ACS and "bad argument key.

Today our ACS (ver 4.1 on windows 2003 server) suddenly stopped working. We use it to authenticate and authorize the main access to the switches via Ganymede. I see "bad argument key" errors in ACS, but the shared secret is the same on both sides (switch vs ACS), so it's not a problem.

A "debug" on a switch Ganymede says:

January 7, 21:32: Telnet2: 1 1 251 1

January 7, 21:32: TCP2: Telnet sent WILL ECHO (1)

January 7, 21:32: Telnet2: 2 2 251 3

January 7, 21:32: TCP2: Telnet sent WILL SUPPRESS-GA (3)

January 7, 21:32: Telnet2: 80000 80000 253 24

January 7, 21:32: TCP2: Telnet sent TO TTY-TYPE (24)

January 7, 21:32: Telnet2: 10000000 10000000 253 31

January 7, 21:32: TCP2: Telnet sent MAKE the SIZE of the WINDOW (31)

January 7, 21:32: TAC +: send worm package AUTHENTIC/START = 192 id = 3650164881

January 7, 21:32: TAC +: using Ganymede server-group "Ganymede +" list by default.

January 7, 21:32: TAC +: 10.1.2.2 (3650164881) AUTHENTIC/START/CONNECTION/ASCII queued

January 7, 21:32:05: TAC +: 10.1.2.2 (3650164881) AUTHENTIC/START/CONNECTION/ASCII - TIMED OUT

January 7, 21:32:05: TAC +: (3650164881) AUTHENTIC/START/CONNECTION/ASCII processed

January 7, 21:32:05: TAC +: using Ganymede server-group "Ganymede +" list by default.

January 7, 21:32:05: TAC +: 10.10.10.1 (3650164881) AUTHENTIC/START/CONNECTION/ASCII queued

January 7, 21:32:10: TAC +: 10.10.10.1 (3650164881) AUTHENTIC/START/CONNECTION/ASCII - TIMED OUT

January 7, 21:32:10: TAC +: (3650164881) AUTHENTIC/START/CONNECTION/ASCII processed

January 7, 21:32:10: TAC +: using Ganymede server-group "Ganymede +" list by default.

(etc.)

There are two servers, ACS, they sync and they both have the same problem.

Accessibility is not the problem.

What should I check for?

Erik

Mohamed

Since it is a new show you could get more and delivers better answers if you start a new thread rather than adding what may appear as most comments on a continuous.

However, since you asked the question here, I have a comment and a suggestion. This production line:

QA: TAC +: invalid package AUTHENTIC/START/CONNECTION/ASCII (control keys).

suggests that something (probably the shared key for authentication of the device) is not properly synchronized between your device and the RADIUS server.

My suggestion would be to search for in the report of attempts failed on the RADIUS server and see if you see the authentication attempt of this unit. If that is what the GANYMEDE server say about the cause of the failure?

HTH

Rick

Tags: Cisco Security

Similar Questions

  • When I try to automate - fusion photo I get this error - which freezes my Mac and I have to force leave to use anything - 19 error: bad argument: invalid resource format. Error on line 0, the character offset 560, in ' {alignChildren: 'fill', text: ' $$$

