Cisco 9134 - MDS Multilayer Fabric Switch Troubleshooting Manual page 333

Mds 9000 family
Hide thumbs Also See for 9134 - MDS Multilayer Fabric Switch:
Table of Contents

Advertisement

Chapter 17
Troubleshooting RADIUS and TACACS+
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
Symptom
Table 17-1
Switch Does Not Communicate with AAA Server
Symptom
Possible Cause
Switch does not
Incorrect authentication or accounting
communicate with
port configured.
AAA server.
Incorrect preshared key configured.
AAA server monitor deadtime set to
high.
Timeout value too low.
OL-9285-05
Switch does not communicate with AAA server.
Solution
Reconfigure the authentication or accounting ports to
match those configured on the AAA server.
For RADIUS servers, see the
Configuration Using Fabric Manager" section on
page 17-4
or the
"Verifying RADIUS Configuration Using
the CLI" section on page
17-4.
For TACACS+ servers, see the
Configuration Using Fabric Manager" section on
page 17-5
or the
"Verifying TACACS+ Configuration
Using the CLI" section on page
Reconfigure the same preshared key on the switch and the
AAA server.
For RADIUS servers, see the
Configuration Using Fabric Manager" section on
page 17-4
or the
"Verifying RADIUS Configuration Using
the CLI" section on page
17-4.
For TACACS+ servers, see the
Configuration Using Fabric Manager" section on
page 17-5
or the
"Verifying TACACS+ Configuration
Using the CLI" section on page
Set the deadtime lower to bring AAA servers active more
quickly.
For RADIUS servers, see the
Monitor Configuration Using Fabric Manager" section on
page 17-6
or the
"Verifying RADIUS Server Monitor
Configuration Using the CLI" section on page
For TACACS+ servers, see the
Server Monitor Configuration Using Fabric Manager"
section on page 17-7
or the
Monitor Configuration Using the CLI" section on
page
17-7.
Change server timeout value to ten seconds or higher.
For RADIUS servers, see the
Monitor Configuration Using Fabric Manager" section on
page 17-6
or the
"Verifying RADIUS Server Monitor
Configuration Using the CLI" section on page
For TACACS+ servers, see the
Server Monitor Configuration Using Fabric Manager"
section on page 17-7
or the
Monitor Configuration Using the CLI" section on
page
17-7.
Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x
AAA Issues
"Verifying RADIUS
"Verifying TACACS+
17-5.
"Verifying RADIUS
"Verifying TACACS+
17-5.
"Verifying RADIUS Server
17-6.
"Verifying TACACS+
"Verifying TACACS+ Server
"Verifying RADIUS Server
17-6.
"Verifying TACACS+
"Verifying TACACS+ Server
17-3

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents