Cisco Prime and Radius

I have setup Prime to use Radius, i can see authenication request to my radius but i keep getting user name and password is incorrect. I have 100's of switches authenticating to this radius server and everything works fine. I have loooked for logs in Prime for radius errors but I can't find anything.
any suggestions?                  

What's getting confused is the difference between AUTHENTICation (who are you?) and AUTHORIZation (what are you allowed to do?).  Clearly FreeRADIUS is saying that the AUTHENTICation passed--the credentials were correct--but it's not passing the correct AUTHORIZation information back.  Your IOS devices may bow to "shell:priv-lvl=15", but Prime Infrastructure isn't an IOS device, and has no idea what to do with that.  As well, the login failure mechanism isn't complicated enough yet to reflect to a user the difference between a failed AUTHENTICation or a failed AUTHORIZation.
There's a sample configuration document about NCS here in the Support Forum:
Freeradius for NCS config
All the correct AUTHORIZation attributes--the lines 'cisco-avpair += "NCS:task0=View Alerts and Events",'--from that sample are what you're missing.  The attributes are listed under Administration >  Users, Roles & AAA > User Groups > select a group > Task List hotlink for each group of user.  Remember that there HAS to be a VIRTUAL-DOMAIN attribute, a ROLE attribute and *ALL* of the TASK attributes associated with that group.  The attributes are going to be different from NCS to Prime Infrastructure, and tend to be different from version to version of each product, so you have to use the ones that are listed in whatever version of whatever product you're using right now.
Once you have FreeRADIUS configured to send the right attributes, to diagnose this full on, go to Administration > Logging, and set the logging level to Trace for the modules AAA, GUI and System, and click Save.  Then change your AAA settings and make a login attempt, allowing it to fail.  When it does, please return to Administration > Logging, and click the Download button to retrieve the logs.zip file.  Look in the ncs-0-0.log file and you'll see the transaction to FreeRADIUS, what Prime Infrastructure has to say to it, what FreeRADIUS says back, and what Prime Infrastructure does with the responses.

Similar Messages

  • Cisco Prime and Maps

    Hi
    When you create a map in Cisco Prime and place the APs, does this effect in any way the RRM configuration on the AP's? or there power\channel selection?
    Or are the maps a purely passive tool?
    Thanks in advance

    RRM operates at the controller level.  Prime maps are passive only and have no impact on RRM.  The maps are more of a visual/graphical tool for heatmaps and planning scenarios.

  • Cisco Prime and UCS 220M3

    Dear folks,
    I have a confusion in one of my deployments. My client ordered initially a UCS 220M3 server, which came along with a windows CD. It was supposed to be used as an LMS 4.1 server. Later on there were some variation and customer wants to have prime infrastructure over it. Now I am unable to understand how to do it. The server which came doesnt have any OS. It has one 600 GB hard drive. Can anyone guide me what should i do / or order additionally to work out through this. I am pasting the BoQ for this server which is the original one before variation, the task is to make it work with Prime Infrastructure. Along with this i am attaching some snaps of the physical server and CIMC console...just to clear out any doubts... i will be very thankful if you suggest me the correct way.
    Part Number
    NMS
    LMS-4.1-100-K9
    Cisco Prime LMS 4.1 Base DVD - 100 device license
    1
    R200-BUN-4
    UCS C200 M2 Rack Svr  1x E5506  1x4GB  1PS
    1
    A01-X0113
    2.13GHz Xeon E5506 80W CPU/4MB cache/DDR3 800MHz
    1
    A02-M304GB2-L
    4GB DDR3-1333MHz RDIMM/PC3-10600/single rank/Low-Dual Volt
    2
    R200-D1TC03
    Gen 2 1TB SAS 7.2K RPM 3.5in HDD/hot plug/C200 drive sled
    1
    CAB-9K10A-UK
    Power Cord  250VAC 10A BS1363 Plug (13 A fuse)  UK
    2
    R2X0-PSU2-650W-SB
    650W power supply  w/added 5A Standby for UCS C200 or C210
    1
    MSWS-08R2-ENHV-RM
    Windows Svr 2008 R2 EN (1-8CPU  25CAL)  Media
    1
    R2X0-ML002
    LSI 1064E (4-port SAS 3.0G RAID 0  1  1E ) Mezz Card
    1
    A01-X0113
    2.13GHz Xeon E5506 80W CPU/4MB cache/DDR3 800MHz
    1
    N01-M304GB1
    4GB DDR3-1333MHz RDIMM/PC3-10600/dual rank 1Gb DRAMs
    1
    R2X0-PSU2-650W-SB
    650W power supply  w/added 5A Standby for UCS C200 or C210
    1
    R2XX-G31032RAIL
    Rail Kit for UCS C200  C210 Rack Servers (23.5 to 36)
    1
    R200-BBLKD
    HDD slot blanking panel for UCS C200 M1 Rack Servers
    3
    R200-BHTS1
    CPU heat sink for UCS C200 Rack Server
    2
    R200-PCIBLKF1
    PCIe Full Height blanking panel for UCS 200 M1 Rack Server
    2
    R200-PCIBLKL1
    PCIe Low Profile blanking panel for UCS 200 M1 Rack Server
    1
    R200-SASCBL-001
    Internal SAS Cable for a base UCS C200 Server
    1
    CON-UCW5-R200BN4W
    UC PLUS 8X5XNBDOS UCSC200M2RckSvr 1x E5506 1x4GB 1PS
    1

    You have the necessary CPU, memory and hard drive specifications for an Express size installation (Reference).
    To install Prime Infrastructure 2.0 you will need to first install VMware ESX/ESXi. This is documented in the same Getting Started Guide I linked to above at this link.
    Once you get that far along, just follow the setup wizard and installation is pretty simple.
    FYI you will get better attention to Prime questions over in the Network Management forum.

  • Cisco Prime and WLC packet capture error - Request Timed Out

    Hello,
    We have a Cisco Prime installation (2.2.0) and a WLC (Cisco 5508)
    I’ve been trying to test the wireless packet capture function, but have now run into problems, a quick rundown of my actions so far:
    Selected a wireless access point in Prime and clicked ‘Packet Capture’
    Did a packet capture saving to the PI, the capture worked fine
    Could not find any way to delete the packet capture
    Selected a wireless access point in Prime and clicked ‘Packet Capture’
    Did a packet capture saving to an FTP server, the capture worked fine
    The 1st capture had finished (10 minute capture) before testing the second
    The 2nd capture has also finished and saved the files to the FTP server as specified
    Now though I cannot capture from any access point as when I click ‘Packet Capture’ I get the error:
    “Request Timed out. Error in getting data from server.”
    The error is ‘instant’ as in no delay indicating something actually timing out.
    So the 2 problems I have are:
    How do I fix the ‘request timed out’ error above
    How do I delete old packet captures from the PI
    I hope someone can help as I can’t find any info on either of the problems.
    Cheers
    Adrian

    I think I've solved (2) by deleting the files from the FTP directory on the prime box through SSH.
    So I'm now just stuck on the timed out error.

  • Cisco Prime and WLC audit

    Hello,
    Is there an automated way to perform audit of Wlc from the Cisco Prime Infrastructure GUI? I use to go to Monitor->Controller, then check the box near one of the managed wlc, finally choosing 'Audit Now' on the top menu. It works fine, but when you have multiple wlcs, such operation takes a long time. I would like to retain the configuration which is on the wlc instead of the one on the PI database too.
    Do you know if there is a better way to perform the audit?
    Thanks
    Théophile

    Have you looked at the background task to see if there is an audit there? Are you really wanting to audit or just refresh the config from the WLC? If you do hate getting the mismatch and dine have all the templates for each of the WLC's, the audit only reviews what's in the templates. Refresh the config from the WLC is the easiest way as you can select all of your WLC and perform this task.
    Sent from Cisco Technical Support iPhone App

  • Cisco Prime and ESX 5.1

    Hi
    we are upgrading LMS from 3.2 (windows) to LMS 4.2 and VMWare. But now i recogniced that it only runs with ESX 5.0.
    We only have version 5.1 so does anyone have experience if its running with 5.1 ?
    Is there any plan from cisco for an official version supporting ESX 5.1 ?
    Thanks
    Norbert                     

    Hello Norbert,
    I've once installed LMS 4.2 on ESXi 5.0 and 5.1 for a test enviroment. Installation and running the application works, but the LMS Software is so slow, that when you click on a menuentrie you have to wait up do 45 second until anything happens.
    As Sebastian said, PI 1.x works fine on ESXi 5.0 and 5.1. We're running several PI 1.3 Installations on ESXi 5.1. Installation and running the application works perfect. For installation I've used the .ova files which can be received at the Cisco Download area.
    But if you ask me, if you want to install PI as a new installation you should switch to PI 2.0 which is or will be release in June, if I'm right.
    If you need some installation help, feel free to contact me.
    Kind regards
    Kai

  • Cisco Prime and WLC HA-SSO

    Hi All.
    i implemented the HA_SSO on two wlc, WLC1 Active and WLC2 Hot Stanby and the system works fine.
    My question reguarding the monitoring. Is Possible monitoring  to the WLC Secondary?
    if by chance the wlc standby should be broken as I can realize this fault?
    Regards

    Is Possible monitoring to the WLC Secondary?
    Currently, the answer is NO.  Wait a few more months.  If I remembered correctly, this feature has been asked several times and might actually be incorporated with CPI 3.0 which is rumoured to be released on May/June 2015.

  • Cisco Prime 2.1 HA and NFS backup

    Hi,
    I've just configured my Cisco Prime with the external NFS backup server using instruction from the Administration Guide,
    http://www.cisco.com/c/en/us/td/docs/net_mgmt/prime/infrastructure/2-1/administrator/guide/PIAdminBook/backup_restore.html#pgfId-1085464
    all works fine but I'm wondering what about HA server? Should I configure all the same steps I did on a primary server?
    Regards
    Gunter

    No, this instruction is for how to configure backup server and how to configure Cisco Prime to be able to use NFS for backup files. It works, I did this and there was no problem during the configuration. The only thing I'm wondering is that I did this on the primary Cisco Prime and not on the HA CP server. So what will hempen if the primary fail and the HA switch over as a primary? Should I configure the same repository on it, should I enable NFS on the HA server also?

  • Cisco Prime - extract list of hostnames and their serial numbers.

    Hi all,
    is there a way of extracting a list of hostnames ( for devices in EMEA ) and their associated serial numbers from Cisco Prime and into say a csv file?
    Many thanks,
    Paul

    Hi Paul,
    if you have Prime Infrastructure then  run the below report :
    Report > Report Launch Pad > Device > Detailed Hardware > Detailed Hardware Report Details
    If Prime LMS then :
    Reports > Inventory > Detailed Device
    Hope it will help
    Thanks-
    Afroz
    ***Ratings Encourages Contributors ***

  • Cisco Prime Infrastructure 2.1: SNMP Connectivity Failed

    Hi,
    I have discharged all my Cisco devices within Cisco Prime and after a few days and when everything worked correctly one of the switches is displayed with the SNMP error Connectivity Failed, nothing has been changed.
    I deleted and i have returned to create the object but it continues to be the same, I've also tried to create another SNMP community still receiving the same error.
    This is the configuration of snmp in the switch WS-C3850-48P with version 03.02.02.SE
    snmp-server community "community" RW
    snmp-server location "location"
    snmp-server contact "contact"
    snmp-server host 10.180.5.22 version 2c "community"
    Best regards.

