Symantec VIP Radius server is offline and service will not start
search cancel

Symantec VIP Radius server is offline and service will not start

book

Article ID: 237171

calendar_today

Updated On:

Products

VIP Service

Issue/Introduction

Radius service will not start

Environment

Symantec VIP Enterprise Gateway (EGW)

Cause

The Radius service requires the User Store connection to be working in order to function. The vast majority of the time if the Radius Service will not start, it is because one of the User Stores is unable to connect.

Resolution

Check all of the User Store connections and verify they are testing correctly. The User Store connection is based on 3 items and you will need to verify each one if it is failing the test:

  1. Domain Controller host - Ensure the name or IP address in the 'Host' section is accurate and that the VIP EGW server can reach it on the network (ping, nslookup, etc...)
    • Note: if SSL is enabled, you must also verify the SSL certificate to the Domain Controller is still valid.
  2. Bind User - Verify the user location (AD Distinguished Name) is still accurate (i.e., User object has not been moved or deleted) and that the password has not been changed or expired. Ideally you want this user to be a service account set to have the "password never expires"
  3. Test User - This user account must still be present in Active Directory and meet all of the requirements outlined in the User Filter. If this user is no longer valid, then the initial test will fail and the Radius will not be able to validate the LDAP connection.

For additional help with the User Store Filter and connection configurations, please refer to this KB article:  https://knowledge.broadcom.com/external/article?articleId=163791