A-3
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
Appendix A Troubleshooting Information for Cisco Secure ACS
Browser Issues
Browser Issues
Cisco IOS Issues
Condition
Recovery Action
The browser cannot bring up the
Cisco Secure ACS HTML
interface.
Open Internet Explorer or Netscape Navigator and choose Help >
About to determine the version of the browser. See
System
Requirements, page 2-2
, for a list of browsers supported by
Cisco Secure ACS and the release notes for known issues with a
particular browser version.
For information about various network scenarios that affect remote
administrative sessions, see
Network Environments and Remote
Administrative Sessions, page 1-27
.
The browser displays the Java
message that your session
connection is lost.
Check the idle timeout value for remote administrators. This is in
the Administration Control window. Increase the value as needed.
Administrator database appears
corrupted.
The remote Netscape client is caching the password. If you specify
an incorrect password, it is cached. When you attempt to
re-authenticate with the correct password, the incorrect password is
sent. Clear the cache before attempting to re-authenticate or close
the browser and open a new session.
Condition
Recovery Action
Under EXEC Commands,
Cisco IOS commands are not
being denied when checked.
•
Examine the Cisco IOS configuration at the AAA client. If it is
not already present, add the following Cisco IOS command to
the AAA client configuration:
aaa authorization command <0-15> default group
•
The correct syntax for the arguments in the text box is
permitargument or denyargument.
Administrator has been locked
out of the AAA client because of
an incorrect configuration set up
in the AAA client.
Try to connect directly to the AAA client at the console port. If that
is not successful, consult your AAA client documentation or go to
Cisco.com regarding password recovery procedures on your AAA
client. For the appropriate URL, see
Cisco.com, page xxxi
.