cancel
Showing results for 
Search instead for 
Did you mean: 

Cisco ACS for RADIUS Auth to SA-700

SOLVED
DougR_
Contributor

Cisco ACS for RADIUS Auth to SA-700

Does any one have experience with Cisco ACS handeling RADIUS auth?

We are seeing the Cisco ACS reuturn an Auth-OK, but the SA still marks it as failed Auth. It works fine with the SBR or other Auth methods.

1 ACCEPTED SOLUTION

Accepted Solutions
DougR_
Contributor

Re: Cisco ACS for RADIUS Auth to SA-700

The problem seems to be with the configuration of the Cisco ACS. When the device is removed from groups the Auth works well. Another reason to use the SBR Smiley Tongue

View solution in original post

4 REPLIES 4
DougR_
Contributor

Re: Cisco ACS for RADIUS Auth to SA-700

In digging through this I want to see the Debug Logging - the log is not in ASCII, what can be used to view the Debug Log from the SA?
DougR_
Contributor

Re: Cisco ACS for RADIUS Auth to SA-700

The only difference I can find in the two Access-Accept responses is the Attribute Value Pairs returned. The SBR only returns session-timeout(27) the Cisco ACS always returns a long Class(25) value along with any other values we set. Is it possible the IVE has a problem with certain vlaues for a class, maybe too large of a value or a format?

DougR_
Contributor

Re: Cisco ACS for RADIUS Auth to SA-700

The problem seems to be with the configuration of the Cisco ACS. When the device is removed from groups the Auth works well. Another reason to use the SBR Smiley Tongue
michael.saw_
Regular Contributor

Re: Cisco ACS for RADIUS Auth to SA-700

Is there a solution for MAG with ACS?

Is there a kb link to share?