RADIUS with c2950G failover problem

Hello

I use a DOT1X authentication based on the two Windows of IAS servers.

My access switches are C2950 and I want to work with several Radius Server for high availability purposes.

But when my primary IAS server falls down (is declared dead when debug radius messages), try my switch to connect with each other and it does not work.

I have the following messages:

"10:22:57.412 Sep 12 UTC: RADIUS: signed new package (key: ciscomgt;). rctx: 0x80DA94

18)

10:22:57.412 Sep 12 UTC: RADIUS: try Server following (10.4.20.112:1812, 1813) for

id157

10:22:57.412 Sep 12 UTC: RADIUS: Fail-over refused to (10.4.20.112:1812, 1813)

id157

10:22:57.412 Sep 12 UTC: RADIUS: no response for id 157

It's still in "swing state" with each other.

With I try separately, the works of two servers correctly. When I try with a C2970 platform that works too. Are there special recommendations with the C2950?

Thanks for your help

Hi Gilou,

Please add the following command and if possible try again failover

RADIUS deadtime server 1

Let me know how it goes

Kind regards

~ JG

Note the useful messages

Tags: Cisco Security

Similar Questions

  • The team of NIC failover problem

    Hi all

    We have a problem with the failover of vSwitches.

    Basically the problem is when I unplug the cable of the two physical natachasery associated with my vSwitch there is a loss of contents of a sachet.  The content of a packet loss creates no real problems but the biggest problem is when you plug the network cable from back in.  That's where we lose 10 packs, what causes host ESXi due relinquish in VCenter since I did the test on the uplink system and causing all virtual machines that are running under it restart on another Member of the same Cluster ESXi host.

    After a lot of reading these forums and Ken vSwitch debate blog http://kensvirtualreality.wordpress.com/2009/04/05/the-great-vswitch-debate%E2%80%93part-3/

    Using the default route based on the original virtual port code should work just fine without the need of any special Cisco switch configuration.

    We run ESXi 4.1 HP DL380 / DL360 servers.  This is the configuration for VMware and switch cisco so any help is greatly appreciated.

    VMware VSwitch and PortGroup configs are attached as images.

    Cisco config which only the two switchports connected to the specific ESXi is attached as a text file.

    What us has monitored him looking at the physical cisco switch when attempting to connect the network to switch the switchport cisco cable flashes orange so that network on ESXi reports linking as down and as soon as the switchport goes green ESXi comes back online.

    Any ideas or recommendations how to solve this are greatly appreciated.

    ... should work just fine without the need of any special Cisco switch configuration...

    There is an important parameter, you must configure. It is the spanning tree portfast

    See http://kb.vmware.com/kb/1003804 for more details

    André

  • Tecra S10 - e-SATA with WD MyBook problem

    I have Tecra S10-10 loaded with win 7/32 final. From the beginning, there is fixation e-sata WD MyBook problem - most of the time cannot be reached
    and Device Manager hangs up refreshing devices. Only restart after sometimes he can be attached, but only those by boot allows. All other devices works fine. Before win 7
    I worked with XP no problem also.

    I tried to update the drivers for the chipset for win 7 - but it failed with the message that this computer does not meet the minimum requirements.
    The BIOS is 2.0. Trying to upgrade the BIOS to 3.0, he replied that Intel TXT must be disabled, but it is set in the BIOS, option cannot be selected.

    No idea how to fix e-sata?

    Hi Damir

    As I see that you do have a general problem with e-SATA, but just when you want to use this device to some so I think that the solution is not so easy.
    This device is not known to me, but I suppose you guessed it with USB cable. You can use it with any other standard USB port?

  • My sister has problems on his laptop, how can I connect to the laptop with my labtop to help him with his computer problems? Thank you.

    My sister has problems on his laptop, how can I connect to laptop with my labtop to help her with her computer problems when I live several States away? Please help me if you know how to do this thank you.

    Suggest you use Team Viewer, free version.
    It is used here every day for several hours.

    Please see the links below for more details...
    http://www.TeamViewer.com/en/index.aspx
    http://www.TeamViewer.com/en/products/remotecontrol.aspx
    http://www.TeamViewer.com/en/help/cat15-remote-control.aspx

  • Can I run the Microsoft Windows Malicious Software Removal Tool w / Kaspersky AntiVirus with/without any problems?

    Can I run the Microsoft Windows Malicious Software Removal Tool w / Kaspersky AntiVirus with/without any problems?

