<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS and Load Balancer in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-and-load-balancer/m-p/1170406#M344991</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your answer. normally we are working with f5 load balancers. so it should also work with them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bye&lt;/P&gt;&lt;P&gt;Torsten&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 Feb 2009 07:47:50 GMT</pubDate>
    <dc:creator>t.waibel</dc:creator>
    <dc:date>2009-02-24T07:47:50Z</dc:date>
    <item>
      <title>ACS and Load Balancer</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-and-load-balancer/m-p/1170404#M344937</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we want to rebuilt our design. In the future we want to have 4 ACS server behind a pair of load balancer. Does anybody knows whether the ASC server works with a load balancer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your answers.&lt;/P&gt;&lt;P&gt;Torsten Waibel&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:20:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-and-load-balancer/m-p/1170404#M344937</guid>
      <dc:creator>t.waibel</dc:creator>
      <dc:date>2019-03-10T23:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and Load Balancer</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-and-load-balancer/m-p/1170405#M344955</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it does! We will be deploying 4 ACS servers behind an ACE shortly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Feb 2009 17:23:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-and-load-balancer/m-p/1170405#M344955</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2009-02-23T17:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and Load Balancer</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-and-load-balancer/m-p/1170406#M344991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your answer. normally we are working with f5 load balancers. so it should also work with them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bye&lt;/P&gt;&lt;P&gt;Torsten&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Feb 2009 07:47:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-and-load-balancer/m-p/1170406#M344991</guid>
      <dc:creator>t.waibel</dc:creator>
      <dc:date>2009-02-24T07:47:50Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and Load Balancer</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-and-load-balancer/m-p/1170407#M345003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What might not be immediately obvious is that some protocols will load balance better than others.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most LBs use a "sticky" timer to ensure that multi-message authentication exchanges (like EAP) will get routed to the same ACS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thats OK, but sticky timers are normally measured in seconds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS may keep 802.1x/SSL session state for hours with supplicants performing periodic re-keying over the session lifetime. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A worst case example: a wireless lan secured using a one-time password like RSA. If a periodic rekey goes to the wrong ACS (that doesnt hold the session state) it will trigger a new full authentication and result in the user having to dig out their RSA token again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just something to bear in mind.. the sticky timer needs to be as long as the re-key/re-authenticate time.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Feb 2009 10:06:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-and-load-balancer/m-p/1170407#M345003</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2009-02-25T10:06:03Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and Load Balancer</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-and-load-balancer/m-p/1170408#M345022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks darpotter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we use the ACS server only for TACACS and RADIUS Authentication, Authorization and Accounting. So we need to know whether a f5 load balancer will work together with 4 ACS server. Will the load balancer distribute the requests from one router round robin to all ACS server or will only one ACS server be responsible for the requests from a router.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Feb 2009 10:16:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-and-load-balancer/m-p/1170408#M345022</guid>
      <dc:creator>t.waibel</dc:creator>
      <dc:date>2009-02-25T10:16:14Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and Load Balancer</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-and-load-balancer/m-p/1170409#M345040</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good point, we sticky by source IP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Feb 2009 14:14:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-and-load-balancer/m-p/1170409#M345040</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2009-02-26T14:14:36Z</dc:date>
    </item>
  </channel>
</rss>

