Send documentation comments to mdsfeedback-doc@cisco.com
17-3
Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x
OL-9285-05
Chapter 17 Troubleshooting RADIUS and TACACS+
AAA Issues
Symptom Switch does not communicate with AAA server.
Table 17-1 Switch Does Not Communicate with AAA Server
Symptom Possible Cause Solution
Switch does not
communicate with
AAA server.
Incorrect authentication or accounting
port configured.
Reconfigure the authentication or accounting ports to
match those configured on the AAA server.
For RADIUS servers, see the “Verifying RADIUS
Configuration Using Fabric Manager” section on
page 17-4 or the “Verifying RADIUS Configuration Using
the CLI” section on page 17-4.
For TACACS+ servers, see the “Verifying TACACS+
Configuration Using Fabric Manager” section on
page 17-5 or the “Verifying TACACS+ Configuration
Using the CLI” section on page 17-5.
Incorrect preshared key configured. Reconfigure the same preshared key on the switch and the
AAA server.
For RADIUS servers, see the “Verifying RADIUS
Configuration Using Fabric Manager” section on
page 17-4 or the “Verifying RADIUS Configuration Using
the CLI” section on page 17-4.
For TACACS+ servers, see the “Verifying TACACS+
Configuration Using Fabric Manager” section on
page 17-5 or the “Verifying TACACS+ Configuration
Using the CLI” section on page 17-5.
AAA server monitor deadtime set to
high.
Set the deadtime lower to bring AAA servers active more
quickly.
For RADIUS servers, see the “Verifying RADIUS Server
Monitor Configuration Using Fabric Manager” section on
page 17-6 or the “Verifying RADIUS Server Monitor
Configuration Using the CLI” section on page 17-6.
For TACACS+ servers, see the “Verifying TACACS+
Server Monitor Configuration Using Fabric Manager”
section on page 17-7 or the “Verifying TACACS+ Server
Monitor Configuration Using the CLI” section on
page 17-7.
Timeout value too low. Change server timeout value to ten seconds or higher.
For RADIUS servers, see the “Verifying RADIUS Server
Monitor Configuration Using Fabric Manager” section on
page 17-6 or the “Verifying RADIUS Server Monitor
Configuration Using the CLI” section on page 17-6.
For TACACS+ servers, see the “Verifying TACACS+
Server Monitor Configuration Using Fabric Manager”
section on page 17-7 or the “Verifying TACACS+ Server
Monitor Configuration Using the CLI” section on
page 17-7.