    Can I run the Microsoft Windows Malicious Software Removal Tool w / Kaspersky AntiVirus with/without any problems?

    Yes.  It is a tool on demand and not in real time thus creates no problems or conflicts with the other application in real time, including Kaspersky Antivirus.

  • S271HL - demand guarantee, she needed no repair - I'm back with the same problem

    Earlier, I sent a S271HL monitor for repair under warranty.  The issue was that the screen would not activate and the only thing that happened was an orange power flashing instead of a constant blue button button.  The problem is that I got, with the same problem that I sent him.

    I am the home monitor today.  The first two pages of order of service, under the description of the problem, I see:

    said c:CX dsnt unit turn on, only a power light flashes

    a: do you have a self test, no go, so informed the cs repair, cx agreed

    r: at the request of the unit for repair

    On the second page, I see this:

    Computer data. Accessories
    No accessories (No. Box)

    Software & other remarks:
    surface scratches, no power

    (Note to this poster: surface scratches?)  Where?  I treated this monitor as it was made of Crystal.)

    Diagnosis / repair:

    Reported problem not noted.  Monitor power towards the top with good screen, stable.  Monitor adopted system intensive burnin test over the weekend, more than 63 hours, without any problem.  At the end of the extensive, intensive, powered burnin test monitor then turn it several times; always under tension with a display of good and stable, no problems noted.  In the course of trials, powered monitor then turn it several times; always constantly lit with a good and stable display.

    ===============

    So, my friend has a supply for his Acer monitor (a smaller one) that has 19v and 2. 1 has, just like mine.  So I borrowed her power to test my monitor and I had the same problem: an orange power button flashing.

    So the question is: has anyone ever encountered this with Acer?  I'll call them, but I wanted to see if there was any opinions here at the same time.

    It seems that this has not worked for the first tester and launched up to more away for another tech fix, but when that tech he walks, it worked fine. I have been a mechanic my whole life, in many areas, and I saw this scenario several times. There is also the possibility that someone got lazy, but you can not prove it so just contact warranty service again and tell them that they must resume and attach it.

  • Windows Media Player version 11.0.6001.7010 with Vista. Problems with the automatic synchronization of music backup

    Windows Media Player version 11.0.6001.7010 with Vista. Problems with the automatic synchronization of music backup.

    Backup not working in all of these songs/albums that appear also in personal playlists. Does not account for all of the media/music in Windows Media Player. It is also not known where there are additional tracks from the same album, appearing in a personal reading list, these additional tracks (that is, it will take 2 album, but ignore the other 10). Has only begun to occur in 2-3 weeks.

    Previously, when I set up the sync partnership, there are options in playlists 'Sync' discovers the device Set Up, such as 'All music' 'All images' "5 * appreciation of music" etc. None of them showing now also available. Offered only my personal Playlists. All solutions?

    Hi Phil,

    Thanks for posting your question in the Microsoft Community forum. I understand that you can't auto sync in Windows Media Player. I'll help you with this problem.

    Before troubleshooting, provide us with information.

    1. don't you make changes to the computer before this problem?

    2. have you updated to Service Pack 2 installed?

    3. don't you make changes to the computer before this problem?

    This problem may occur if there is an inconsistency in the system files related to Windows Media Player. Follow these methods:

    Method 1.

    Solve problems in Windows Media Player: http://windows.microsoft.com/en-us/windows-vista/troubleshoot-problems-in-windows-media-player

    Method 2.

    Open the troubleshooting Windows Media Player settings Troubleshooter by clicking the Start button, then Control Panel. In the search box, type troubleshooting, and then click Troubleshooting. Click View all, and then click the Windows Media Player settings.

    Method 3.

    You can try to disable and enable the Media Player Control Panel.

    Steps to disable Media Player.

    (a) click the Start button, select Control Panel, click programs and then click turn on turn Windows features on or off. If you are prompted for an administrator password or a confirmation, type the password or provide confirmation.

    (b) to develop media features and uncheck the box next to Windows Media player. Click on ok and wait a few minutes to complete. Once this is done, restart the computer.

    Steps to activate the Media Player.

    (a) click the Start button, select Control Panel, click programs and then click turn on turn Windows features on or off. If you are prompted for an administrator password or a confirmation, type the password or provide confirmation.

    (b) to develop media features and check the box next to Windows Media player. Click on ok and wait a few minutes to complete. Once this is done, restart the computer.

    Method 4.

    You can run the Microsoft Safety Scanner to make sure that the computer is virus-free.

    Microsoft Safety Scanner: http://www.microsoft.com/security/scanner/en-us/default.aspx

    Security Scanner warning: there will be a loss of data through an analysis using the Microsoft safety scanner to remove any viruses found.

    Additional information.

    Set up a device to sync in Windows Media Player: http://windows.microsoft.com/en-US/windows-vista/Set-up-a-device-to-sync-in-Windows-Media-Player

    Windows Media Player sync: Frequently asked questions: http://windows.microsoft.com/en-us/windows-vista/windows-media-player-sync-frequently-asked-questions

    If you need help on this particular issue or any other related Windows issue, let know us and we will be happy to help you.

  • [WRVS4400N] RADIUS with VPN?

    Hello

    I have an Active Directory with RADIUS server and I intend to buy a wireless router with VPN functionality,

    I took a glance at the WRVS4400N documentation and I saw the use of RADIUS with 802. 1 X and wireless, but nothing about its use with VPN...

    It is therefore possible to use RADIUS for authentication on the VPN?

    Thank you

    Hi Mathieu chick and welcome in the community at the homepage of Cisco!

    The WRVS440N is managed by the Cisco Small Business Support Community.

    For discussions about this product, go here.

  • launch of checkers problems: error: trying to re-launch your game. If the problem persists, it may be network with the server problems or a problem with the configuration of your firewall.

    Windows Vista can not launch problem of checkers: try to re-launch your game. If the problem persists, it may be network with the server problems or a problem with the configuration of your firewall. Please check your firewall settings by visiting the Open Ports FAQ.

    Original title: launch of the problems of checkers:

    Hello

    If you have not yet tried to disable the antivirus/firewall software, then try the following steps to disable them.

    Disable the anti-virus software: http://windows.microsoft.com/en-US/windows-vista/Disable-antivirus-software

    Enable or disable Windows Firewall: http://windows.microsoft.com/en-US/windows-vista/Turn-Windows-Firewall-on-or-off

    IMPORTANT: Antivirus software can help protect your computer against viruses and other security threats. In most cases, you should not disable your antivirus software. If you do not disable temporarily to install other software, you must reactivate as soon as you are finished. If you are connected to the Internet or a network during the time that your antivirus software is disabled, your computer is vulnerable to attacks

  • TV LCD W2607C with the same problem of power W2600

    My Dell W2607C LCD TV has even no power problem. I had less than 3 years and have had very good care of it. I stop it after watching some tv to go with dinner. Two hours later I tried to turn it on and I have nothing. Not even a blink on the LCD. Power LED turned blue, then blinked orange.

    A week ago, I finally called Dell customer service. Of course, I've been waiting for about 20 minutes. After giving all pertinent information about my Dell 26 '' LCD/TV, the operator (in English very hilly, I might add) guided me through all the troubleshooting steps I had done. None worked troubleshooting.

    She tried pulling the line 'contact your cable operator' old, but I told her that the cable is fine cause it is also plugged into a second TV. She then tried to explain since it was out of warranty he could not replace. I did not stay in there and started to explain how Dell sold me a defective product and that I have LCD screens and televisions last more than 2 years and how it was unfair for a loyal customer to treat them that way. She then tried to send me to another service of technical support, but the only difference is they were going to charge me. I said 'No' and then asked his supervisor.

    He tried to give the same line on 'out of warranty' and I told him that this is not an uncommon problem and if you google "Dell 26 '' TV does not turn on", he would see that there are a large number of consumers out there with the same problem as me.

    He then said, "Oh but the problem you have raised is the 2600 series model not yours, yours is the 2607C.» I answered, without hesitation, "but it is still part of the same series, is - not? And it seems that the same problem was overlooked when they made the one I bought. »

    I was told someone to a "higher authority" would contact me, but their calls have been rather erratic and I can't return their calls only leave voicemails. I get emails telling me how they just tried to call and when they say they would call between some time next, I end up wasting time to wait for a call that never comes.

    As a last resort, I post here in the hope that I get response and are not facing customers by service script.

    I ordered from Dell recently, his good faith. If I'm stuck with a very expensive paperweight, I might as well made my recent purchases and cut all ties with Dell completely.


