Cisco AAA/Identity/Nac :: ACS 4.2 / 2851 / There Is Authentication Failure With Error No 254

Nov 22, 2011

we have ACS 4.2 and 2851 router with IOS 15.0(1)M4. There is authentication failure with error no 254. Is there any compatibilty issue with 15.0(1)M4 IOS

View 1 Replies


ADVERTISEMENT

AAA/Identity/Nac :: ACS 5.2 AD Authentication Restriction Failure?

Aug 24, 2011

I've my ACS linked with AD to give administration access to few network devices and I've created an access policy to link my AD groups with those network devices and command sets.
 
Unfortunately I found I can use any user from my AD to login to my devices. Only LOGIN, the authorization definition is restricting the command set for those users.
 
How can I restrict the LOGIN to an specific AD group?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: 13017 Way To Configure Email Notification For Specific Authentication Failure

May 14, 2011

Is there a way to configure an email notification for a specific authentication failure?  Specifically, I'd like to see if I can have an email notifcation sent to me when failure reason is "13017 Received TACACS+ packet from unknown Network Device or AAA Client".

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Authentication Error In ACS 5.3

Sep 7, 2012

I configured ACS 5.3 and added AAA clients with TACACS+ server and shared secret key as cisco123. i did the below config on switch also. when i try to authenticate login with ACS it does not respond. Find the configuration and debug output.nd
 
In debug output it gives ruser and rem_addr is null. i did not understand why .
 
I am able to ping to ACS server and i used telnet 192.x.x.10 49 and it gives the proper output.
 
aaa new-model
aaa authentication login default group tacacs+ local
!
tacacs-server host 192.168.60.10 key cisco123
tacacs-server directed-request
ip tacacs source-interface Vlan172

View 2 Replies View Related

AAA/Identity/Nac :: 1841 Giving Error In Authentication

May 15, 2013

I have an 1841 that was working fine - I could SSH to it with my Radius login and console into it with local credentials ("Fred").I added another use ("Mike") with priv 15 so the end user could log in locally via console if needed.After that, we can both log in via console, but when we try to enter privileged mode we get "% Error in Authentication", before even entering the   password.I can still log in via Radius SSH with no problems and access privilege mode via SSH.What am I missing so we can have two different users be able to log in locally with different credentials and access privileged mode, and keep my ssh radius working?

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.2.0 Error In ACS Authentication For Accessing Devices

Jun 11, 2012

We are using acs version 4.2.0 build 124 on windows server 2003. Our domain controller has been upgraded from 2003 to windows 2008 R2.Now we are facing following error in ACS authentication for accessing our devices.Error: AUTH  06/09/2012 11:55:40 E 1810 3316 0x8f21 External DB [NTAuthenDLL.dll]: Windows  authentication FAILED (error 1326L)if we restarted services of ACS server then users get authentiated fine.

View 1 Replies View Related

Cisco AAA / Identity / Nac :: 1310 Bridges - FreeRadius Authentication Error

Mar 2, 2011

I have two 1310 bridges. one configured as root and the other as non-root. Authentication Settings: Open with EAP and Network EAP with no addition. Set up: when non-root bridge tries to associate with root bridge, root bridge checks with radius server if it's ok to associate with the non-root bridge.
 
I can see communication with the radius server (I'm using FreeRadius) and the radius server even sends a SUCCESS back to the root bridge. However I'm seeing this error on the non-root bridge: DOT1X_SHIM-3-PLUMB_KEY_ERR: Unable to plumb keys - Eap key struct is NULL and the bridges do not authenticate.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: 5508 - NGS Guest Server Authentication Error

Apr 29, 2011

I installed NGS 2.0.2 for wireless guest user management and authentication. I implement webauth via webauth page on wlc deployed.One Branch with a WLC5508 version 7.0 wireless anchor controller is working on the NGS.But now I integrate next branch with WLC4402 version 6.0.188 and the authentication of users at the new branch gets an error, wrong user/password.
 
I double checked configuration and user/password but I can't find any configuration error. Also stopping and starting of radius service and reboot of NGS still does not work. I tried to debug the radius via web interface and watched for the loggfile and there is still a reject.I also tried the freeradius command radiusd -X but I got an error when starting the radiusd -X.
 
1.) How can I figure out, if I will get the correct password from my WLC ? Are there any debug options to see more ? e.g. some cli commands, radiustest utilities or how to get the received password from the chap challenge of the debug ?
 
2.) I have appended a part from my radius loggfile. How can I find the detailed error in the radius log file? Is it correct that the password in the debug file is empty ? raiuds logg line "[radius-user-auth] expand: %{User-Password} -> "

View 3 Replies View Related

Cisco WAN :: 2851 - Nat Ls Giving Error

Apr 24, 2013

Up to today I used Verizoon 4G to a Windows Visata box running Internet connection Sharing to get my home lab connected to the Internet .  All was working well.
 