    Hi ,
    check if you are getting these errors in "show log" again:
     %SNMP-3-INPUT_QFULL_ERR: Packet dropped due to input queue full
    If yes , then either a lot of SNMP polling happening on the device
    or
    CPU utilization is going high sometime , being SNMP as a least priority process , you will see this issue. check for "show proc cpu history"
    It is a device side issue definitely.
    I would suggest to apply a Access-list on the SNMP community string allowing only the
    valid NMS to poll the device
    Thanks-
    Afroz
    ***Ratings Encourages Contributors ***

  • E-mail will be suppressed up to 30 minutes for these alarms. Cisco Prime

    Hi
    I'm trying out the email notification in the cisco prime and encountered this issue.
    E-mail will be suppressed up to 30 minutes for these alarms.
    This causes the other AP's that I restart to not send an notification, and I cannot find a way to remove this email suppression.
    I want all the critical emails to be sent and not get dropped.
    Or am I misunderstanding this? I cant find any threshold to change / disable
    Cisco prime 2.0 fyi
    thanks!

    This is still a problem in Prime 2.0.  I opened a case asking how to change the email suppression time period from 30 minutes to 4 hours so that alarms tripped overnight that won't be acknowledged wouldn't result in a flooded mailbox, and was told this is not a configurable option. So apparently the only "fix" is to turn off the alarm, or change the category to a lesser one that won't result in an email being sent.  I hope in a future release they will decide to make this configurable.

  • How view snmp Traps CISCO PRIME 1.2

                       It is posible to view snmp Traps from WLC to CISCO Prime ?? How ?

    Hi Steve :
    I need to view the traps which are generated in the Controller, I need to view that in the Cisco Prime Infractructure. I´ve configured Communities in WLC with IP Address to Cisco Prime and Trap Receiver with IP address to Cisco Prime.
    Now, How can I view these Traps in the Cisco Prime ?.
    Another question , Is it posible to configure Switch from Cisco Prime ?
    Thanks,
    Claudio

  • Ask the Expert: Overview of Cisco Prime Service Catalog and Process Orchestrator Solutions

    Welcome to this Cisco Support Community Ask the Expert conversation. This is an opportunity to learn and ask questions about the Cisco Prime Service Catalog and Process Orchestrator solutions.
    Cisco expert Jason Davis will discuss Cisco’s network management products offered under the Cisco Prime framework. If you have questions about Cisco Prime infrastructure or data center automation with our Cisco Prime Service Catalog and Process Orchestrator solutions, join us on the Cisco Support Community.
    Jason Davis is a distinguished services engineer in the Intelligent Infrastructure Practice team of Cisco Advanced Services. His role is to provide strategic and tactical consulting for hundreds of Advanced Services customers, lead service innovation, and assess new services and technologies. Jason's primary expertise areas are in network management systems, intelligent automation, virtualization, data center operations, software-defined networking, and network programmability.
    Based out of the Research Triangle Park (RTP) campus, Jason is also responsible for administering the Research Triangle Park Network Management Lab, Cisco's largest network management lab.
    Since joining Cisco in 1998, Jason has been a frequent speaker at Cisco's Networkers and CiscoLive conferences in the United States and Europe. In the past five years he has also been involved in the conference network setup and monitoring. He is a much sought-after resource by the field sales teams to assist with presales solutions and executive briefings. He has provided strategic and tactical network management consulting for several hundred customers.
    Jason is a subject matter expert with the following products and features:
    Cisco Prime LAN management solution
    Cisco Prime infrastructure
    CiscoSecure ACS
    Cisco Prime Network Registrar
    Cisco Process Orchestrator
    Cisco Prime Service Catalog
    Cisco IP SLA
    Embedded Event Manager
    SNMPv3
    onePK and OpenFlow
    Cisco UCS
    Device instrumentation
    VMware ESX, ESXi, and vCenter
    ITIL
    Jason received his bachelor of science degree in electrical engineering from the University of Miami (FL). He has been married for 20 years and has 4 children. His interests include providing audiovisual technical support for churches and conference venues, camping and biking with his family, remote-control helicopter piloting, paintball, and recreational shooting.
    Remember to use the rating system to let Jason know if you have received an adequate response.
    Because of the volume expected during this event, Jason might not be able to answer every question. Remember that you can continue the conversation in Data Center > Intelligent Automation under the subcommunity Cisco Prime Service Catalog shortly after the event. This event lasts through September 12, 2014. Visit this forum often to view responses to your questions and the questions of other Cisco Support Community members.

