ISE Could not locate Network Device or AAA Client
When authenticating using 802.1x and MAB, I recieve an authentication failure with the error 11007(Could not locate Network Device or AAA Client). The root cause that ISE spits back at me is "Could not find the network device or the AAA Client while accessing NAS by IP during authentication." I did pretty much everything by the book except instead of using a loopback interface I used a vlan with a defined ip address. Could this be causing the problem?
Here is the config of the port that I'm testing on:
interface GigabitEthernet1/0/9
switchport access vlan 9
switchport mode access
switchport voice vlan 8
ip access-group ACL-ALLOW in
srr-queue bandwidth share 1 30 35 5
queue-set 2
priority-queue out
authentication event fail action next-method
authentication event server dead action reinitialize vlan 4
authentication event server dead action authorize voice
authentication host-mode multi-auth
authentication open
authentication order dot1x mab
authentication priority dot1x mab
authentication port-control auto
authentication violation restrict
mab
mls qos trust device cisco-phone
mls qos trust cos
dot1x pae authenticator
dot1x timeout tx-period 10
auto qos voip cisco-phone
spanning-tree portfast
service-policy input AUTOQOS-SRND4-CISCOPHONE-POLICY
end
I can ping both the vlan and the endpoint from the ISE. As far as allowing ISE to speak snmp and RADIUS to the NAD, I have enabled it on the NAD config inside the ISE. I have also double checked the snmp and radius shared passwords.
I have gotten MAB authentication to work but I am still getting the same error for dot1x authentication. Here are some of the configs on the switch.
aaa new-model
aaa authentication dot1x default group radius
aaa authentication dot1x defualt group radius
aaa authentication dot1x group group radius
aaa authorization network default group radius
aaa accounting dot1x default start-stop group radius
aaa server radius dynamic-author
aaa session-id common
ip radius source-interface TenGigabitEthernet1/0/1
radius-server attribute 6 on-for-login-auth
radius-server attribute 6 support-multiple
radius-server attribute 8 include-in-access-req
radius-server attribute 25 access-request include
radius-server dead-criteria time 5 tries 3
radius-server host 10.10.10.47 auth-port 1812 acct-port 1813 test username test key 7 097940581F5412162B464D
radius-server vsa send accounting
radius-server vsa send authentication
dot1x system-auth-control
authentication order dot1x mab
authentication priority dot1x mab
dot1x pae authenticator
dot1x timeout tx-period 10
Similar Messages
-
11007 could not locate network device or aaa client
Dears,
I have two redundant WLC and two ISE configured as primary and secondary.
I configured the Dot1x and users authenticated successfully, but my issue that i'm still receiving this error message (11007 could not locate network device or aaa client).
Any ideas or suggestions highly appreciated,ISE NAD Import via CSV passes with invalid IP, unable to load NAD config
CSCur65990
Description
Symptom:
RADIUS requests dropped due to failure reason "11007 Could not locate Network Device or AAA Client", even though they are successfully loaded in ISE.
Conditions:
Issue with Network Device import via CSV.
Known Affected Releases:
(2)
1.2(0.912)
1.3(0.876) -
Installing iTunes "could not locate network location itunes\."
Can anyone help me with the following error:
"could not locate network location itunes\."
I have had an iPod for a week now and can't instal iTunes
JohnNo problem
You tried everything from both of these articles?
http://docs.info.apple.com/article.html?artnum=300361
http://docs.info.apple.com/article.html?artnum=93976 -
13017 Received TACACS+ packet from unknown Network Device or AAA Client
I am adding new routers to our Corporate network for a new MPLS network. I am getting 13017 Received TACACS+ packet from unknown Network Device or AAA Client errors for these new routers. They are added to ACS 5.4.0.30 correctly just like all of our other devices. We have never had real routers on the network before, just switches and access points. Is there something special I need to set in ACS for these to work and authenticate correctly? I can only access the currently with built in login locally.
One of the new router configs
Current configuration : 2370 bytes
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
hostname T666
boot-start-marker
boot-end-marker
enable secret 5 $1$h7b3$.T2idTKb9H98BQ8Op0MAC/
aaa new-model
aaa authentication login default group tacacs+ local
aaa authentication enable default group tacacs+ enable
aaa authorization exec default group tacacs+ local if-authenticated
aaa accounting exec default start-stop group tacacs+
aaa session-id common
clock timezone CST -6
clock summer-time CDT recurring
ip cef
ip auth-proxy max-nodata-conns 3
ip admission max-nodata-conns 3
voice-card 0
crypto pki trustpoint TP-self-signed-2699490457
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-2699490457
revocation-check none
rsakeypair TP-self-signed-2699490457
username netadmin privilege 15 secret 5 $1$SIR2$A3MpShVNeAOlTPyLZESr..
interface FastEthernet0/0
ip address 10.114.2.1 255.255.255.0
ip helper-address 10.30.101.4
duplex auto
speed auto
interface FastEthernet0/1
no ip address
shutdown
duplex auto
speed auto
interface Serial0/1/0
ip address X.X.X.X 255.255.255.252
no fair-queue
service-module t1 timeslots 1-24
service-module t1 remote-alarm-enable
service-module t1 fdl ansi
no cdp enable
router bgp 65065
no synchronization
bgp log-neighbor-changes
network 10.114.2.0 mask 255.255.255.0
neighbor X.X.X.X remote-as 209
neighbor X.X.X.X default-originate
default-information originate
no auto-summary
ip forward-protocol nd
ip bgp-community new-format
ip http server
ip http authentication aaa
ip http secure-server
ip tacacs source-interface FastEthernet0/0
no logging trap
tacacs-server host 10.30.101.221 key 7 1429005B5C502225
tacacs-server host 10.30.101.222 key 7 1429005B5C502225
tacacs-server directed-request
control-plane
banner exec ^CC
C
Login OK
^C
banner motd ^CC
C
** UNAUTHORIZED ACCESS TO THIS SYSTEM IS PROHIBITED. USE OF
** THIS SYSTEM CONSTITUES CONSENT TO MONITORING AT ALL TIMES.
** RUAN Transport Corporation
** Network Services
** [email protected]
** 515.245.2512
^C
line con 0
line aux 0
line vty 0 4
exec-timeout 30 0
transport input all
line vty 5 15
exec-timeout 30 0
scheduler allocate 20000 1000
end
T666#AAA Protocol > TACACS+ Authentication Details
Date :
September 19, 2014
Generated on September 19, 2014 10:21:27 AM CDT
Authentication Details
Status:
Failed
Failure Reason:
13017 Received TACACS+ packet from unknown Network Device or AAA Client
Logged At:
Sep 19, 2014 10:21 AM
ACS Time:
Sep 19, 2014 10:21 AM
ACS Instance:
acs01
Authentication Method:
Authentication Type:
Privilege Level:
User
Username:
Remote Address:
Network Device
Network Device:
Network Device IP Address:
10.114.2.1
Network Device Groups:
Access Policy
Access Service:
Identity Store:
Selected Shell Profile:
Active Directory Domain:
Identity Group:
Access Service Selection Matched Rule :
Identity Policy Matched Rule:
Selected Identity Stores:
Query Identity Stores:
Selected Query Identity Stores:
Group Mapping Policy Matched Rule:
Authorization Policy Matched Rule:
Authorization Exception Policy Matched Rule:
Other
ACS Session ID:
Service:
AV Pairs:
Response Time:
Other Attributes:
ACSVersion=acs-5.3.0.40-B.839
ConfigVersionId=359
Device Port=59840
Protocol=Tacacs
Authentication Result
Steps
Received TACACS+ packet from unknown Network Device or AAA Client
Additional Details
DiagnosticsACS Configuration Changes -
TACACS+ packet from unknown Network Device or AAA Client
Hi all,
I can't perform login using the credential set at ACS server, From the log it shown:
