Troubleshooting Network Configurations


Probably the most common configuration problem we have ever seen in ACS for initial communications between an AAA client and ACS is the configuration of the shared secret key. The following items might help in troubleshooting problems with the shared secret key:

  • Ensure that the shared secret key on the AAA client matches the shared secret key that is configured on the ACS.

  • The shared secret key is case sensitive. Ensure that the case of the shared secret key is the same both on the ACS and the AAA client.

  • Make sure that the AAA client has been defined in the ACS. If it is not, all packets from it are discarded by the ACS.

  • If the AAA client is in a group of clients defined on the server and you are using an IP range rather than individual IP addresses, ensure that the IP address of the AAA client is within the range defined on the ACS.

  • Ensure that the protocol used to communicate, TACACS+ or RADIUS, is the same on both the ACS and the AAA client.

  • If you have verified the items in the preceding bullets and you are still experiencing communication failures, ensure that the AAA client has basic connectivity to the ACS via ping.

  • Ensure that no firewall policy is blocking communications between the ACS and the AAA client.

  • If communications are not reliable, ensure that the "Single TCP session" option is not selected.

  • Use the reports in ACS. Although they have not been discussed yet, you could use the Passed and Failed Attempts reports in the ACS interface. These are discussed in Chapter 12, "Reports and Logging for Windows Server."

If you have verified everything in the preceding list and you are still having problems, you might want to check the Cisco Network Professionals Connection on CCO, or open a Cisco TAC case at Cisco.com.




Cisco Access Control Security(c) AAA Administrative Services
Cisco Access Control Security: AAA Administration Services
ISBN: 1587051249
EAN: 2147483647
Year: 2006
Pages: 173

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net