    Hello Jason,
    Thank you very much for welcoming me to your expert discussion :) I feel to be in the right place, at the right time. Thank you also for answering question beyond your scope here, much appreciated. The information received will help me to go further as such I have submitted a 5 start rating for your first reply.
    That sounds promising about the LMS part so yes, I stay tuned and wait patiently.
    Ok, now let’s revert to the actual topic discussed here. Cisco Prime Service Catalog and Process Orchestrator solutions I have briefly read up on this on CCO (where elseJ) and picked out the following quote
    ---- Quote from the Cisco Prime Service Catalog Data Sheet
     Today’s end users want self-service and easy access to IT tools and services.
    Simultaneously, organizations are seeking ways to extend their cloud management
    platforms beyond self-service delivery of virtual machines and infrastructure resources
    while increasing their use of cloud-based solutions to enhance business agility and effectiveness.
    Cisco Prime™ Service Catalog offers tremendous benefits to organizations that want to unify the ways in
    which all types of IT services are ordered and fulfilled, not just infrastructure requests
    ---- un quote ---
    I try to understand what (at high level of course) happens in the back ground when an order is raised and which vendor solution your product can interact with.
    As mentioned in the quoted text, this service catalogue goes beyond the standard infrastructure.
    Let’s say, a user wants to deploy a new email services, or in your example,  extends or create a new web-portal (i.e. for HR to view and manage holiday, staff absence and benefits).
    Your solution will need to interact somehow with the 3rd party vendor application that is capable building such portal I believe.
    Without disclosing to many information, I assume the portal is linked to backend VM,s that spin up requested resources (and more magic of course). Perhaps I am mixing this up with another cisco product where a user can go on the portal and spin up virtual Firewalls, virtual Routers can be provisioned in now time.
    Out if interest; Is this product also known as Mozart? (project code within Cisco?)
    I hope query is ok.
    Best wishes
    Markus

  • Ask The Expert: Understanding, Implementing, and Troubleshooting Cisco Prime Network

    Ask questions and learn about Cisco Prime Network with Cisco experts Vignesh Rajendran Praveen and Jaminder Singh Bali.
    Cisco Prime Network is and  Cisco Prime Network provides cost-effective device operation, administration and network fault management for today’s complex and evolved programmable networks (EPNs). It is a single solution to support both the traditional physical network components, as well as compute infrastructure, and the virtual elements found in data centers. Automated configuration and change management combined with advanced troubleshooting and diagnostics greatly help service providers enable proactive service assurance. Additionally, the flexible and extensible architecture is designed to support the multivendor environment, helping to lower operational costs.
    This event runs January 5 through January 16, 2015.
    Vignesh Rajendran Praveen is a High Touch Engineer with the Focused Technical Services team supporting Cisco's major Service Provider customers in Routing, Switching, Multiprotocol Label Switching (MPLS) technologies and Cisco Prime Network related issues. Previously at Cisco he has worked as a Network Consulting Engineer for Enterprise Customers and as a Customer Support Engineer for Service Provider customers. He has been in the networking industry for ten years and holds CCIE certification (#34503) in the Routing and Switching as well as Service Provider tracks.
    Jaminder Singh Bali is a Customer Support Engineer working in SP-NMS TAC team, supporting Cisco's major service provider customers in Cisco Prime Network, Performance and Prime Central related issues. His areas of expertise include Oracle, Linux and NMS applications. He has been in the industry for past six years.
    Remember to use the rating system to let the experts know if you have received an adequate response. 
    The Experts might not be able to answer each question due to the volume expected during this event. Remember that you can continue the conversation in Network Infrastructure community, sub-community, LAN, Switching and Routing discussion forum shortly after the event. This event lasts through January 16, 2015. Visit this forum often to view responses to your questions and the questions of other community members.