  • Users wireless with peap authentication problem

    Good afternoon

    I am currently trying to authenticate users wireless using PEAP and an external RADIUS server. The problem is when I try to authenticate that I get this error:

    AAA/AUTHENTIC/PPP: List of selection method "permanent premises.

    Dot11-7-AUTH_FAILED: Station... Failed authentication

    Should not use local authentication, but the aaa server that I set up.

    I looked on the internet but have not found a working solution.

    Does anyone know why it does not work?

    Here is my configuration running:

    Current configuration: 4276 bytes
    !
    ! Last modification of the configuration at 00:45:40 UTC Monday, March 1, 1993
    ! NVRAM config update at 16:38:23 UTC Thursday, July 24, 2014
    ! NVRAM config update at 16:38:23 UTC Thursday, July 24, 2014
    version 15.2
    no service button
    horodateurs service debug datetime msec
    Log service timestamps datetime msec
    encryption password service
    !
    host ap name
    !
    !
    Pulse 9 logging console
    enable secret 5 $1$ QVC3$ dIVAarlXOo52rN3ceZm1k0
    !
    AAA new-model
    !
    !
    AAA rad_eap radius server group
    192.168.2.2 Server ACCT-port auth-port 1812 1813
    !
    AAA rad_mac radius server group
    !
    AAA rad_acct radius server group
    !
    AAA rad_admin radius server group
    !
    AAA server Ganymede group + tac_admin
    !
    AAA rad_pmip radius server group
    !
    RADIUS server AAA dummy group
    !
    AAA authentication login eap_methods group rad_eap
    AAA authentication login mac_methods local
    AAA authorization exec default local
    AAA accounting network acct_methods power group rad_acct
    !
    !
    !
    !
    !
    AAA - the id of the joint session
    no ip Routing
    no ip cef
    !
    !
    !
    dot11 syslog
    !
    ssid dot11 test
    authentication open eap eap_list
    authentication-key wpa version2 management
    Comments-mode
    !
    !
    EAP peap profile
    peap method
    !
    Crypto pki token removal timeout default 0
    !
    ...
    !
    !
    Bridge IRB
    !
    !
    !
    interface Dot11Radio0
    no ip address
    no ip route cache
    !
    encryption ciphers aes - ccm mode
    !
    SSID test
    !
    gain of antenna 0
    STBC
    beamform ofdm
    root of station-role
    Bridge-Group 1
    Bridge-group subscriber-loop-control 1
    Bridge-Group 1 covering-disabled people
    Bridge-Group 1 block-unknown-source
    No source of bridge-Group 1-learning
    unicast bridge-Group 1-floods
    !
    interface Dot11Radio1
    no ip address
    no ip route cache
    Shutdown
    gain of antenna 0
    no block of dfs
    channel SFR
    root of station-role
    Bridge-Group 1
    Bridge-group subscriber-loop-control 1
    Bridge-Group 1 covering-disabled people
    Bridge-Group 1 block-unknown-source
    No source of bridge-Group 1-learning
    unicast bridge-Group 1-floods
    !
    interface GigabitEthernet0
    no ip address
    no ip route cache
    automatic duplex
    automatic speed
    dot1x EAP authenticator
    Bridge-Group 1
    Bridge-Group 1 covering-disabled people
    No source of bridge-Group 1-learning
    !
    interface BVI1
    192.168.3.10 IP address 255.255.255.0
    no ip route cache
    !
    The default gateway IP
    IP forward-Protocol ND
    IP http server
    IP http secure server
    IP http help-path http://www.cisco.com/warp/public/779/smbiz/prodconfig/help/eag
    radius of the IP source-interface BVI1
    !
    format of server RADIUS attribute 32 include-in-access-req hour
    RADIUS-server host 192.168.2.2 auth-port 1812 acct-port 1813 borders 7 140441081E501F0B7D
    RADIUS vsa server send accounting
    !
    1 channel ip bridge
    !
    !
    !
    Line con 0
    line vty 0 4
    transport of entry all
    !
    end

    Thank you

    I don't have installation autonomous APs before but I think I see the problem. You define a list of authentication , called "eap_methods" but you never call for it in the settings of your SSID. Instead he call you a list named "eap_list" in addition, I think that you might miss one order more. So maybe try this:

     dot11 ssid test authentication open eap eap_methods authentication network-eap eap_methods authentication key-management wpa version 2 guest-mode

    I hope this helps!

