cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1913
Views
0
Helpful
5
Replies

ACS 4.2 doesn't response RADIUS access-request

Brian.Burgett
Level 1
Level 1

I have configured radius 4,2:

- Create an internal database, a account

- Create an AAA client, with pass the same on Authenticator server

- Authenticate using Radius-Aironet (and try with other radius vendor)

- Submit and Apply

From Authenticator ( Ruckus Zone-director 1000)


- Configure the same secret pass with ACS

- IP: ACS, Port: 1812

- Send user name and pass which created on ACS server

From authenticator, send raidius access-request with username & pass have created on ACS, but ACS doesn't response any message even fail ..

Could you please help me figure out the happening problem

Thank a lot

-Brian.

5 Replies 5

dancampb
Level 7
Level 7

From the failed attempts log it says unknown NAS.  This means that the communication between the AP and ACS isn't working correctly.  This could be that the AP doesn't have the right shared secret key, the AP isn't defined in Network Devices, or one of the configs.  Do you have this device in a Network Group on the ACS server?  If so make sure you have the group shared secret key defined on the AP.

I have double checked all shared secret key and make sure they was right

They was also added to ACS network group as well

The problem is still happening

Brian,


I would also like you to check following,

Please go to Network Configuration > If we have Network Device Group option enabled, then go the network device group---Edit properties---remove the shared secret from there---submit the changes.

And try again, If authentication works, that would mean that we have configured a Network Device Group level key. And a NDG level key over rides the AAA

Client level key.

http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1/user/NetCfg.html#wp342699


Are we seeing "unknown NAS" with the same NAS ip address the one we have added on the ACS under network configuration?



Regds,

JK


Do rate helpful posts-

~Jatin

sorry for late response

i have changed as your suggestion, but nothing differences ?

Do you have other suggestion

thank you

Brain,

Unknown NAS shows up when ACS do not have aaa-client listed with required protocol ie tacacs or radius. Make sure that IP we see in failed logs is there in NDG or aaa-client.

That should fix it.

Regards,

~JG

Do rate helpful posts

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: