192.168.1.10:1645,1646) for id 1645/

4

*Mar 21 09:31:36.327: RADIUS: Retransmit to (192.168.1.10:1645,1646) for id 1645/

4

*Mar 21 09:31:41.095: RADIUS: Retransmit to (192.168.1.10:1645,1646) for id 1645/

4No authoritative response from any server.

Rack01R1#

*Mar 21 09:31:45.799: %RADIUS-4-RADIUS_DEAD: RADIUS server 192.168.1.10:1645,1646

is not responding.

*Mar 21 09:31:45.799: RADIUS: Tried all servers.

*Mar 21 09:31:45.799: RADIUS: No valid server found. Trying any viable server

*Mar 21 09:31:45.799: RADIUS: Tried all servers.

*Mar 21 09:31:45.799: RADIUS: No response from (192.168.1.10:1645,1646) for id 16

45/4

*Mar 21 09:31:45.799: RADIUS: No response from server

Rack01R1#

*Mar 21 09:31:45.803: %RADIUS-4-RADIUS_ALIVE: RADIUS server 192.168.1.10:1645,164

6 is being marked alive.

Tried changing the ports to 1812,1813 still the same. No Windows FW turned on in the ACS Server..

steven.pw.lau Fri, 03/21/2008 - 08:43

Latest update. Managed to solve the problem..

Resolution: Re-install Cisco ACS

But would definately welcome a better suggestion than the above for anyone who has experienced this problem before. Could it be Java related problem?

Actions

This Discussion