Today I had Hughesnet come and installl their service and I can no longer get access to the Internet from my PC netowrk.  my VPN to my office for my IP phone coomes up an works just fine.  At the router I do have Internet access which then leads me to believe that my problem is NAT related.
 
My router is a 2851. 
 
When I enter PING 4.2.2.2 I get !!!!! but when i enter PING 4.2.2.2 SOURCE 192.168.69.3 I get .....
 
Here is my config info:
 
crypto isakmp policy 1
encr 3des
hash md5(code)

View 1 Replies View Related

Cisco VPN :: 2851 Death By Retransmission P1 Error?

Feb 2, 2011

I am having issues bringing up a tunnel between a cisco 861 router and Cisco 2851 router.  Tunnel has been dropping every week atleast once or twice.  Usually router reboot fixes it but today it is just not coming back up. have updatee remote, reloaded the config still no use.  It seems like it is partially coming up but I see the following two messages on the main router:
 
1- Death by retransmission P1

2- 11:03:03.789: %CRYPTO-6-IKMP_NOT_ENCRYPTED: IKE packet from 12.234.109.169  was not encrypted and it should've been
 
I have checked the config on both routers it is the same as the VPN was up and we didn't make any changes on either of the two routers.

View 4 Replies View Related

Cisco WAN :: 2851 Router Hanging Error Message

Mar 5, 2011

i have 2851 router and it is hanging when i login on it while it is hanging it gives me the following error message: [code]

View 2 Replies View Related

Cisco WAN :: 2851 Router Showing Error For Peer Set Configuration

May 28, 2012

We have Cisco 2851 Router part code  CISCO2851-SEC/K9 facing issue while set peer configuration, issue description  below.
 
Issue:We are facing the problem while configuring set peer as when we try to this we face error like 'unable to set peer.maximum numbwe of peer (40)exceeded'
 
We suspected the IOS issue hence we have gone for IOS upgrade for this Router but this error is still coming while configuring set peer.
 
Previous IOS: c2800nm-advsecurityk9-mz.124-15.T7.bin New IOS:c2800nm-advsecurityk9-mz.124-24.T7.bin
 
We are attaching here the snap shot of error that is coming while configuring the Router with set peer command along with show tech of the Router to understand this case brief.

View 1 Replies View Related

Cisco Switching/Routing :: 2851 / 6506 - Error Messages

Dec 26, 2010

I had these error messages on both my Cisco 2851 and on my Cisco Catalyst 6506.
 
On Cisco 2851:
%SYS-SP-3-CPUHOG: Task is running for (2000)msecs, more than (2000)msecs (4/4),process = SEA write CF process. [code]...
 
And on 6506:
Dec 27 15:20:55 MET: %SYS-SP-3-CPUHOG: Task is running for (2000)msecs, more than (2000)msecs (129/129),process = SEA write CF process.[ code]...
 
I have these IOS versions on my Cisco:
Cisco 2851: 15.0(1)M4
Cisco 6506: 12.2(33)SXI

View 3 Replies View Related

Cisco :: VRRP Authentication Failure

Jan 1, 2013

I have a following question. I configured different authentication passwords in Master and slave VRRP setup.

View 2 Replies View Related

Cisco Application :: ANM 5.2 Authentication Failure

Apr 15, 2013

I'm using the Cisco ANM 5.2 version and I'm trying to import the configurations from ACE modules of Cisco switches. The first step is to import the configuration from Cisco switch and the second one is to import the ACE module in the ANM software. I'm getting an authentication problem to import the configuration from Cisco switch and of course I cannot import the ACE as well. The switches and the ACE are using AAA authentication and I have created a specific username to authenticate and import the configurations in the ANM. If I remove the AAA configurations from the switches and ACE modules it works fine.
 
Is there some problem with the AAA configurations in the switches or ACE module?

View 7 Replies View Related

Cisco :: SSH Authentication Failure CiscoWorks LMS 4.0

Oct 24, 2012

I am trying to get CiscoWorks LMS 4.0 to connect to my routers in order to back up configurations, but I am getting SSH authentication failures reported in the router logs (and archiving fails).
 
The credentials LMS is using is a username and password with priviledge 15: the account is established in TACACS+. I can log into the devices directly with this user account.However, I cannot TFTP from the routers to the LMS either (I get a permission denied message in the router).
 
LMS did manage to fetch some configs, but 90% of my devices are having this issue.

View 4 Replies View Related

Cisco Wireless :: AAA Authentication Failure On WLC 4402?

Jun 13, 2012

Error: AAA Authentication Failure for UserName:radiususername User Type: WLAN USER
 
I am using a window radius server. I have added my WLC 4402 as a radius client on my radius server.
 
