cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
963
Views
0
Helpful
2
Replies

RADIUS/TACACS+ not responding even on the same vlan

steven.pw.lau
Level 1
Level 1

Hi,

Have anyone encountered this problem before? My radius is at 192.168.1.10 and R1 is on 192.168.1.1. Both are connected to a switch and ping works perfect. ACS has been configured with R1 as the AAA client with a key. I'm baffled as to why this does not work. I've even changed the authentication to TACACS+ and still the same problem occurs.

R1#test aaa group radius cisco cisco legacy

Attempting authentication test to server-group radius using radius

No authoritative response from any server.

R1#ping 192.168.1.10

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 192.168.1.10, timeout is 2 seconds:

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/4 ms

2 Replies 2

steven.pw.lau
Level 1
Level 1

debug radius authentication shows

*Mar 21 09:31:26.919: RADIUS: User-Name [1] 7 "cisco"

*Mar 21 09:31:26.919: RADIUS: User-Password [2] 18 *

*Mar 21 09:31:31.687: RADIUS: Retransmit to (192.168.1.10:1645,1646) for id 1645/

4

*Mar 21 09:31:36.327: RADIUS: Retransmit to (192.168.1.10:1645,1646) for id 1645/

4

*Mar 21 09:31:41.095: RADIUS: Retransmit to (192.168.1.10:1645,1646) for id 1645/

4No authoritative response from any server.

Rack01R1#

*Mar 21 09:31:45.799: %RADIUS-4-RADIUS_DEAD: RADIUS server 192.168.1.10:1645,1646

is not responding.

*Mar 21 09:31:45.799: RADIUS: Tried all servers.

*Mar 21 09:31:45.799: RADIUS: No valid server found. Trying any viable server

*Mar 21 09:31:45.799: RADIUS: Tried all servers.

*Mar 21 09:31:45.799: RADIUS: No response from (192.168.1.10:1645,1646) for id 16

45/4

*Mar 21 09:31:45.799: RADIUS: No response from server

Rack01R1#

*Mar 21 09:31:45.803: %RADIUS-4-RADIUS_ALIVE: RADIUS server 192.168.1.10:1645,164

6 is being marked alive.

Tried changing the ports to 1812,1813 still the same. No Windows FW turned on in the ACS Server..

Latest update. Managed to solve the problem..

Resolution: Re-install Cisco ACS

But would definately welcome a better suggestion than the above for anyone who has experienced this problem before. Could it be Java related problem?