Chapter 14 Troubleshooting ACS with the Monitoring & Report Viewer

Working with Expert Troubleshooter

Step 6 Click Show Results Summary to view the diagnosis and resolution steps.

Related Topics

Available Diagnostic and Troubleshooting Tools, page 14-1

Connectivity Tests, page 14-1

ACS Support Bundle, page 14-1

Expert Troubleshooter, page 14-2

Comparing Device SGT with ACS-Assigned Device SGT

For Security Group Access-enabled devices, ACS assigns each network device an SGT value through RADIUS authentication. The Device SGT diagnostic tool connects to the network device whose IP address you provide and does the following:

1.Obtains the network device’s SGT value.

2.Checks the RADIUS authentication records to determine the SGT value that ACS had assigned to it most recently.

3.Displays the Device-SGT pairs in a tabular format and identifies whether the SGT values are the same or different.

Use this diagnostic tool to compare the device SGT with ACS-assigned device SGT. To do this:

Step 1 Choose Monitoring and Reports > Troubleshooting > Expert Troubleshooter.

The Expert Troubleshooter page appears.

Step 2 Click Device SGT from the list of troubleshooting tools.

The Expert Troubleshooter page is refreshed and lists the fields described in Table 14-11.

Table 14-11

Device SGT

Option

Description

Enter Information

Network Device IPs (comma-separated list)

Enter the network device IP addresses (whose device SGT you want to compare with an ACS-assigned device SGT) separated by commas.

 

 

User Guide for Cisco Secure Access Control System 5.3

 

 

 

 

 

 

OL-24201-01

 

 

14-15

 

 

 

 

 

Page 457
Image 457
Cisco Systems OL-24201-01 manual Comparing Device SGT with ACS-Assigned Device SGT, 14-15