I followed the instructions on the MS link : [URL]
 
I want to use my windows raduis authentication for WLC management login and Web-Auth for guest WLAN user login.

View 2 Replies View Related

Cisco VPN :: 5510 Anyconnect SSL VPN Authentication Failure

Dec 26, 2012

I have configured an Asa 5510 as SSL vpn gataway ver 8.2(4) Anyconnect Essential. The clients are authenticated via Radius and OTP password.All work well since yesterday. When I have did same configuration changes. My objective was has that the clients accept the self signed certificate issued by the Asa whitout give the warning about the private cert.
 
So I have try to generaste a new certificate with FQDN equal to myasa.mydomain.com and also a CN=myasa
 
Then I have change the profile XML file of my anyconnect in this way: [code]

View 1 Replies View Related

Cisco Wireless :: 5508 - AAA Authentication Failure

Aug 3, 2011

I've set up several local network users (Security > Local Net Users) on the WLC (5508 running 7.0.98.0). Whenever I try to connect with one of these user accounts (I'm testing this out for now), the attempt is unsuccessful and I see an "AAA Authentication Failure for UserName: xxxxxxx User Type: WLAN USER" in the Trap Log. I thought that after trying to authenticate through a RADIUS server, the local user database would be polled and then a user account in that database would be able to authenticate.

View 1 Replies View Related

Cisco Routers :: PEAP Authentication Failure With RV120W

Jul 31, 2012

I have a Cisco Small bussiness RV120w and I setup the radius server , WPA2 Enterprise with a windows 2008 NPS radius server . The big problem is that the authentication fails .This is the error that I see in event viewer / server roles / Network policy and access services: reason-code 49 "The connection attempt did not match any connection request policy".The radius key is matching between the server and the client . The radius server is reachable and I don't find any routing issues .Does anybody tested this router with this type of wireless security?

View 3 Replies View Related

Cisco Wireless :: 5508 WLC Excessive Client Authentication Association Failure

Jan 29, 2013

I have been noticing in my trap logs that there are an excessive amount of Client Association/Authentication Failures. I cannot figure out why. I have a Cisco 5508 WLC with 81 AP's (1131ag, 1142abgn, 1262N) models. The wireless devices are on a Windows Domain and use 802.1x EAP authentication, authenticating the user and computer info with a RADIUS Server. I look at the logs and all it can tell me is Reason:Unspecified ReasonCode:1. I read that the Reason Code is due to "Client associated but no longer authorized" but to be honest I am not sure what that means.

View 9 Replies View Related

Cisco :: ACS 4.2.1 - Alteon 3408 L4 Switch Authentication Failure By RADIUS Protocol?

Jul 25, 2012

I have a question about ACS RADIUS authentication with Alteon 3408 L4 Switch.
 
I configured a ACS 4.2.1(build 15 patch 4) software for windows on Windows Server 2008 Server STD.TACACS authentication with CISCO product was successfully passed.but RADIUS (IETF) authentication with NORTEL 3408 Switch was failed. ACS Authentication Failure Code was a " ACS password invalid "
 
I read the post that RADIUS VSA is needed in my environment.but i can not search any sample Nortel VSA dictionary configuration. Need Notel specific VSA configuration.

View 4 Replies View Related

Linksys Wireless Router :: E4200v2 - Bizarre WPA2 Authentication Failure

May 3, 2012

Just installed 2 E4200v2's for a customer today.  Was very optimistic because they worked great in my lab, both for my Win7 laptop  a MacBook.  And after installing 1 on-site and testing w/ my laptop, it worked fine.BUT problems arose when I installed both at the same time (I don't think I ever did this in the lab) and then I tested some computers.  Every computer that I tested (except mine of course), cannot authenticate correctly using the WPA2 password.
 
For the Mac's they get the error "The wi-fi network... requires a WPA2 password" then after entering the *correct* pswd, it says "Invalid password".  They're a Mac shop, but I did try one other Win laptop and that also had a problem, and the error was something like "security mismatch" although I was rushed and didn't write it down.

View 2 Replies View Related

Cannot Access PC In LAN - Get Error Message Logon Failure?

Jan 22, 2013

I have three PCs in my lan. (A, B & C).I can access shared drives of B & C from A

I can access shared drive of A from C but cannot access B from C

I can access shared drive of C from A & B.

I get error message "Logon failure: the user has not been granted the requested logon type at this computer".

All the systems are Win 7, A & B are desktop and C is a laptop.I added the C's name in A's "Security Settings -> Local Policies -> User Rights Assignment -> Access this Computer from the Network" too. Still can't access.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: 802.1x Credentials Failure With ACS 5.2

Jun 20, 2011

I recently tried to deploy an ACS appliance with version 5.2 installed on it for a customer.
 