"Failure Reason: 13017 Received TACACS+ packet from unknown Network Device or AAA Client"
I know there's some changes on TACACS+ part for new catalyst IOS, so i refer the guide and this is my config snipet:
aaa group server tacacs+ TAC_PLUS
server name AUTH
tacacs server AUTH
address ipv4 10.10.21.251
key xxxxxx
aaa authentication login TAC_PLUS group tacacs+ local line
aaa authorization exec TAC_PLUS group tacacs+ none
aaa authorization commands 15 default if-authenticated
aaa accounting update periodic 1
aaa accounting exec TAC_PLUS start-stop group tacacs+
aaa accounting network TAC_PLUS start-stop group tacacs+
aaa accounting connection TAC_PLUS start-stop group tacacs+
My platform is
- C6500 running on IOS 12.2 (33) SXJ1
- ACS 5.2.0.26
Need guidance on this, thanks
NoelHello,
Is the appropriate IOS IP address defined on the Network Devices and AAA Clients for the ACS? If yes, which IP address is reported on the ACS Failure that includes the error "TACACS+ packet from unknown Network Device or AAA Client"? Is the ACS reporting the IP address as unknown when it is already defined appropriately?
Regards. -
Could not access network location :. help please!
I cannot get APPLE MOBILE DEVICE SUPPORT uninstalled from my system,when I try to remove it from add/remove programs this is what I get:
Could not access network location :.
All other apple Itunes products I can remove,but not AMDS.
Also when I try to install a fresh copy of itunes it cannot be completed because of the aforementioned issue crops up when trying to install.That's suggesting damage to the installation database in the AppleMobileDeviceSupport.msi (or related installation configuration information), sheena.
Unfortunately, this sort of trouble has gotten more complicated to deal with ever since Microsoft pulled the Windows Installer CleanUp utility from their Download Center on June 25 2010. First we have to find a copy of the utility.
Let's try Googling. (Best not to use Bing, I think.) Look for a working download site for at least version 3.0 of the Windows Installer CleanUp utility. (The results from mydigitallife and Major Geeks are worth checking.)
After downloading the utility installer file (msicuu2.exe), scan the file for malware, just in case. (I use the free version of Malwarebytes AntiMalware to do single-file scans for that.)
If the file is clean, to install the utility, doubleclick the msicuu2.exe file you've downloaded.
Now run the utility ("Start > All Programs > Windows Install Clean Up"). In the list of programs that appears in CleanUp, select any Apple Mobile Device Support entries and click "Remove".
Quit out of CleanUp. Restart the PC, and try another iTunes install. Does it go through properly this time? -
Error reads. Could not access network location %APPDATA%\\
Could not access network location %APPDATA%/
With that particular variety of 1606 (it's a 1606 error message even though the 1606 error message number isn't returned by the iTunes installer), the following Microsoft document is worth a try:
[You receive an "Error 1606" error message when you try to install or remove a Microsoft program|http://support.microsoft.com/kb/886549] -
I CANNOT INSTALL I-TUNES 64 BIT ON MY COMPUTER. I HAVE A DELL 750 OPTIPLEX DESKTOP COMPUTER RUNNING WINDOWS 7 PROFESSIONAL SP1, INTEL Q965/Q963 EXPRESS CHIPSET FAMILY. THE ERROR MESSAGE I KEEP ON GETTING EVERY SINGLE TIME IS:
Could not access network location %PUBLIC%\Desktop\.
ANYONE HAVE AN IDEA ON HOW TO FIX THIS PROBLEM? THANKS FOR YOUR HELP IN ADVANCE!Hello there, jag123059.
The following Knowledge Base article offers up some great steps to follow for resolving issues with installing iTunes:
Issues installing iTunes or QuickTime for Windows
http://support.apple.com/kb/ht1926
Thanks for reaching out to Apple Support Communities.
Cheers,
Pedro. -
Help can't install or uninstall itunes keep getting the message " could not access network location %APPDATA%\, "
And follow this:
http://support.apple.com/kb/HT1925
Apple moved some drivers for 64-bit now to where they should have been.
Quicktime also use to place files outside the norm.
One of the reasons I recommend when it comes to Apple:
Wait for the ".1" and always use the uninstaller first and then install.
That means you may want manual standalone installer instead - and that way you have 10.4.1 in case you need to later downgrade. -
ITunes will not install, error message "could not access network location"
I just got a new iPod Classic for Christmas but I have an older Mac so I was going to use an extra PC that we have laying around the house but every time I try to install iTunes, I get this Error:
Could not access network location \\S090100\d$\Data.Backup\C09010009-FDR\My Documents\My Pictures\.
It does not have Error 1606 anywhere on it and it asks me if I want to Retry or Cancel. I have tried EVERYTHING, please help!!For general advice see Troubleshooting issues with iTunes for Windows updates.
The steps in the second box are a guide to removing everything related to iTunes and then rebuilding it which is often a good starting point unless the symptoms indicate a more specific approach. Review the other boxes and the list of support documents further down the page in case one of them applies.
The further information area has direct links to the current and recent builds in case you have problems downloading, need to revert to an older version or want to try the iTunes for Windows (64-bit - for older video cards) release as a workaround for installation or performance issues, or compatibility with QuickTime or third party software.
Your library should be unaffected by these steps but there are also links to backup and recovery advice should it be needed.
tt2 -
When i try to install i tunes, it goes so far down the installation process and then comes up with a message ' could not access network location %APPDATA%\. I then retry and it comes up with the same message.
It also tells me i tunes needs 'Quick Time' to support the software. I have downloaded Quicktime from i tunes seperately and gone through the whole process again, only to get the same message.
Can anyone please help?These kind of messages can often be cleared by using the Microsoft Installer cleanup Utility.
Here is a method for cleanup of your old iTunes installation and reinstall.
== uninstall with cleanup ==
Download a fresh copy of iTunes and the stand alone version of Quicktime (the one without iTunes)
http://www.apple.com/quicktime/download/win.html
http://www.apple.com/itunes/download/
Save the files on your PC.
Download and install Microsoft Installer cleanup utility, there are instructions on the page as well as the download. Note that what you download is the installer not the program – you have to run it to install the program. The installer doesn't give any message to confirm the installation.
http://support.microsoft.com/kb/290301/
(To run the program – All Programs>>Windows Install)
Now use the following method to remove iTunes and its components:
XP
http://support.apple.com/kb/HT1925
Vista or Win 7
http://support.apple.com/kb/HT1923
*If you hit a problem with one of the uninstalls don't worry*, carry on with the deleting of files and folders as directed in the method.
When you get to deleting Quicktime files in the system32 folder as advised in the method, you can delete any file or folder with Quicktime in the name.
Restart your PC.
Run the Microsoft Installer Cleanup Utility. (Start > All Programs > Windows Install Clean Up)
Remove any references you find to the programs you removed - strictly speaking you only need to worry about those programs where the uninstall failed.
If you don’t see an entry for one of the programs that did not uninstall, look out for blank entries or numeric entries that look like version numbers e.g. 7.x for Quicktime or 1.x for Bonjour.
restart your PC
Install the stand alone Quicktime and check that it works.
If it does, install iTunes. -
Okay, I received a never used iPod Nano
(Model MC034LL ,Version 1.0. 2 PC, it looks like this http://www.iphonemag.ch/wp-content/uploa…
for Christmas this year, however; I'm having some trouble installing iTunes.
I have already downloaded iTunes, but installing seems to be the problem.
