<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS - LDAP TCP Keepalive (v5.2) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-ldap-tcp-keepalive-v5-2/m-p/1618214#M273558</link>
    <description>&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-thread-post"&gt;&lt;DIV class="jive-thread-post-body clearfix"&gt;&lt;DIV class="jive-thread-post-body-container"&gt;&lt;DIV class="jive-thread-post-message"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;reposting as with subject including v5.2:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an ACS 4.2.1.15 patch 3 and Novell Netware LDAP Server separated by a Firewall. The Firewall's default tcp session timeout is 3600 seconds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When no LDAP-Request is made for over one hour, the Firewall drops the connection from its table. The Problem is, that the ACS-Server thinks the connection is still open. When it tries to send an LDAP-Query this results in retransmissions and finally a RST... On the User side the Authentication attempt fails (timeout).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to enable TCP Keepalives on the Windows-Server side, but this has no effect on the LDAP-Connections used by ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any possibility to enable Keepalives in ACS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for any help!&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-thread-post-details clearfix"&gt;&lt;DIV id="jive-content-avgrating"&gt;&lt;DIV id="jive-content-avgrating-score" title="Average User Rating: 0"&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-1"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-2"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-3"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-4"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-5"&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-thread-ratings clearfix" id="jive-thread-ratings-2,059,103"&gt;&lt;STRONG class="csc-message-rating"&gt;Average Rating: 0 (0 Votes)&lt;/STRONG&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;A href="https://community.cisco.com/post!reply.jspa?thread=2059103" title="Reply to this message" target="_blank"&gt;&lt;SPAN class="jive-icon-sml jive-icon-comment-add"&gt;&lt;/SPAN&gt;Reply&lt;/A&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;A href="https://community.cisco.com/thread/2059103?tstart=0&amp;amp;viewcondensed" target="_blank"&gt;Outline View&lt;/A&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-reply-first jive-reply-indent1 jive-thread-expanded jive-thread-expanded-1 jive-message-odd"&gt;&lt;DIV class="jive-thread-reply-indent1"&gt;&lt;DIV class="jive-thread-reply-indent-shadow"&gt;&lt;DIV class="jive-thread-reply&amp;nbsp; clearfix"&gt;&lt;DIV class="jive-thread-reply-body"&gt;&lt;A name="3257937" target="_blank"&gt;&lt;/A&gt;&lt;DIV class="jive-author"&gt;&lt;DIV class="jive-thread-username"&gt;&lt;A class="jiveTT-hover-user jive-username-link" href="https://community.cisco.com/people/javier" id="jive-50694648,331,694,190,318,204" target="_blank"&gt;Javier Henderson&lt;/A&gt;&lt;/DIV&gt;&lt;SPAN class="jive-author-avatar-container"&gt;&lt;SPAN class="jive-cisco-user-points"&gt;&lt;IMG alt="Employee" src="https://community.cisco.com/resources/images/status/cisco_16x16.gif" title="Employee" /&gt;&lt;/SPAN&gt;&lt;A class="jiveTT-hover-user" href="https://community.cisco.com/people/javier" target="_blank"&gt;&lt;IMG alt="Javier Henderson" border="0" class="jive-avatar" height="30" src="https://community.cisco.com/people/javier/avatar/30.png?a=-1" width="30" /&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;DIV class="jive-username-link-wrapper"&gt;&lt;EM&gt;159 posts since&lt;/EM&gt;&lt;EM&gt;Mar 12, 2010&lt;/EM&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-thread-reply-body-container"&gt;&lt;DIV class="jive-thread-reply-subject"&gt;&lt;DIV class="jive-thread-reply-date"&gt;&lt;SPAN class="bold"&gt;1.&lt;/SPAN&gt; &lt;SPAN&gt;Dec 28, 2010 5:54 PM&lt;/SPAN&gt; &lt;A href="https://community.cisco.com/message/3255519#3255519" title="in response to: Zentraler Informatikdienst" target="_blank"&gt;&lt;IMG class="jive-icon-sml jive-icon-arrow-top" src="https://community.cisco.com/images/transparent.png" /&gt;&lt;/A&gt; in response to: &lt;A href="https://community.cisco.com/message/3255519#3255519" title="Go to message" target="_blank"&gt;Zentraler Informatikdienst&lt;/A&gt;&lt;/DIV&gt;&lt;STRONG&gt;&lt;A href="https://community.cisco.com/message/3257937#3257937" target="_blank"&gt;Re: ACS 4.2 - LDAP TCP Keepalive&lt;/A&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class="jive-thread-reply-message"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;You are seeing the effects of bug CSCti03338 which I filed a few months ago, though it is supposed to be fixed on 4.2.1(15) patch 3. Please open a TAC case so we can look into this in detail.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-content-controls"&gt;&lt;DIV class="jive-controls clearfix"&gt;&lt;DIV class="jive-thread-ratings clearfix" id="jive-thread-ratings-1"&gt;&lt;DIV id="jive-content-rating"&gt;&lt;DIV id="jive-content-userrating"&gt;&lt;DIV class="unrated 3257937 jive-rating-scores" id="jive-content-userrating-score"&gt;&lt;A href="https://community.cisco.com/thread/2059103?decorator=print&amp;amp;displayFullThread=true#" id="jive-icon-userrating-1" title="1: Not Helpful" target="_blank"&gt;ACS 4.2 - LDAP TCP Keepalive&lt;/A&gt;&lt;A href="https://community.cisco.com/thread/2059103?decorator=print&amp;amp;displayFullThread=true#" id="jive-icon-userrating-2" title="2: Somewhat Helpful" target="_blank"&gt;ACS 4.2 - LDAP TCP Keepalive&lt;/A&gt;&lt;A href="https://community.cisco.com/thread/2059103?decorator=print&amp;amp;displayFullThread=true#" id="jive-icon-userrating-3" title="3: Helpful" target="_blank"&gt;ACS 4.2 - LDAP TCP Keepalive&lt;/A&gt;&lt;A href="https://community.cisco.com/thread/2059103?decorator=print&amp;amp;displayFullThread=true#" id="jive-icon-userrating-4" title="4: Very Helpful" target="_blank"&gt;ACS 4.2 - LDAP TCP Keepalive&lt;/A&gt;&lt;A href="https://community.cisco.com/thread/2059103?decorator=print&amp;amp;displayFullThread=true#" id="jive-icon-userrating-5" title="5: Extremely Helpful" target="_blank"&gt;ACS 4.2 - LDAP TCP Keepalive&lt;/A&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV id="jive-content-avgrating"&gt;&lt;DIV id="jive-content-avgrating-score" title="Average User Rating: 0"&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-1"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-2"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-3"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-4"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-5"&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-thread-ratings clearfix" id="jive-thread-ratings-3257937"&gt;&lt;STRONG class="csc-message-rating"&gt;Average Rating: 0 (0 Votes)&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://community.cisco.com/message-abuse!input.jspa?objectID=3257937&amp;amp;objectType=2" target="_blank"&gt;&lt;SPAN class="jive-icon-sml jive-icon-warn"&gt;&lt;/SPAN&gt;Report Abuse&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;A href="https://community.cisco.com/post!reply.jspa?message=3257937" title="Reply to this message" target="_blank"&gt;&lt;SPAN class="jive-icon-sml jive-icon-comment-add"&gt;&lt;/SPAN&gt;Reply&lt;/A&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-reply-indent2 jive-thread-expanded jive-thread-expanded-2 jive-message-even"&gt;&lt;DIV class="jive-thread-reply-indent2"&gt;&lt;DIV class="jive-thread-reply-indent-shadow"&gt;&lt;DIV class="jive-thread-reply jive-thread-reply-alt&amp;nbsp; clearfix"&gt;&lt;DIV class="jive-thread-reply-body"&gt;&lt;A name="3271557" target="_blank"&gt;&lt;/A&gt;&lt;DIV class="jive-author"&gt;&lt;DIV class="jive-thread-username"&gt;&lt;A class="jiveTT-hover-user jive-username-link" href="https://community.cisco.com/people/juergen_m1" id="jive-55460948,331,694,212,815,204" target="_blank"&gt;Juergen Meier&lt;/A&gt;&lt;/DIV&gt;&lt;SPAN class="jive-author-avatar-container"&gt;&lt;SPAN class="jive-cisco-user-points"&gt;&lt;IMG alt=" " src="https://community.cisco.com/resources/images/status/nostar.gif" title=" " /&gt;&lt;/SPAN&gt;&lt;A class="jiveTT-hover-user" href="https://community.cisco.com/people/juergen_m1" target="_blank"&gt;&lt;IMG alt="Juergen Meier" border="0" class="jive-avatar" height="30" src="https://community.cisco.com/people/juergen_m1/avatar/30.png?a=-1" width="30" /&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;DIV class="jive-username-link-wrapper"&gt;&lt;EM&gt;2 posts since&lt;/EM&gt;&lt;EM&gt;Sep 28, 2010&lt;/EM&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-thread-reply-body-container"&gt;&lt;DIV class="jive-thread-reply-subject"&gt;&lt;DIV class="jive-thread-reply-date"&gt;&lt;SPAN class="bold"&gt;2.&lt;/SPAN&gt; &lt;SPAN&gt;Jan 17, 2011 5:46 AM&lt;/SPAN&gt; &lt;A href="https://community.cisco.com/message/3257937#3257937" title="in response to: Javier Henderson" target="_blank"&gt;&lt;IMG class="jive-icon-sml jive-icon-arrow-top" src="https://community.cisco.com/images/transparent.png" /&gt;&lt;/A&gt; in response to: &lt;A href="https://community.cisco.com/message/3257937#3257937" title="Go to message" target="_blank"&gt;Javier Henderson&lt;/A&gt;&lt;/DIV&gt;&lt;STRONG&gt;&lt;A href="https://community.cisco.com/message/3271557#3271557" target="_blank"&gt;Also ACS 5.2 (was: ACS 4.2 - LDAP TCP Keepalive)&lt;/A&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class="jive-thread-reply-message"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;Apparently this bug has re-appeared in ACS 5.2 (5.2.0.26). ACS re-uses stale TCP connections many hours after the last TCP packet was sent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It also uses different TCP connections for LDAP search queries and the subsequent authentication bind requests, so sometimes the search query and sometimes the bind request fails due to the TCP connection been timed-out long ago on all network devices (stateful firewalls, IDS/IPS, load balancers) between the ACS and the LDAP servers.&lt;/P&gt;&lt;P&gt;Further ACS fails to detect stale TCP connections and reports bogus authentication failures back to the NAS.&lt;/P&gt;&lt;P&gt;A new ticket will be filed with TAC today.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-content-controls"&gt;&lt;DIV class="jive-controls clearfix"&gt;&lt;DIV class="jive-thread-ratings clearfix" id="jive-thread-ratings-2"&gt;&lt;DIV id="jive-content-rating"&gt;&lt;DIV id="jive-content-userrating"&gt;&lt;DIV class="unrated 3271557 jive-rating-scores" id="jive-content-userrating-score"&gt;&lt;A href="https://community.cisco.com/thread/2059103?decorator=print&amp;amp;displayFullThread=true#" id="jive-icon-userrating-1" title="1: Not Helpful" target="_blank"&gt;ACS 4.2 - LDAP TCP Keepalive&lt;/A&gt;&lt;A href="https://community.cisco.com/thread/2059103?decorator=print&amp;amp;displayFullThread=true#" id="jive-icon-userrating-2" title="2: Somewhat Helpful" target="_blank"&gt;ACS 4.2 - LDAP TCP Keepalive&lt;/A&gt;&lt;A href="https://community.cisco.com/thread/2059103?decorator=print&amp;amp;displayFullThread=true#" id="jive-icon-userrating-3" title="3: Helpful" target="_blank"&gt;ACS 4.2 - LDAP TCP Keepalive&lt;/A&gt;&lt;A href="https://community.cisco.com/thread/2059103?decorator=print&amp;amp;displayFullThread=true#" id="jive-icon-userrating-4" title="4: Very Helpful" target="_blank"&gt;ACS 4.2 - LDAP TCP Keepalive&lt;/A&gt;&lt;A href="https://community.cisco.com/thread/2059103?decorator=print&amp;amp;displayFullThread=true#" id="jive-icon-userrating-5" title="5: Extremely Helpful" target="_blank"&gt;ACS 4.2 - LDAP TCP Keepalive&lt;/A&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV id="jive-content-avgrating"&gt;&lt;DIV id="jive-content-avgrating-score" title="Average User Rating: 0"&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-1"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-2"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-3"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-4"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-5"&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-thread-ratings clearfix" id="jive-thread-ratings-3271557"&gt;&lt;STRONG class="csc-message-rating"&gt;Average Rating: 0 (0 Votes)&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://community.cisco.com/message-abuse!input.jspa?objectID=3271557&amp;amp;objectType=2" target="_blank"&gt;&lt;SPAN class="jive-icon-sml jive-icon-warn"&gt;&lt;/SPAN&gt;Report Abuse&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;A href="https://community.cisco.com/post!reply.jspa?message=3271557" title="Reply to this message" target="_blank"&gt;&lt;SPAN class="jive-icon-sml jive-icon-comment-add"&gt;&lt;/SPAN&gt;Reply&lt;/A&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-reply-indent3 jive-thread-expanded jive-thread-expanded-last jive-message-odd"&gt;&lt;DIV class="jive-thread-reply-indent3"&gt;&lt;DIV class="jive-thread-reply-indent-shadow"&gt;&lt;DIV class="jive-thread-reply jive-thread-reply-self&amp;nbsp; clearfix"&gt;&lt;DIV class="jive-thread-reply-body"&gt;&lt;A name="3293230" target="_blank"&gt;&lt;/A&gt;&lt;DIV class="jive-author"&gt;&lt;DIV class="jive-thread-username"&gt;&lt;A class="jiveTT-hover-user jive-username-link" href="https://community.cisco.com/rob.schieron@analog.com" id="jive-55720548,331,694,239,279,204" target="_blank"&gt;ROB SCHIERON&lt;/A&gt;&lt;/DIV&gt;&lt;SPAN class="jive-author-avatar-container"&gt;&lt;SPAN class="jive-cisco-user-points"&gt;&lt;IMG alt=" " src="https://community.cisco.com/resources/images/status/nostar.gif" title=" " /&gt;&lt;/SPAN&gt;&lt;A class="jiveTT-hover-user" href="https://community.cisco.com/rob.schieron@analog.com" target="_blank"&gt;&lt;IMG alt="ROB SCHIERON" border="0" class="jive-avatar" height="30" src="https://community.cisco.com/people/rob.schieron%40analog.com/avatar/30.png?a=-1" width="30" /&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;DIV class="jive-username-link-wrapper"&gt;&lt;EM&gt;5 posts since&lt;/EM&gt;&lt;EM&gt;Oct 20, 2010&lt;/EM&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-thread-reply-body-container"&gt;&lt;DIV class="jive-thread-reply-subject"&gt;&lt;DIV class="jive-thread-reply-date"&gt;&lt;SPAN class="bold"&gt;3.&lt;/SPAN&gt; &lt;SPAN&gt;Feb 14, 2011 10:29 PM&lt;/SPAN&gt; &lt;A href="https://community.cisco.com/message/3271557#3271557" title="in response to: Juergen Meier" target="_blank"&gt;&lt;IMG class="jive-icon-sml jive-icon-arrow-top" src="https://community.cisco.com/images/transparent.png" /&gt;&lt;/A&gt; in response to: &lt;A href="https://community.cisco.com/message/3271557#3271557" title="Go to message" target="_blank"&gt;Juergen Meier&lt;/A&gt;&lt;/DIV&gt;&lt;STRONG&gt;&lt;A href="https://community.cisco.com/message/3293230#3293230" target="_blank"&gt;Re: Also ACS 5.2 (was: ACS 4.2 - LDAP TCP Keepalive)&lt;/A&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class="jive-thread-reply-message"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;I'm seeing this issue too on 5.2.0.26.1, running LDAP auth through a F5 Load Balancer to a pair of Sun directory servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you make any progress with your TAC case?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Without using the root patch, this command is useful for finding out what is going on (it's just netstat):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# show tech-support | i ldap | i tcp&lt;/P&gt;&lt;P&gt;ldap&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 389/tcp&lt;/P&gt;&lt;P&gt;ldaps&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 636/tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # LDAP over SSL&lt;/P&gt;&lt;P&gt;tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 exc2-acscor-1401:53892&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; acs.ldapunix.co:ldap ESTABLISHED&lt;/P&gt;&lt;P&gt;tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 exc2-acscor-1401:53893&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; acs.ldapunix.co:ldap ESTABLISHED&lt;/P&gt;&lt;P&gt;tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 exc2-acscor-1401:53890&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; acs.ldapunix.co:ldap ESTABLISHED&lt;/P&gt;&lt;P&gt;tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 exc2-acscor-1401:53891&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; acs.ldapunix.co:ldap ESTABLISHED&lt;/P&gt;&lt;P&gt;tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 exc2-acscor-1401:53889&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; acs.ldapunix..co:ldap ESTABLISHED&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Also try adjusting "Max. Admin Connections" for LDAP.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;From the admin guide:&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;P&gt;&lt;EM&gt;LDAP Connection Management&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;ACS 5.1 supports multiple concurrent LDAP connections. Connections are opened on demand at the time of the first LDAP authentication. The maximum number of connections is configured for each LDAP server. Opening connections in advance shortens the authentication time. You can set the maximum number of connections to use for concurrent binding connections. The number of opened connections can be different for each LDAP server (primary or secondary) and is determined according to the maximum number of administration connections configured for each server.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;ACS retains a list of open LDAP connections (including the bind information) for each LDAP server that is configured in ACS. During the authentication process, the connection manager attempts to find an open connection from the pool. If an open connection does not exist, a new one is opened.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;If the LDAP server closed the connection, the connection manager reports an error during the first call to search the directory, and tries to renew the connection.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;After the authentication process is complete, the connection manager releases the connection to the connection manager.&lt;/EM&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;I'd be interested to hear if you have fixed your issue, or if anyone else is facing similar problems load balancing LDAP servers for the ACS.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Cheers&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;R.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 00:49:26 GMT</pubDate>
    <dc:creator>rob.schieron</dc:creator>
    <dc:date>2019-03-11T00:49:26Z</dc:date>
    <item>
      <title>ACS - LDAP TCP Keepalive (v5.2)</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-ldap-tcp-keepalive-v5-2/m-p/1618214#M273558</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;DIV class="jive-thread-post"&gt;&lt;DIV class="jive-thread-post-body clearfix"&gt;&lt;DIV class="jive-thread-post-body-container"&gt;&lt;DIV class="jive-thread-post-message"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;reposting as with subject including v5.2:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an ACS 4.2.1.15 patch 3 and Novell Netware LDAP Server separated by a Firewall. The Firewall's default tcp session timeout is 3600 seconds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When no LDAP-Request is made for over one hour, the Firewall drops the connection from its table. The Problem is, that the ACS-Server thinks the connection is still open. When it tries to send an LDAP-Query this results in retransmissions and finally a RST... On the User side the Authentication attempt fails (timeout).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to enable TCP Keepalives on the Windows-Server side, but this has no effect on the LDAP-Connections used by ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any possibility to enable Keepalives in ACS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for any help!&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-thread-post-details clearfix"&gt;&lt;DIV id="jive-content-avgrating"&gt;&lt;DIV id="jive-content-avgrating-score" title="Average User Rating: 0"&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-1"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-2"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-3"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-4"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-5"&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-thread-ratings clearfix" id="jive-thread-ratings-2,059,103"&gt;&lt;STRONG class="csc-message-rating"&gt;Average Rating: 0 (0 Votes)&lt;/STRONG&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;A href="https://community.cisco.com/post!reply.jspa?thread=2059103" title="Reply to this message" target="_blank"&gt;&lt;SPAN class="jive-icon-sml jive-icon-comment-add"&gt;&lt;/SPAN&gt;Reply&lt;/A&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;A href="https://community.cisco.com/thread/2059103?tstart=0&amp;amp;viewcondensed" target="_blank"&gt;Outline View&lt;/A&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-reply-first jive-reply-indent1 jive-thread-expanded jive-thread-expanded-1 jive-message-odd"&gt;&lt;DIV class="jive-thread-reply-indent1"&gt;&lt;DIV class="jive-thread-reply-indent-shadow"&gt;&lt;DIV class="jive-thread-reply&amp;nbsp; clearfix"&gt;&lt;DIV class="jive-thread-reply-body"&gt;&lt;A name="3257937" target="_blank"&gt;&lt;/A&gt;&lt;DIV class="jive-author"&gt;&lt;DIV class="jive-thread-username"&gt;&lt;A class="jiveTT-hover-user jive-username-link" href="https://community.cisco.com/people/javier" id="jive-50694648,331,694,190,318,204" target="_blank"&gt;Javier Henderson&lt;/A&gt;&lt;/DIV&gt;&lt;SPAN class="jive-author-avatar-container"&gt;&lt;SPAN class="jive-cisco-user-points"&gt;&lt;IMG alt="Employee" src="https://community.cisco.com/resources/images/status/cisco_16x16.gif" title="Employee" /&gt;&lt;/SPAN&gt;&lt;A class="jiveTT-hover-user" href="https://community.cisco.com/people/javier" target="_blank"&gt;&lt;IMG alt="Javier Henderson" border="0" class="jive-avatar" height="30" src="https://community.cisco.com/people/javier/avatar/30.png?a=-1" width="30" /&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;DIV class="jive-username-link-wrapper"&gt;&lt;EM&gt;159 posts since&lt;/EM&gt;&lt;EM&gt;Mar 12, 2010&lt;/EM&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-thread-reply-body-container"&gt;&lt;DIV class="jive-thread-reply-subject"&gt;&lt;DIV class="jive-thread-reply-date"&gt;&lt;SPAN class="bold"&gt;1.&lt;/SPAN&gt; &lt;SPAN&gt;Dec 28, 2010 5:54 PM&lt;/SPAN&gt; &lt;A href="https://community.cisco.com/message/3255519#3255519" title="in response to: Zentraler Informatikdienst" target="_blank"&gt;&lt;IMG class="jive-icon-sml jive-icon-arrow-top" src="https://community.cisco.com/images/transparent.png" /&gt;&lt;/A&gt; in response to: &lt;A href="https://community.cisco.com/message/3255519#3255519" title="Go to message" target="_blank"&gt;Zentraler Informatikdienst&lt;/A&gt;&lt;/DIV&gt;&lt;STRONG&gt;&lt;A href="https://community.cisco.com/message/3257937#3257937" target="_blank"&gt;Re: ACS 4.2 - LDAP TCP Keepalive&lt;/A&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class="jive-thread-reply-message"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;You are seeing the effects of bug CSCti03338 which I filed a few months ago, though it is supposed to be fixed on 4.2.1(15) patch 3. Please open a TAC case so we can look into this in detail.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-content-controls"&gt;&lt;DIV class="jive-controls clearfix"&gt;&lt;DIV class="jive-thread-ratings clearfix" id="jive-thread-ratings-1"&gt;&lt;DIV id="jive-content-rating"&gt;&lt;DIV id="jive-content-userrating"&gt;&lt;DIV class="unrated 3257937 jive-rating-scores" id="jive-content-userrating-score"&gt;&lt;A href="https://community.cisco.com/thread/2059103?decorator=print&amp;amp;displayFullThread=true#" id="jive-icon-userrating-1" title="1: Not Helpful" target="_blank"&gt;ACS 4.2 - LDAP TCP Keepalive&lt;/A&gt;&lt;A href="https://community.cisco.com/thread/2059103?decorator=print&amp;amp;displayFullThread=true#" id="jive-icon-userrating-2" title="2: Somewhat Helpful" target="_blank"&gt;ACS 4.2 - LDAP TCP Keepalive&lt;/A&gt;&lt;A href="https://community.cisco.com/thread/2059103?decorator=print&amp;amp;displayFullThread=true#" id="jive-icon-userrating-3" title="3: Helpful" target="_blank"&gt;ACS 4.2 - LDAP TCP Keepalive&lt;/A&gt;&lt;A href="https://community.cisco.com/thread/2059103?decorator=print&amp;amp;displayFullThread=true#" id="jive-icon-userrating-4" title="4: Very Helpful" target="_blank"&gt;ACS 4.2 - LDAP TCP Keepalive&lt;/A&gt;&lt;A href="https://community.cisco.com/thread/2059103?decorator=print&amp;amp;displayFullThread=true#" id="jive-icon-userrating-5" title="5: Extremely Helpful" target="_blank"&gt;ACS 4.2 - LDAP TCP Keepalive&lt;/A&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV id="jive-content-avgrating"&gt;&lt;DIV id="jive-content-avgrating-score" title="Average User Rating: 0"&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-1"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-2"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-3"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-4"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-5"&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-thread-ratings clearfix" id="jive-thread-ratings-3257937"&gt;&lt;STRONG class="csc-message-rating"&gt;Average Rating: 0 (0 Votes)&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://community.cisco.com/message-abuse!input.jspa?objectID=3257937&amp;amp;objectType=2" target="_blank"&gt;&lt;SPAN class="jive-icon-sml jive-icon-warn"&gt;&lt;/SPAN&gt;Report Abuse&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;A href="https://community.cisco.com/post!reply.jspa?message=3257937" title="Reply to this message" target="_blank"&gt;&lt;SPAN class="jive-icon-sml jive-icon-comment-add"&gt;&lt;/SPAN&gt;Reply&lt;/A&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-reply-indent2 jive-thread-expanded jive-thread-expanded-2 jive-message-even"&gt;&lt;DIV class="jive-thread-reply-indent2"&gt;&lt;DIV class="jive-thread-reply-indent-shadow"&gt;&lt;DIV class="jive-thread-reply jive-thread-reply-alt&amp;nbsp; clearfix"&gt;&lt;DIV class="jive-thread-reply-body"&gt;&lt;A name="3271557" target="_blank"&gt;&lt;/A&gt;&lt;DIV class="jive-author"&gt;&lt;DIV class="jive-thread-username"&gt;&lt;A class="jiveTT-hover-user jive-username-link" href="https://community.cisco.com/people/juergen_m1" id="jive-55460948,331,694,212,815,204" target="_blank"&gt;Juergen Meier&lt;/A&gt;&lt;/DIV&gt;&lt;SPAN class="jive-author-avatar-container"&gt;&lt;SPAN class="jive-cisco-user-points"&gt;&lt;IMG alt=" " src="https://community.cisco.com/resources/images/status/nostar.gif" title=" " /&gt;&lt;/SPAN&gt;&lt;A class="jiveTT-hover-user" href="https://community.cisco.com/people/juergen_m1" target="_blank"&gt;&lt;IMG alt="Juergen Meier" border="0" class="jive-avatar" height="30" src="https://community.cisco.com/people/juergen_m1/avatar/30.png?a=-1" width="30" /&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;DIV class="jive-username-link-wrapper"&gt;&lt;EM&gt;2 posts since&lt;/EM&gt;&lt;EM&gt;Sep 28, 2010&lt;/EM&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-thread-reply-body-container"&gt;&lt;DIV class="jive-thread-reply-subject"&gt;&lt;DIV class="jive-thread-reply-date"&gt;&lt;SPAN class="bold"&gt;2.&lt;/SPAN&gt; &lt;SPAN&gt;Jan 17, 2011 5:46 AM&lt;/SPAN&gt; &lt;A href="https://community.cisco.com/message/3257937#3257937" title="in response to: Javier Henderson" target="_blank"&gt;&lt;IMG class="jive-icon-sml jive-icon-arrow-top" src="https://community.cisco.com/images/transparent.png" /&gt;&lt;/A&gt; in response to: &lt;A href="https://community.cisco.com/message/3257937#3257937" title="Go to message" target="_blank"&gt;Javier Henderson&lt;/A&gt;&lt;/DIV&gt;&lt;STRONG&gt;&lt;A href="https://community.cisco.com/message/3271557#3271557" target="_blank"&gt;Also ACS 5.2 (was: ACS 4.2 - LDAP TCP Keepalive)&lt;/A&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class="jive-thread-reply-message"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;Apparently this bug has re-appeared in ACS 5.2 (5.2.0.26). ACS re-uses stale TCP connections many hours after the last TCP packet was sent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It also uses different TCP connections for LDAP search queries and the subsequent authentication bind requests, so sometimes the search query and sometimes the bind request fails due to the TCP connection been timed-out long ago on all network devices (stateful firewalls, IDS/IPS, load balancers) between the ACS and the LDAP servers.&lt;/P&gt;&lt;P&gt;Further ACS fails to detect stale TCP connections and reports bogus authentication failures back to the NAS.&lt;/P&gt;&lt;P&gt;A new ticket will be filed with TAC today.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-content-controls"&gt;&lt;DIV class="jive-controls clearfix"&gt;&lt;DIV class="jive-thread-ratings clearfix" id="jive-thread-ratings-2"&gt;&lt;DIV id="jive-content-rating"&gt;&lt;DIV id="jive-content-userrating"&gt;&lt;DIV class="unrated 3271557 jive-rating-scores" id="jive-content-userrating-score"&gt;&lt;A href="https://community.cisco.com/thread/2059103?decorator=print&amp;amp;displayFullThread=true#" id="jive-icon-userrating-1" title="1: Not Helpful" target="_blank"&gt;ACS 4.2 - LDAP TCP Keepalive&lt;/A&gt;&lt;A href="https://community.cisco.com/thread/2059103?decorator=print&amp;amp;displayFullThread=true#" id="jive-icon-userrating-2" title="2: Somewhat Helpful" target="_blank"&gt;ACS 4.2 - LDAP TCP Keepalive&lt;/A&gt;&lt;A href="https://community.cisco.com/thread/2059103?decorator=print&amp;amp;displayFullThread=true#" id="jive-icon-userrating-3" title="3: Helpful" target="_blank"&gt;ACS 4.2 - LDAP TCP Keepalive&lt;/A&gt;&lt;A href="https://community.cisco.com/thread/2059103?decorator=print&amp;amp;displayFullThread=true#" id="jive-icon-userrating-4" title="4: Very Helpful" target="_blank"&gt;ACS 4.2 - LDAP TCP Keepalive&lt;/A&gt;&lt;A href="https://community.cisco.com/thread/2059103?decorator=print&amp;amp;displayFullThread=true#" id="jive-icon-userrating-5" title="5: Extremely Helpful" target="_blank"&gt;ACS 4.2 - LDAP TCP Keepalive&lt;/A&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV id="jive-content-avgrating"&gt;&lt;DIV id="jive-content-avgrating-score" title="Average User Rating: 0"&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-1"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-2"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-3"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-4"&gt;&lt;/SPAN&gt;&lt;SPAN class="jive-icon-med jive-icon-rate-avg-off" id="jive-icon-avgrating-5"&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-thread-ratings clearfix" id="jive-thread-ratings-3271557"&gt;&lt;STRONG class="csc-message-rating"&gt;Average Rating: 0 (0 Votes)&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://community.cisco.com/message-abuse!input.jspa?objectID=3271557&amp;amp;objectType=2" target="_blank"&gt;&lt;SPAN class="jive-icon-sml jive-icon-warn"&gt;&lt;/SPAN&gt;Report Abuse&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;A href="https://community.cisco.com/post!reply.jspa?message=3271557" title="Reply to this message" target="_blank"&gt;&lt;SPAN class="jive-icon-sml jive-icon-comment-add"&gt;&lt;/SPAN&gt;Reply&lt;/A&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-reply-indent3 jive-thread-expanded jive-thread-expanded-last jive-message-odd"&gt;&lt;DIV class="jive-thread-reply-indent3"&gt;&lt;DIV class="jive-thread-reply-indent-shadow"&gt;&lt;DIV class="jive-thread-reply jive-thread-reply-self&amp;nbsp; clearfix"&gt;&lt;DIV class="jive-thread-reply-body"&gt;&lt;A name="3293230" target="_blank"&gt;&lt;/A&gt;&lt;DIV class="jive-author"&gt;&lt;DIV class="jive-thread-username"&gt;&lt;A class="jiveTT-hover-user jive-username-link" href="https://community.cisco.com/rob.schieron@analog.com" id="jive-55720548,331,694,239,279,204" target="_blank"&gt;ROB SCHIERON&lt;/A&gt;&lt;/DIV&gt;&lt;SPAN class="jive-author-avatar-container"&gt;&lt;SPAN class="jive-cisco-user-points"&gt;&lt;IMG alt=" " src="https://community.cisco.com/resources/images/status/nostar.gif" title=" " /&gt;&lt;/SPAN&gt;&lt;A class="jiveTT-hover-user" href="https://community.cisco.com/rob.schieron@analog.com" target="_blank"&gt;&lt;IMG alt="ROB SCHIERON" border="0" class="jive-avatar" height="30" src="https://community.cisco.com/people/rob.schieron%40analog.com/avatar/30.png?a=-1" width="30" /&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;DIV class="jive-username-link-wrapper"&gt;&lt;EM&gt;5 posts since&lt;/EM&gt;&lt;EM&gt;Oct 20, 2010&lt;/EM&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="jive-thread-reply-body-container"&gt;&lt;DIV class="jive-thread-reply-subject"&gt;&lt;DIV class="jive-thread-reply-date"&gt;&lt;SPAN class="bold"&gt;3.