    Error 19: Bad argument: invalid resource format. Error on line 0, the character offset 560, in ' {}alignChildren: 'fill', text: ' $$$ / AdobePlugin/Shared/Photomerge/process/Name = Photomerge', orientation: 'row', alignment: "fill."View1: Panel{"text: ' $$$ / AdobePlugin/Shared/Photomerge/Scr/layout = layout", direction: "column", alignment: ["fill", "fill"],View2: Group{orientation: "column", alignment: "fill."_LOauto: RadioButton {text: ' $$$ / AdobePlugin/shine/Photomerge/Scr/Auto = Auto ", alignment: 'left'"},view4: Image {image: "/Applications/Adobe%20Photoshop%20CS6/Presets/Scripts/Stack%20Scripts%20Only/P_AutoAlign _Automatic_87x38.png"}},view5: Group{orientation: "column", alignment: "fill."_LOperspective: RadioButton {text: ' $$$ / AdobePlugin/Shared/Photomerge/Scr/Perspective = Perspective', alignment: 'left'},Vision7: Image {image: "/Applications/Adobe%20Photoshop%20CS6/Presets/Scripts/Stack%20Scripts%20Only/P_AutoAlign _Perspective_87x38.png"}},view8: Group{orientation: "column", alignment: "fill."_LOcylindrical: RadioButton {text: ' $$$ / AdobePlugin/Shared/Photomerge/Scr/cylindrical cylindrical = ', alignment: 'left'},view10: Image {image: "/Applications/Adobe%20Photoshop%20CS6/Presets/Scripts/Stack%20Scripts%20Only/P_AutoAlign _Cylindrical_87x38.png"}},view11: Group{orientation: "column", alignment: "fill."_LOspherical: RadioButton {text: ' $$$ / AdobePlugin/Shared/Photomerge/Scr/spherical ball = ", alignment: 'left'"},view13: Image {image: ' /}

    Hi Donald,.

    Sorry for the inconvenience.

    This happens usually when the script does not have enough permissions to manage this.

    Please make sure that this folder applications, and two libraries have full read and write.

    Also if it happens again, please tell me if you use Bridge for example or directly with Photoshop.

    Thank you

    Jitendra

  • Satellite M40X-286: energy saving and the E - key utility does not work on Vista

    First of all, sorry for my bad English.

    I managed to install Windows Vista Ultimate 32-bit on my Satellite M40X-286. Everything works, except for the energy saving and the E - key utility. I tried the added value of packages of other TOSHIBA models, but they all give an error message during the installation. Is there a solution for this problem?

    Now I can't change the speed of the processor and the brightness of my screen, and I can't even adjust these settings in a power mode. The only way to change the brightness is manually using the FN + F6 and F7 keys.

    Kind regards
    Stijn.

    Please don t be crazy about me, but there is no problem at all. The situation is quite clear.

    First: tools and utilities are similar, but in most cases have to be adapted for each laptop model. It may happen that some tools work on the different model of laptop, but this does not mean that he has to work on each model.

    Second important fact is that Toshiba does not Satellite M40X support for Vista operating system and I guess you won't be able to use this tool. In my opinion, it is not so important, because all the energy-saving settings you can find in Vista power options.

    For utility E - key, I don't see a solution. If you use OS not supported, you must live with it.

  • Variable with a value. «PURGE error: bad Argument Type.»

    
    

    Hi, my 50G calculator accuses a value for the variable 'X' but I can't find it in any directory, and when I try to delete I get the message "' PURGE error: bad Argument Type." " I also have the theta variable with the same problem. How can I remove the value of these variables? TKS

    In addition to Make suggestions, two other possibilities come to mind: 'X' can be a directory object (which would cause the error to the wrong Type of Argument because non-empty directory objects cannot be purged by PURGE, but must be purged by PGDIR), or it could be a local variable (which can only be served by putting an end to the environment that created which is usually a program).  So if Make suggestions don't work, try foster 'X' PGDIR and if that does not work, try KILL (which ends all the current environments).

    If those WHO do not work, please do 'X' TYPE HOME and tell us what object type 'X'.

    DISCLAIMER: I do not work for HP; I'm a happy user of HP Calculator.

  • Pavilion dv6 - 7095ca: no boot device - insert boot disk and press any key


    Thanks for your help and please excuse my bad English.
    Please check item 7, if you're in a hurry. This is the point with my Pavilion DV6 - 7095-CA:

    (1) the operating system is Windows 7 Home Premium (64 bit), the provided original with my 7095CA Pavilion, more updates HP until 2013, and all Windows updates until July 2015.

    (2) now I can't access the operating system and I have no interface UEFI. I can see that I press F2 at startup, just a test simple disk in BIOS f.0Une (the test shows that the disc is OK)

    (3) return in 2013 it took a drive failure. I did replace the disk and reinstall original Win7, all updates, including the HPS, win7 updates and all my personal software.

    (4) at this time, I bought a spare hard drive and did a complete copy of the disc using Partition Wizard bootable cd. The second disc has been tested and worked perfectly, with all of my personal software on this subject.

    So I have 2 HDs identical with the same system on both drives, fully working and tested.

    (5) a few days ago I came across the HP website and made a few updates, including the BIOS f.0Une (the last BIOS update, was of course).

    (6) after BIOS update ran, I received the message "no boot device - insert boot disk and press any key".

    (7) I couldn't solve the problem, so I did remove the hard drive and install my backup drive, which lay in a dry place without danger from 2013.

    (8) I turned on the computer and got the same message "No boot device - insert boot disk and press any key", and I couldn't find any way to solve this problem.

    Now I'm doing a new installation on a third HD everything works very well, so far, in the new facility and I will never buy HP again.

  • Satellite 2140CDS: message: "insert the disk and press a key".

    Hello

    I got this laptop but the necessary update. I tried to put a master drive from my other laptop to update and it came with 'error' and now when I turned it back on it does nothing about it, totally blank and rpet "insert the disk and press a key".

    I've got everything I can think but still can not do anything.

    Please can someone help?

    Hello

    What do you mean with master drive? Do you mean the Toshiba Recovery CD or what?

    It seems that the laptop can not find a source of seed and so this message appears on the screen!

    If you use a FDD drive please check if the disk has been removed.

    You must simply insert your Toshiba Recovery CD and boot from the CD/DVD drive. That's all.

    PS: Check if the HARD drive isn't too bad, as if the internal HARD drive is malfunctioning you will not be able to reinstall the OS from the CD

  • LabVIEW 2015 do not install it, autorun.exe "met a bad argument.

    Hello

    I recently got a new laptop and tried to install labVIEW on it. He started to install, but the system loses power in the middle and close. I deleted the National Instruments folder in Program Files (x 86) and retried, but when I run autorun.exe said he "met a bad argument" with a red 'X'. So I tried to launch setup.exe, and he starts, but bypasses LabVIEW and continues for the module in real time, where it says "LabVIEW 2015 must be installed before you install the real time module. Any help would be appreciated.

    Thank you


  • NO BOOT DEVICE - PLEASE INSERT the STARTUP DISK AND press a KEY ANY * please help *.

    I have a Compaq CQ-50 that worked very well. It has been upgraded to winows 7 Bonus a year ago. This is the message I get when I press the power button

    NO BOOT DEVICE - PLEASE INSERT THE BOOT DISK AND PRESS ANY KEY

    any help would appreciated more than you know

    Hello

    Have you tried to reinstall the hard drive if yes. Then the drive is bad & who has need of a replacement.

    If your laptop is still under warranty, contact HP and arrange for the disc replaced.

    If you are out of warranty and would like a guide to replacing the hard drive yourself, let me know.

  • HP Pavilion A6722SC: reboot and select proper boot device or insert boot media in selected boot device and press a key

    My computer has just stopped working and when I turned it on, it says I should change my hard drive. I did, but now the message is whenever I turn on my computer: reboot and select proper boot device or insert boot media in selected boot device and press a key.

    I have Hp Pavilion A6722SC. I have my 1st drive on the driver that I bought and I have the Boot Device Priority :

    1st boot Device [hard disk group]

    2 St boot Device [CD-ROM Group]

    3rd boot device [network startup group]

    4 rd boot Device [group Floppy]

    -> Disk Boot Priority group [not installed]

    -> Group of CD-ROM boot Priority [DSK02...]

    -> Group of HDD to boot Priority [DSK00...]

    -> Group network boot priority [not installed]

    I saw that many said I should disable the floppy, or I should have hard on the boot device 1 or driver, but this doesn't work for me. Someone who have solved problems of this kind? I need help!

    Thanks in advance.

    Sorry for the bad spelling.

    I needed a new OS... I had Windows Vista and I can't install it more, so I have to buy a new OS.

  • Caps lock and num lock keys lights don't light up

    Hello

    My caps lock and num lock keys lights don't light up when I turn the plugs or NumLock on, I recently contacted Microsoft Tech support, they told me to contact my HP manufacturing and it's a laptop, they did ' t really gives me a lot of support, so I'm here without you people asking how to solve this problem.

    Thank you
    Marco

    Hello Marco818,

    Thank you for your message.  Microsoft was right to put you in touch with the manufacturer of your.  The keyboard will fall under the material, so only they can fix or diagnose what the problem.  It could be something as simple as a bad supply or burnt cable bulb.  Anyway, that falls under HP support.

    See you soon

  • Windows 7 Ult has suddenly and bad start showing a message "non-genuine copy".

    Since I used it last there two days, my copy of Windows 7 Ultimate has suddenly and bad start showing a message "not real".  Enter the correct product key Activation menu causes the message that Microsoft has blocked this key.  It's infuriating and totally unfair!  No explanation?

    Please run the Microsoft Genuine Diagnostics Tool then copy and paste the results into an answer here for further analysis:
    http://go.Microsoft.com/fwlink/?LinkId=52012

    In addition, if you were using a pre-release version of Windows 7 Service Pack 1, your license status can change in non-genuine. You must uninstall the beta or RC, and then install the final version:

    http://Windows.Microsoft.com/en-us/Windows7/uninstall-SP1

    http://Windows.Microsoft.com/troubleshootwindows7sp1

    Learn how to install Windows 7 Service Pack 1 (SP1)
    http://Windows.Microsoft.com/en-us/Windows7/learn-how-to-install-Windows-7-Service-Pack-1-SP1

  • ACS 4.0 Ganymede + key

    Hello

    I try to use an ACS for switch GANYMEDE + authentic. I'm getting an incompatibility of keys, but I know more actually to the definition of a key for GANYMEDE on the GBA unit. How can I reset / know where it is?

    Thank you.

    1. side ACS:

    -Connect to ACS via web browser

    -On the main menu of ACS, check the configuration of switch (called Client AAA) State under "Network Configuration - AAA Client".

    http://www.Cisco.com/en/us/products/sw/secursw/ps5338/products_user_guide_chapter09186a0080233613.html#wp142681

    -Check the details of the switch and the secret key said. You can re-enter the same key or set the new key (without spaces or characters).

    -Compare or use this key in the switch, which is configured in the setting "radius-server."

    -Save the config

    2 switch

    -Connection to the switch CLI (console/telnet/ssh)

    -Scroll down to the "radius-server key" configuration line.

    http://www.Cisco.com/en/us/products/hw/switches/ps637/products_configuration_guide_chapter09186a008007f032.html#xtocid238207

    -Delete the existing key (normally / encrypted hash). Enter the same key - no more space or characters.

    -Make sue you're pointing to the ACS server/IP address

    -Do not save the config yet. Test the Ganymede + / authentication AAA to verify that the ACS server and the used switch button fix / identical.

    I hope this helps. Pls note all useful message (s)

    AK

  • Problem with GANYMEDE + (ACS) and cat 2950

    I have configured the 2950 as below and properly configured ACS and I can connect to the 2950 using this configuration, the problem lies after that I go to enable and try any command, I get approval to next error command failed.

    What I missed out the config that will allow me to execute commands?

    AAA new-model

    AAA authentication login default group Ganymede + local

    AAA authorization exec default group Ganymede + local authenticated by FIS

    AAA authorization commands 15 default group Ganymede + authenticated if

    AAA authorization network default group Ganymede + local authenticated by FIS

    AAA accounting exec default start-stop Ganymede group.

    orders accounting AAA 15 by default start-stop Ganymede group.

    AAA accounting network default start-stop Ganymede group.

    GANYMEDE server host ***. ***

    radius-server key 7 *.

    Thanks in advance.

    Jon

    Hi Jon,

    AAA of the switch seems ok, maybe you need to take a look at your ACS.