After setting up the WLC to use the ACS as a radius server, and successfully testing connection from the ACS to the AD, I get an error message " 12321 PEAP failed SSL/TLS handshake because the client rejected the ACS local-certificate" anytime a client tries to connect to the network.
 
This is surprising because I had already generated a certficate for the ACS from a CA and binded the CA signed certificate with the ACS, I also specified the CA in the client machine's wireless properties and checked the "validate certificate" button.
 
When I tried to connect using the internal identity store, the client was successfully authenticated without any certificate issues.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS V5.3 Identity Selection For Authentication?

Jan 16, 2012

I configured before ACS v4.2 to authenticate network devices using internal users at first, and if the user is not found use AD list users.  But with v5.3 I have some problems doing this, on identity policies I use rule based result selection option, I configured 2 polices for Identity source, one for Internal Users and other policy for AD user, but it only works with the first policy, internal users or AD, but works only for the first policy identity.  how to do that, if the user is not found on first policy, continue to the next policy.

View 7 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Identity Base Authentication

Jul 3, 2011

I need a specify users to allow access to particular devices and give privilege only for show command or show run. Here is how I tried to configured.
 
1. Configured two seperate Shell Profile and Command set with privilege level 4-5 and allowing only show run command

2. create seperate service selection rule with adding the require NDG and protocol TACACS and maching service "RestrictAccess"

3. In the RestrictAccess Service I have following configured; Identity: internal users, Group Mapping to a particular group where the user exists, authorization: matching the above created identity group, NDG, shell profile, command sets
 
All the steps are attached in the .doc file. However when I tried with the particular user he is able to access everything and he is not hitting the correct access rule.

View 6 Replies View Related

Cisco VPN :: ASA 5505 To 5510 Error / Connection Denied Due To NAT Reverse Path Failure

Apr 28, 2011

Connection denied due to NAT reverse path failure

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Error - 22056 Subject Not Found In Applicable Identity

Oct 6, 2012

I have two ACS v 5.2 (primary and secundary) and some users are in the internal stor and the others are in the AD.The local site topology is like this:
 
PC - AP - WLC - ACS - AD
 
Authentication method is PEAP(EAP-MSCHAPv2) and all user have the certificate company installed. The OS in the client users is Windows 7.Users was working fine but some users reports intranet disconnections. I see in the ACS log  many "22056 Subject not found in the applicable identity store(s)." and "24415 User authentication against Active Directory failed since user's account is locked out" alarms.I believed it was because user wasn´t in the AD data base, but some times the same user is authenticated successfull and other i see the "22056...." or "24415...." alarms.
 
I switched the role for ACS primary to works as secundary and we see the same alarms.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: Active Directory And ACS 5.3 Failure?

May 21, 2012

I am receiving a RADIUS authentication failure stating user must change password; however, password has been changed in AD and is not requiring change password any longer on the AD side.
 
Is there a cache on the ACS that needs to be cleared? AD connection from ACS to domain is fine.  All other accounts authenticate.
 
It appears that if a user lets their account expire is when this happens.  Account has been reenabled in AD and password has been changed.  Still will not authenticate via ACS.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.2 Simulate AD Failure - Cannot Login

Feb 2, 2012

We have an ACS 4.2 installation and we have users configured on the user setup, they authenicate using the windows database (AD). We ran failure tests and simulated AD failure but disabling the firewall rule. So the ACS server is up, AD is down. Tested user login to a switch and get the following error. External DB user invalid. It looks like as the ACS does not get a response from AD it rejects the user login.
 
What we want it to do is in the event of AD failure is to be able to login to the switch with the username configured on the switch. (as if ACS server does not respond)
 
Date Time Message-Type User-Name Group-Name Caller-ID Network  Access Profile Name Authen-Failure-Code Author-Failure-Code Author-Data NAS-Port NAS-IP-Address Filter  Information PEAP/EAP-FAST-Clear-Name EAP  Type EAP  Type Name Reason Access  Device Network  Device Group 02/03/201214:09:13Authen failedtest.testNetwork192.168.1.1(Default)External DB user invalid or bad password....tty310.0.0.1..........SWITCH30Office

View 3 Replies View Related

Cisco AAA/Identity/Nac :: Failure To Apply Patch To ACS 5.0.3

Jun 12, 2012

I am trying to apply pach 5 to my ACS version 5.3 using FTP but i receive the following errors after issuing the show backup history command. When i use TFTP, i get a message saying that the file is too big, which i understand 164 MB.
 
after issuing the show repository "repository name", i get the following error.% Error reading directory on remote server.the patch is on one of my hard drives D, how do i specify on the ACS file path which drive to use?I can only place a url but without specifying which drive.

View 3 Replies View Related

AAA/Identity/Nac :: ASC SE 1113 Boot Failure?

Sep 14, 2011

i'm trying to re-image an asc se 1113 with a recovery cd but i keep getting a disk error complaining of an invalid destination drive

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved