User Cannot Access Certain Features; Troubleshooting Radius And Tacacs+ With Cisco Acs - Cisco 9134 - MDS Multilayer Fabric Switch Troubleshooting Manual

Mds 9000 family
Hide thumbs Also See for 9134 - MDS Multilayer Fabric Switch:
Table of Contents

Advertisement

Chapter 17
Troubleshooting RADIUS and TACACS+
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m

User Cannot Access Certain Features

Symptom
Table 17-4
User Cannot Access Certain Features
Symptom
Possible Cause
User cannot access
User is assigned incorrect role.
certain features.
Role is not configured for appropriate
access.

Troubleshooting RADIUS and TACACS+ With Cisco ACS

To troubleshoot RADIUS and TACACS+ issues with Cisco ACS, follow these steps:
Choose Network Configuration using Cisco ACS and view the AAA Clients table to verify that the
Step 1
Cisco SAN-OS switch is configured as an AAA client on Cisco ACS.
Choose User Setup > User Data Configuration to verify that the user is configured.
Step 2
View the Cisco IOS/PIX RADIUS Attributes setting for a user. Verify that the user is assigned the correct
Step 3
roles in the AV-pairs. For example,
Note
Step 4
If the Cisco IOS/PIX RADIUS Attributes field is not present, follow these steps:
a.
b.
c.
Choose System Configuration > Logging to activate logs to look for reasons for failed authentication
Step 5
attempts.
Step 6
Choose Reports and Activity to view the resulting logs.
On the Cisco SAN-OS switch, use the show radius-server command to verify that the RADIUS server
Step 7
timeout value is set to 5 seconds or greater.
OL-9285-05
User cannot access certain features.
The Cisco IOS/PIX RADIUS Attributes field is case-sensitive. Verify that the role listed in the
AV-pair exists on the Cisco SAN-OS switch.
Choose Interface > RADIUS (Cisco IOS/PIX).
Check the User and Group check boxes for the cisco-av-pair option and click Submit.
Choose User Setup > User Data Configuration and add the AV-pair to assign the correct role to
each user.
Troubleshooting RADIUS and TACACS+ With Cisco ACS
Solution
For RADIUS, configure the vendor-specific attributes on
the server for the role using:
Cisco-AVPair = shell:roles=" rolename1 rolename2"
For TACACS+, configure the attribute/value pair on the
server for the role using:
roles=" rolename1 rolename2"
Verify that all roles are defined on the switch.
See
Chapter 18, "Troubleshooting Users and Roles."
shell:roles="network-admin"
Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x
.
.
.
17-11

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents