[RADIATOR] Cisco NX-OS TACACS+ problems

Heikki Vatiainen hvn at open.com.au
Fri Oct 18 04:07:15 CDT 2013


On 10/18/2013 11:23 AM, Alexander Hartmaier wrote:
> On 2013-10-11 13:56, Caporossi, Steve G. wrote:
>> We also have issues with NXOS; in our case using RADIUS.
>>
>> It always seems to begin with these syslog messages;
>> 2013 Oct 10 19:56:14.103 mdf1 %RADIUS-3-RADIUS_ERROR_MESSAGE: Failed looking up IP address for RADIUS server <server address>
>> 2013 Oct 10 19:56:14.105 mdf1 %RADIUS-3-RADIUS_ERROR_MESSAGE: Failed looking up IP address for RADIUS server <server address>
>> 2013 Oct 10 19:56:14.106 mdf1 %RADIUS-3-RADIUS_ERROR_MESSAGE: Failed looking up IP address for RADIUS server <server address>
>> 2013 Oct 10 19:56:14.107 mdf1 %RADIUS-3-RADIUS_ERROR_MESSAGE: All RADIUS servers failed to respon
>> d after retries.
>>
>>  Authentication fails and we to fallback to local authentication to "fix" the issue by sending test authentication to the RADIUS servers.
>>
>> We have the DNS entries configured on the Nexus devices and when this is happening the device can ping the servers using the hostname. Another strange thing is it happens primarily in one VDC and much less frequently on the others using the same OOB management network.
> What do you mean with 'dns entries configured *on* the Nexus'? Does it
> happen too if you configure the radius servers ip addresses instead of
> their dns names?
> 
> @Radiator guys: any update from you?

For the RADIUS/DNS problem above, I can only think of configuring the
server with address instead of name. Why it fails? Maybe there's a rate
limit on the DNS side. If there are lots of RADIUS requests each causing
a DNS lookup, that might cause the lookup failures.

What comes to NX-OS problems Alexander sees, could it be possible that
accounting requests are sent to different Radiators than authentication
or authorization requests?

If so, then there might be a different shared key configured on the
NX-OS than on Radiator? In this case Radiator logs should show errors
hinting about 'Bad key?'. If Radiator thinks the key is bad, it will
disconnect and this may be logged as 'All servers failed to respond'.

Thanks,
Heikki

-- 
Heikki Vatiainen <hvn at open.com.au>

Radiator: the most portable, flexible and configurable RADIUS server
anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald,
Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS,
TTLS, PEAP, TNC, WiMAX, RSA, Vasco, Yubikey, MOTP, HOTP, TOTP,
DIAMETER etc. Full source on Unix, Windows, MacOSX, Solaris, VMS,
NetWare etc.


More information about the radiator mailing list