
Appendix A Troubleshooting Information for Cisco Secure ACS
User Authentication Issues
A-14
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
User Authentication Issues
Condition
Recovery Action
After the administrator removes the Check NT
Callback setting from External User Databases:
Database Configuration: Windows NT/2000:
Configuration, Windows NT/2000 database users
can still dial in and apply the Callback string
configured under the Windows NT/2000 user
database.
Restart Cisco Secure ACS services. For steps, see
Stopping, Starting, or Restarting Services,
page 8-2
.
Callback is not working.
Ensure that callback works on the AAA client
when using local authentication. Then add AAA
authentication.
User authentication fails when using PAP.
Outbound PAP is not enabled. If the Failed
Attempts report shows that you are using
outbound PAP, go to Interface Configuration and
select the Per-User Advanced
Features check box. Then, go to User Setup:
Advanced Settings. Click
Enable Control and type and confirm the
password in the Outbound Password
box.
Unknown users are not authenticated.
Go to External User Databases: Unknown User
Policy. Click Check the following external user
databases. From the External Databases list,
select the database(s) against which to
authenticate unknown users. Click —> (right
arrow button) to add the database to the Selected
Databases list. Click Up or Down to move the
database into the desired position in the
authentication hierarchy.
If you are using the Cisco Secure ACS Unknown
User feature, external databases can authenticate
using only PAP.
User did not inherit settings from new group.
Users moved to a new group inherit new group
settings but they keep their existing user settings.
Manually change the settings in User Settings.