&lt;/SPAN&gt; &lt;SPAN&gt;Feb 14, 2011 10:29 PM&lt;/SPAN&gt; &lt;A href="https://community.cisco.com/message/3271557#3271557" title="in response to: Juergen Meier" target="_blank"&gt;&lt;IMG class="jive-icon-sml jive-icon-arrow-top" src="https://community.cisco.com/images/transparent.png" /&gt;&lt;/A&gt; in response to: &lt;A href="https://community.cisco.com/message/3271557#3271557" title="Go to message" target="_blank"&gt;Juergen Meier&lt;/A&gt;&lt;/DIV&gt;&lt;STRONG&gt;&lt;A href="https://community.cisco.com/message/3293230#3293230" target="_blank"&gt;Re: Also ACS 5.2 (was: ACS 4.2 - LDAP TCP Keepalive)&lt;/A&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class="jive-thread-reply-message"&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;I'm seeing this issue too on 5.2.0.26.1, running LDAP auth through a F5 Load Balancer to a pair of Sun directory servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you make any progress with your TAC case?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Without using the root patch, this command is useful for finding out what is going on (it's just netstat):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# show tech-support | i ldap | i tcp&lt;/P&gt;&lt;P&gt;ldap&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 389/tcp&lt;/P&gt;&lt;P&gt;ldaps&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 636/tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # LDAP over SSL&lt;/P&gt;&lt;P&gt;tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 exc2-acscor-1401:53892&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; acs.ldapunix.co:ldap ESTABLISHED&lt;/P&gt;&lt;P&gt;tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 exc2-acscor-1401:53893&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; acs.ldapunix.co:ldap ESTABLISHED&lt;/P&gt;&lt;P&gt;tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 exc2-acscor-1401:53890&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; acs.ldapunix.co:ldap ESTABLISHED&lt;/P&gt;&lt;P&gt;tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 exc2-acscor-1401:53891&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; acs.ldapunix.co:ldap ESTABLISHED&lt;/P&gt;&lt;P&gt;tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 exc2-acscor-1401:53889&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; acs.ldapunix..co:ldap ESTABLISHED&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Also try adjusting "Max. Admin Connections" for LDAP.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;From the admin guide:&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;P&gt;&lt;EM&gt;LDAP Connection Management&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;ACS 5.1 supports multiple concurrent LDAP connections. Connections are opened on demand at the time of the first LDAP authentication. The maximum number of connections is configured for each LDAP server. Opening connections in advance shortens the authentication time. You can set the maximum number of connections to use for concurrent binding connections. The number of opened connections can be different for each LDAP server (primary or secondary) and is determined according to the maximum number of administration connections configured for each server.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;ACS retains a list of open LDAP connections (including the bind information) for each LDAP server that is configured in ACS. During the authentication process, the connection manager attempts to find an open connection from the pool. If an open connection does not exist, a new one is opened.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;If the LDAP server closed the connection, the connection manager reports an error during the first call to search the directory, and tries to renew the connection.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;After the authentication process is complete, the connection manager releases the connection to the connection manager.&lt;/EM&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;I'd be interested to hear if you have fixed your issue, or if anyone else is facing similar problems load balancing LDAP servers for the ACS.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Cheers&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;R.&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:49:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-ldap-tcp-keepalive-v5-2/m-p/1618214#M273558</guid>
      <dc:creator>rob.schieron</dc:creator>
      <dc:date>2019-03-11T00:49:26Z</dc:date>
    </item>
  </channel>
</rss>