The 'iTunesSetup' icon appears on my desktop and I double-clicked it to begin the installing process.
When I do so, it says
"Gathering required information... Status: Computing Space Requirements"
after a few seconds it says, "Could not access network location %APPDATA%/."
As soon as I click 'retry' it says the same thing.
If I press cancel, the same message pops up and then it says,
"iTunes Installer Completed
The installer encountered errors before iTunes could be configured.
Your system has not been modified To retry these operations at a later time, please run the installer again.
Click exit to finish the installer"
I tried the help page for iTunes, but noting seemed helpful.
Message was edited by: Seraph6886Could not access network location %APPDATA%/
With that particular variety of 1606 (it's a 1606 error message even though the 1606 error message number isn't returned by the iTunes installer), the following Microsoft document is worth a try:
[You receive an "Error 1606" error message when you try to install or remove a Microsoft program|http://support.microsoft.com/kb/886549] -
Trying to update iTunes on XP. Keep getting message "could not access network location iTunes\."
Any ideas"could not access network location iTunes\."
(1) Download the Windows Installer CleanUp utility installer file (msicuu2.exe) from the following Major Geeks page (use one of the links under the "DOWNLOAD LOCATIONS" thingy on the Major Geeks page):
http://majorgeeks.com/download.php?det=4459
(2) Doubleclick the msicuu2.exe file and follow the prompts to install the Windows Installer CleanUp utility. (If you're on a Windows Vista or Windows 7 system and you get a Code 800A0046 error message when doubleclicking the msicuu2.exe file, try instead right-clicking on the msicuu2.exe file and selecting "Run as administrator".)
(3) In your Start menu click All Programs and then click Windows Install Clean Up. The Windows Installer CleanUp utility window appears, listing software that is currently installed on your computer.
(4) In the list of programs that appears in CleanUp, select any iTunes entries and click "Remove", as per the following screenshot:
(5) Quit out of CleanUp, restart the PC and try another iTunes install. Does it go through properly this time? -
Itunes wont install ,could not access network location %appdata% error?
itunes wont install ,could not access network location %appdata% error?
Let's try the following user tip with that one:
"Could not access network location %APPDATA%" install errors -
Install Problem: "Could not access network location %APPDATA%\."
I get "Could not access network location %APPDATA%\." when trying to install or uninstall itunes. Has anyone seen this. I've tried several of the general troubleshooting topics.
Similar problem..."Could not access network location ." went through all the microsoft repairs for a 1606 error. No resolve. My itunes used to work perfectly then when I went through an itunes initiated update, then my itunes would bring up the error whenever I tried to update. I uninstalled itunes then tried to reinstall without any success. Still get the error. And now I dont have itunes. Has anyone figured this out yet or do I need to abandon and go to droid?
Maybe you are looking for
-
Urgent - Need an answer - XML Java API
This is the 3rd time I've posted this question in last week - Oracle Support: How can I get an answer to this? This question is about how to free up the memory of XMLDocuments, Parsers, etc using the Java APIs - not the PLSQL wrappers. I'm writing an
-
Does the Mini have a seperate HDMI or Display port in addition to the Thunnderbolt port? Here is my dilema: I need to use an analog VGA display - no problem as there is an adaptor for that? I also need the Thunderbolt port to connect to a device, a B
-
FileLoadException with Oracle.DataAccess
Hello, I get the following error when I try to run my application on the app server. It works fine on my development box. Details on the server's configuration are below the error message. **** BEGIN ERROR MESSAGE **** System.IO.FileLoadException: Th
-
I am unable to update my new credit card on my payment details???
Hi there, I got a notification my credit card epxired and therefore this has stopped my CC payment. I am getting an error message when I try to upload my new card? It wont work. Any advice?
-
Authorization review process document
Hi all, Our management wants to review authorization of all users yearly once.They are asking for a process document which will state all the process and procedures to do the same.I have no clue how should I go about it. Can anybody please help