14-3
User Guide for Cisco Secure Access Control System 5.3
OL-24201-01
Chapter 14 Troubleshooting ACS with the Monitoring & Report Viewer
Performing Connectivity Tests

Performing Connectivity Tests

You can test your connectivity to a network device with the device’s hostname or IP address. For
example, you can verify your connection to an identity store by performing a connectivity test.
To test connectivity between your ACS and a device’s hostname or IP address:
Step 1 Select Monitoring and Reports > Troubleshooting > Connectivity Tests.
The Connectivity Tests page appears as described in Table 14-2:
Step 2 Modify the fields in the Connectivity Tests page as required.
Step 3 Click ping, traceroute, or nslookup, depending upon your test.
The output of the ping, traceroute, or nslookup command appears.
Trust Sec Tools
Egress (SGACL) Policy Compares the Egress Policy (SGACL) between a network device and ACS.
See Comparing SGACL Policy Between a Network Device and ACS,
page 14-11 for more information.
SXP-IP Mappings Compares SXP mappings between a device and peers. See Comparing the
SXP-IP Mappings Between a Device and its Peers, page 14-12 for more
information.
IP User SGT Compares IP-SGTs on a device with ACS authentication-assigned
User-IP-SGT records. See Comparing IP-SGT Pairs on a Device with
ACS-Assigned SGT Records, page 14-14 for more information.
Device SGT Compares device SGT with ACS-assigned SGT. See Comparing Device
SGT with ACS-Assigned Device SGT, page 14-15 for more information.
Table 14-1 Expert Troubleshooter - Diagnostic Tools (continued)
Diagnostic Tool Description
Table 14-2 Connectivity Tests
Option Description
Hostname or IP Address Enter the hostname or IP address of a connection you want to test. Click Clear to clear the
hostname or IP address that you have entered.
ping Click to see the ping command output, where you can view the packets sent and received, packet
loss (if any) and the time for the test to complete.
traceroute Click to see the traceroute command output, where you can view the intermediary IP addresses
(hops) between your ACS and the tested hostname or IP address, and the time for each hop to
complete.
nslookup Click to see the nslookup command output, where you can see the server and IP address of your
tested domain name server hostname or IP address.