S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
20-38
Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x
OL-9285-05
Chapter 20 Troubleshooting IP Storage Services
iSCSI Issues
RADIUS Configuration Troubleshooting
If iSCSI authentication is through the RADIUS server, ping the RADIUS server to and from the switch
to make sure it can be reached over IP.
Verifying RADIUS Key and Port for Authentication and Accounting
Choose
Switches > Security > AAA > RADIUS
in Fabric Manager to verify the RADIUS key and port
for authentication.
Or use the
show radius-server
CLI command to verify that the RADIUS key and port for authentication
and accounting are an exact match with what is configured on the RADIUS server.
switch#
show radius-server
retransmission count:3
timeout value:5
following RADIUS servers are configured:
171.71.49.197:
available for authentication on port:1812
available for accounting on port:1813
RADIUS shared secret:radius
Adjust the RADIUS timeout and retransmission accordingly, as they have a default value of 1 second
and 1 time.
Figure 20-12
shows a Windows-based RADIUS server configuration.
Figure 20-12
Windows-Based RADIUS Server Configuration Dialog Box
If the items in
Figure 20-12
match your switch’s configuration, then verify that the client user name and
password also match those in the RADIUS server.
The following example shows the output of the
debug security radius
command, if the iSCSI client logs
in successfully.