Troubleshooting Guide

Table Of Contents
Parameter Description
cli-profile-enable Specifies if RADIUS ACLI profiling is enabled. ACLI
profiling grants or denies access to users being
authenticated by way of the RADIUS server. You can
add a set of ACLI commands to the configuration on
the RADIUS server, and you can specify the
command-access mode for these commands. The
default is false.
enable Specifies if RADIUS authentication is globally
enabled on the switch.
igap-passwd-attr Specifies the IGMP for user Authentication Protocol
(IGAP) password attribute.
igap-timeout-log-fsize Specifies the IGMP for user Authentication Protocol
(IGAP) timeout log file size.
maxserver Specifies the maximum number of servers allowed
for the device. The default is 10.
mcast-addr-attr-value Specifies the value of the multicast address attribute.
The default is 90.
sourceip-flag Specifies if the switch can use a configured source
IP address. If the outgoing interface on the switch
fails, a different source IP address is used, which
requires that you make configuration changes to
define the new RADIUS client on the RADIUS
server. To simplify RADIUS server configuration, you
can configure the switch to use a circuitless IP
(CLIP) address as the source IP and NAS IP
address when transmitting RADIUS packets.
By default, the switch uses the IP address of the
outgoing interface as the source IP, and the NAS IP
address for RADIUS packets that it transmits.
Administrator unable to obtain accounting information from the
TACACS+ server
If the administrator is unable to obtain accounting information from the TACACS+ server, perform
the following steps.
Procedure
1. Check whether you enabled accounting on the switch:
show tacacs
2. Check whether you enabled accounting on the TACACS+ server.
Troubleshooting TACACS+
January 2017 Troubleshooting 245
Comments on this document? infodev@avaya.com