    Hello Jerome,
    A variety of Cisco devices are supported by the the Cisco Prime Network. I would encourage you to go through the below links on the user guide depending the version of Cisco Prime Network being used.
    "Cisco Prime Network Supported Cisco Virtual Network Elements (VNEs)"
    "Cisco Prime Network Supported Cisco VNEs - Addendum"
    Below is the link for the user guide.
    http://www.cisco.com/c/en/us/support/cloud-systems-management/prime-network/products-user-guide-list.html
    Hope this would help in providing you more clarity.
    ***********Plz do rate this post if you found it helpful*************************
    Thanks & Regards,
    Vignesh R P

  • Replicate in the Master controller and creation of new user with cisco prime infrastructure 2.1.

    Hello!!
    We have multiple controllers Cisco WLC 5508 (all running software version 7.6.120.0) distributed in various buildings and a controller in other control building (also Cisco WLC 7.6.120.0 5508) operating as Master and backup of the buildings's controllers . 
    Each building is radiated such an SSID that is used as a validation of the user connected to that SSID web portal each controller (in the WLAN, Security -> Layer 3 -> Web Policy), using the local database to validate the user. 
    The problem is that the local database of users is not being replicated between controllers buildings and the Master controller, so if you drop the controller of a building, the Master controller begins to provide service to the buildings access points, but the equivalent radiated SSID cannot able to validate users. 
    I need know if it's possible through Cisco Prime Infrastruture 2.1, first replicate in the Master controller on the basis of existing controllers buildings each local data and, second, that the creation of new users are automatically perform both the controllers like to the Master .
    Thanks.

    As noted earlier, it is not advisable to use the root user to log in for normal use. New users and groups can be created by navigating to Administration > Users, Roles & AAA as shown in the preceding figures. It would help to chalk out what are the various levels at which you want to distribute the users, and to create those roles first. It doesn’t really matter whether you create users or groups first. New users can be easily added by going to Administration > Users, Roles & AAA > Users > Add Users > Select “Add Users” from the drop-down on the right side. Once you get into the add user workflow, fill in the username, password, and local authorization for this user as shown in the figure below.
    A virtual domain can also be assigned to the users when you define their roles by selecting the virtual domain on the left side and moving it to the right side as shown in the image below (left).

Maybe you are looking for

  • Transport fails with return code 12 for 0CHANOTASSIGNED Characteristics

    Dear Experts, I am transporting the 0CHANOTASSIGNED characteristics from BI Dev to BI QA. In BI Dev, I use the option Necessary Object. While importing request into BI QA, it fails with a return code 12. Some of the errors are: Start of the after-imp

  • Question about select query.

    Hi, i want to insert the result of query to a table, all the fields are corresponding except one field. is there a way to this or i need to do insert ( f1 , f2 ....) i did this way INTO CORRESPONDING FIELDS OF TABLE It_Return_Date but i have another

  • Transfer Custom and enhanced infotypes to ALE HR

    Hi All. We have a few customer infotypes (9xxx) and have enhanced a few standard ones like pa0185 etc. Now we have to transfer the data of these infotypes to other system. Standard PFAL transaction does not populate these. I know there is an enhancem

  • Upgrading to SSD for Pavilion SE (dv6885se)

    Hello all, I was wondering if I can possibly replace my current HDD to SDD. If so, what's the maximum size I can purchase? As with the OS, I'm planning of upgrading it to Windows 7. Any feedback and recommendations are much appreciated.

  • Authenticating Dynamically

    I have gone through the sample car rental authentication eg ...for authentication bofore starting the application a screen appears asking for user id..this screen appears automatically...i have a login web dynpro page in my application...how do i aut