    Thank you for evaluating useful messages!

  • BlackBerry Smartphones Synching with Yahoo - password problems

    Hello

    I'm looking for help with a synchronization problem. I use an 8310. Windows Vista. Desktop Manager v 4.2.2.14.

    I'm going to synchronize. Get to a point where the connection fails, and he asks my Yahoo password. I enter, but he is not happy. The password is deifintely ok. I tried uninstalling & reinstalling different versions of Desktop Manager, but nothing helps. In the past, I had the problem, but it seemed to solve with uninstalling and reinstalling. However, who now does not work?

    What should do?

    What I have to do a complete uninstall - I see that it mentioned elsewhere?

    This is a very frustrating problem! Drives me crazy and preventing the use of my BB.

    I see also said elsewhere that a single don't use Media Manager - why is - this? Is there a good alternative out there to use for my BB as an MP3 player?

    Martin

    mgkelly wrote:

    I see also said elsewhere that a single don't use Media Manager - why is - this? Is there a good alternative out there to use for my BB as an MP3 player?

    HOWTO: use your blackberry as a USB device
    http://supportforums.BlackBerry.com/Rim/Board/message?board.ID=BlackBerryDesktopSoftware&thread.ID=3...

  • DMVPN with dynamic failover HSRP/IPSEC

    "DMVPN with dynamic failover HSRP/IPSEC."

    Hi all. Is this possible? When you use a direct IPSEC LAN to LAN, you have a card encryption and when you secure the card encryption at the source of the tunnel interface, you configure "' crypto map redundancy with State '."

    The DMVPN does not use encryption card, sound by using an IPSEC profile with protection of tunnel. How you configure stateful with HSRP IPSEC in this situation?

    We're heading for a double cloud dmvpn topology with 2 heads dmvpn geographically separate. I want that every network head to have a redundancy HSRP, which can be done fairly easily. But I also want State IPSEC to be replicated for all security associations IPSEC do not fall in the case of a failover. Is it possible in this scenario and how?

    Thanks a lot as always.

    Hello again ;-)

    There are currently no plan at the moment (that I know) to mix with State redundancy and anythign with protection of tunnel.

    Frankly it is best to create redundancy in DMVPN termination on both turntable and relying on routing protocols - which I am sure you aware of so I won't bore you with details.

    That said, my personal observation is - if you want a failover go to ASA, when you have routers, you have all these wonderful tools like VTI/GRE for IPsec that mix well with routing protocols, and MUCH MUCH more. It is very often to change some timers for routing protocol driven "failover" happen very quickly.

    Marcin

  • Impossible pictures send normal gmail, messaging LR and with server validation problem coming out?

    Unable to send photos with gmail, the problem of validation of the LR email and outgoing server

    Could attach you a screenshot of the error you get?

    Also did you shoot 2 verification channels and make less secure applications.

  • I bought a desktop computer and wanted to know if I am able to have creative clouds on this plan as well as my laptop with the same problem, I'm currently?

    I bought a desktop computer and wanted to know if I am able to have creative clouds on this plan as well as my laptop with the same problem, I'm currently?

    Your subscription license allows you to have two facilities activated, so if both machines meets the system requirements so you should be able to install and connect the two.

Maybe you are looking for

  • Siri does not (problems with the connection)

    Hello I installed macOS Sierra yesterday. Everything seems to work fine, except Siri. With Siri I always get an error message "I am having some problems with the connection. Please try again in a moment. ». But this seems to appear every time. The ne

  • My book for Mac "preparing backup".

    Hi all I've updated to Sierra this morning and since then my WD My Book for Mac has been slain in the backup of the preparation for about 10 hours. My backup before the upgrade went through without a problem. Is the amount of time the backup takes to

  • How can I get all my favorites for dupes or by name?

    It would be very useful to work simultaneously on all bookmarks. They grow up and be able to keep them as a group would be a very interesting addition.

  • How can I Debrick/Unbrick a Nighthawk X4S D7800

    Hello I was just wondering how I would go on debriking/unbrick my router (Nighthawk X4S D7800), in which case I have to. This happened until needed for Openwrt firmware. As well as not having the best of luck with the software in genral. Thanks in ad

  • Backup of symbolic links

    Hello I'm looking for some advice... I have a file which includes a number of MK links and symbolic links to other folders on my system, when I backup my system what will save the file linked twice? Once: the folder holding the link twice: the actual