    Check the following information, where you have to apply it in your ACS config:

    http://www.Cisco.com/en/us/products/sw/secursw/ps5338/products_configuration_guide_chapter09186a00801fd6fc.html#wp676529

    Rgds,

    AK

  • authentication between the ACS and AD

    Hello

    I would like to know what kind of authentication mechanism ACS 5.1 use to speak with Active Directory. Does simply use MSCHAP, MSCHAPv2 or PAP. By default, it uses PAP to talk between the Cisco IOS and the AEC on the 5.1.

    If you llook at the default admin tab and click on allowed protocols---> he mentions PAP.

    Should I use a safe means of transport between the ACS and AD. IDF, so anyone can say the authentication mechanism?

    Thank you

    Any meeting of directors like telnet, ssh and comfort they always use PAP as an authentication method.

    Although communication pap can be captured and read in this case in clear text. However, since we have Ganymede in use, he always encrypt the whole package with shared secret defined on the IOS and ACS/GANYMEDE so if you capture traffic between the radius and the device you won't be able to decipher it without the key.

    In case you have Ray then using SSH (Putty) so that it can help you for a safe communication.

    ACS and AD support PAP, CHAP, MSCHAPv1 and MSCHAPv2.

    However, the administration does not work on another method of authentication except PAP.

    HTH

    Regds,

    Jousset

    Note the useful posts ~

  • ACS SE backup private key

    How to back up the private key of the ACS SE. I have the public key certified by a commercial CA already and you don't want to waste money spent in the purchase of the certificate. Reason I want because I'm getting following error on the console and backup services have stopped.

    "Before called API initialized to H:\ismg_israel_acs\Acs\EndPoint\Core\endpoint.c.

    pp:394 ".

    ===============

    Cisco Secure ACS: 4.1.4.13

    The application management software: 4.1.4.13

    Base Unit image: 4.1.1.4

    CSA build 4.0.1.543.2: (Patch: 4_0_1_543)

    ==========

    CSAdmin - arrested

    CSAuth - arrested

    CSDbSync - arrested

    Case - stop

    CSMon - from

    CSRadius - from

    CSTacacs - shut down

    ===================

    Can I use the backup feature? It also backs up the private key?

    Maury,

    Unfortunately, there is no way to export just the private key and the certificate.

    which can be re-imported in the ACS. There was a request in this regard

    feature to allow the export of private keys and certificates for the purposes of backup. Is the bug ID: CSCed14965.

    http://www.Cisco.com/cgi-bin/support/Bugtool/onebug.pl?BugID=CSCed14965

    However, what you can do, is make a backup of the database. This will save the registry

    that includes the certificate and the private key. Then, you can restore this backup file

    on a new machine and choose to restore the part of the System Configuration. This will restore

    the certificate and the private key in the certificate of the CSA page.

    Hope that helps

    Kind regards

    ~ JG

    Note the useful messages

Maybe you are looking for

  • Is it OK Set Up Apple pay on the watch and not the iPhone?

    I created Apple pay on my watch, but not on my iPhone. Is there a problem with that. My reasoning is that I always have my Apple Watch on and use it only for pay. Is there a reason to set up on the phone?

  • I try the installation key OEM Office or upgrade to another version of Vista

    Hi, I had the same problem here. until someone shows me at the door, shouting that I have tried the vista OEM key to install office or upgrade to another version of vista, here are the facts: -C' is my work laptop.-It was installed with a volume work

  • Key issues of a recovery/key - Lenovo Y50

    Hello. I have a few questions about one of the keys. My laptop came with windows installed 8.1, and all drivers installed - to make sure that I've updated all the drivers via the Lenovo Web site and my via the website of nvidia graphics card driver.

  • Help for the SQL Installation

    Recently, I installed the following DBMS MS SQL version SQL Server Express with Tools (with LocalDB, including the database engine and SQL Server Management Studio Express) Although the details under the heading download said for beginners / learning

  • Failed to initialize at startup in Vista

    When I start Windows Vista Basic Homw, I get the error: "failed to initialize: 0x800106ba.» A problem caused this program service stop.This began after I clicked to download the Service Pack 1 on the site, but even that didn't download.Could you plea