cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
277
Views
0
Helpful
3
Replies

AS5350 failing ppp authentication through secondary ACS server.

cbjohn
Level 1
Level 1

We have three AS5350 access servers using two Cisco ACS servers for RADIUS authentication. When I attempt to failover to the secondary ACS server the access server starts to experience "ppp authentication" failures. Has anyone seen this problem befoe? If so, what is a way to get it to work?

3 Replies 3

tepatel
Cisco Employee
Cisco Employee

Pl. make sure that the database of those two RADIUS servers are in sync with eachother..Try to use the individual RADIUS server to make sure that the authentication works ok before deploying in the failover mode..

I've verified that the secondary server works by making it the primary Access server and it works fine. The databases are identical as well database syncronization between the two ACS servers happens each morning at 6AM.

Need to know "how do you attempt to do failover" On the router or simply taking primary radius server down..Lets have following debug from router when you do failover

debug ppp nego

debug aaa authentication

debug radius

debug aaa authorization

Along with "sh run" from the router..The above detail will paint the clear picture about whats going on there...Tejal

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Innovations in Cisco Full Stack Observability - A new webinar from Cisco