14-12
User Guide for Cisco Secure Access Control System 5.4
OL-26225-01
Chapter14 Troubleshooting ACS with the Monitoring and Report Viewer
Working with Expert Troubleshooter
Comparing SGACL Policy Between a Network Device and ACS
For Security Group Access-enabled devices, ACS assigns an SGACL for every source SGT-destination
SGT pair based on the Egress policy matrix that you configure in ACS. The Egress policy diagnostic tool
does the following:
1. Connects to the device whose IP address you provide and obtains the ACLs for each source
SGT— destination SGT pair.
2. Checks the Egress policy that is configured in ACS and obtains the ACLs for each source
SGT— destination SGT pair.
3. Compares the SGACL policy obtained from the network device with the SGACL policy obtained
from ACS.
4. Displays the source SGT —destination SGT pair if there is a mismatch. Also, displays the matching
entries as additional information.
To compare the SGACL policy between a network device and ACS:
Step1 Choose Monitoring and Reports > Troubleshooting > Expert Troubleshooter.
Step2 Select Egress (SGACL) Policy from the list of troubleshooting tools.
The Expert Troubleshooter page is refreshed and shows the Network Device IP field.
Step3 Enter the IP address of the Security Group Access device whose SGACL policy you want to compare
with ACS.
Step4 Click Run to compare the SGACL policy between ACS and the network device.
The Progress Details page appears. The Monitoring and Report Viewer prompts you for additional input.
Step5 Click the User Input Required button and modify the fields as described in Table14-5.
Step6 Click Submit.
The Progress Details page appears with a brief summary of the results.
Step7 Click Show Results Summary to view the diagnosis and resolution steps.
The Results Summary page appears with the information described in Table 14 -6.
Related Topics
Available Diagnostic and Troubleshooting Tools, page14-1
Connectivity Tests, page14-1
ACS Support Bundle, page14-1
Expert Troubleshooter, page 14-2
Comparing the SXP-IP Mappings Between a Device and its Peers
Security Group Access devices communicate with their peers and learn their SGT values. The Security
Exchange Protocol-IP (SXP)-IP Mappings diagnostic tool connects to the device whose IP address you
provide and lists the peer devices’ IP addresses and SGT values.
You must select one or more of the device’s peers. This tool connects to each of the peers that you select
and obtains their SGT values to verify that these values are the same as the values that it learned earlier.