Chapter 14 Troubleshooting ACS with the Monitoring & Report Viewer

Performing Connectivity Tests

Table 14-1 Expert Troubleshooter - Diagnostic Tools (continued)

Diagnostic Tool

Description

Trust Sec Tools

Egress (SGACL) Policy

Compares the Egress Policy (SGACL) between a network device and ACS.

 

See Comparing SGACL Policy Between a Network Device and ACS,

 

page 14-11for more information.

 

 

SXP-IP Mappings

Compares SXP mappings between a device and peers. See Comparing the

 

SXP-IP Mappings Between a Device and its Peers, page 14-12for more

 

information.

 

 

IP User SGT

Compares IP-SGTs on a device with ACS authentication-assigned

 

User-IP-SGT records. See Comparing IP-SGT Pairs on a Device with

 

ACS-Assigned SGT Records, page 14-14for more information.

 

 

Device SGT

Compares device SGT with ACS-assigned SGT. See Comparing Device

 

SGT with ACS-Assigned Device SGT, page 14-15for more information.

 

 

Performing Connectivity Tests

You can test your connectivity to a network device with the device’s hostname or IP address. For example, you can verify your connection to an identity store by performing a connectivity test.

To test connectivity between your ACS and a device’s hostname or IP address:

Step 1 Select Monitoring and Reports > Troubleshooting > Connectivity Tests.

The Connectivity Tests page appears as described in Table 14-2:

Table 14-2 Connectivity Tests

Option

Description

 

 

Hostname or IP Address

Enter the hostname or IP address of a connection you want to test. Click Clear to clear the

 

hostname or IP address that you have entered.

 

 

ping

Click to see the ping command output, where you can view the packets sent and received, packet

 

loss (if any) and the time for the test to complete.

 

 

traceroute

Click to see the traceroute command output, where you can view the intermediary IP addresses

 

(hops) between your ACS and the tested hostname or IP address, and the time for each hop to

 

complete.

 

 

nslookup

Click to see the nslookup command output, where you can see the server and IP address of your

 

tested domain name server hostname or IP address.

 

 

Step 2 Modify the fields in the Connectivity Tests page as required.

Step 3 Click ping, traceroute, or nslookup, depending upon your test.

The output of the ping, traceroute, or nslookup command appears.

 

 

User Guide for Cisco Secure Access Control System 5.3

 

 

 

 

 

 

OL-24201-01

 

 

14-3

 

 

 

 

 

Page 445
Image 445
Cisco Systems OL-24201-01 manual Performing Connectivity Tests, Diagnostic Tool Description, 14-3