The problem indicates the primary ACS Server failed to respond to authentication request (radius).
The server might be up & running, and you even ping it without any problem. This has something to do with the radius (or tacacs+) services. Check the radius status from the ACS "Reports & Activity - ACS Service Monitoring", or from the server's event viewer.
Under the ACS Service monitoring, check the latest 'CSMonLog.csv' (or older file) for any CSRadius failed services.
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...