<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Secure ACS Intermittent in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697584#M421636</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With 3.x there was a way to tweak ACS but with 4.x you will have to open a TAC case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vivek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Feb 2007 10:31:23 GMT</pubDate>
    <dc:creator>Vivek Santuka</dc:creator>
    <dc:date>2007-02-22T10:31:23Z</dc:date>
    <item>
      <title>Secure ACS Intermittent</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697576#M421628</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using Cisco Secure ACS and for the past week, our switch and router logins are really really intermittent. Most of the time, even if we are into the console already and issue a command, "authorization failed" will appear then just keep pressing up and enter then the command will be accepted. Any idea why is this happening? Thank you very much.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:59:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697576#M421628</guid>
      <dc:creator>jpl861</dc:creator>
      <dc:date>2019-03-10T21:59:17Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ACS Intermittent</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697577#M421629</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could try looking in the in failed attempts report. This would be a good place to start.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Feb 2007 11:36:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697577#M421629</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2007-02-15T11:36:58Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ACS Intermittent</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697578#M421630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One more thing which is worth trying is to increase the tacacs-server timeout value.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vivek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Feb 2007 12:07:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697578#M421630</guid>
      <dc:creator>Vivek Santuka</dc:creator>
      <dc:date>2007-02-15T12:07:16Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ACS Intermittent</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697579#M421631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;we have the same problem in our network. Commands entered rapidly first work fine but after a period of time the commands are rejected - "authorization failed". With an increased "tacacs timeout" the message "authorization failed" doesn't appear anymore. as a result the tacacs queue increases and the switch or router has a faint response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The accepted commands are listed in the "TACACS+ administration" log - as assumed. But the rejected commands don't appear in any log...what's the problem?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2007 07:30:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697579#M421631</guid>
      <dc:creator>smue_decm</dc:creator>
      <dc:date>2007-02-22T07:30:39Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ACS Intermittent</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697580#M421632</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you tried running a constant ping from the device to the ACS server? Is there something that is dropping packets along the path (ie from congestion or something)?  What version of ACS are you running?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2007 08:11:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697580#M421632</guid>
      <dc:creator>ellis_b</dc:creator>
      <dc:date>2007-02-22T08:11:11Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ACS Intermittent</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697581#M421633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're using ACS 4.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The network's fine. We tested connectivity from a switch within our LAN AND over many hops from other devices in the network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2007 09:04:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697581#M421633</guid>
      <dc:creator>smue_decm</dc:creator>
      <dc:date>2007-02-22T09:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ACS Intermittent</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697582#M421634</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can try adding "single-connection" keyword after the "tacacs-server host" command in the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The single-connection keyword specifies a single connection (only valid with ACS). Rather than have the router open and close a TCP connection to the server each time it must communicate, the single-connection option maintains a single open connection between the router and the server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The single connection is more efficient because it allows the server to handle a higher number of TACACS operations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vivek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2007 09:40:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697582#M421634</guid>
      <dc:creator>Vivek Santuka</dc:creator>
      <dc:date>2007-02-22T09:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ACS Intermittent</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697583#M421635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this works better now. But still, after several tries the entered commands end up in a queue...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any possiblity without reconfiguring a switch or router?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2007 10:25:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697583#M421635</guid>
      <dc:creator>smue_decm</dc:creator>
      <dc:date>2007-02-22T10:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ACS Intermittent</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697584#M421636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With 3.x there was a way to tweak ACS but with 4.x you will have to open a TAC case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vivek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2007 10:31:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697584#M421636</guid>
      <dc:creator>Vivek Santuka</dc:creator>
      <dc:date>2007-02-22T10:31:23Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ACS Intermittent</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697585#M421637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hmmm.. how many concurrent admin sessions might be performing T+ authorisation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This could be ACS running out of spare connections. You'd see no errors in the ACS CSV, but you might see something in the CSTacacs service log. It really should log if connections/packets are being dropped.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2007 11:51:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697585#M421637</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2007-02-22T11:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ACS Intermittent</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697586#M421641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Infact not only concurrent authorization session but accounting sessions also matter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS can handle limited number of concurrent tacacs sessions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2007 12:32:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697586#M421641</guid>
      <dc:creator>Vivek Santuka</dc:creator>
      <dc:date>2007-02-22T12:32:55Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ACS Intermittent</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697587#M421645</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ACS appliance doesn't reply to ping packets. We are using ACS 3.3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sometimes we have to type our username and password again and again because the ACS is not responding. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can the timeout resolve this issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much guys. &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2007 13:21:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697587#M421645</guid>
      <dc:creator>jpl861</dc:creator>
      <dc:date>2007-02-22T13:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ACS Intermittent</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697588#M421649</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very interesting indeed, do you have that magic number as I'm experiencing that same issue too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only figures that I've found documented are from 3.2 and only for 800 AP's and 100K users (how artificially they derived this synthetic info is questionable but Dewan the Product Manager for Cisco Wireless was kinda quiet about it)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2007 13:23:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697588#M421649</guid>
      <dc:creator>akemp</dc:creator>
      <dc:date>2007-02-22T13:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ACS Intermittent</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697589#M421653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your thoughts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How many tacacs sessions can acs handle?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2007 13:48:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697589#M421653</guid>
      <dc:creator>smue_decm</dc:creator>
      <dc:date>2007-02-22T13:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ACS Intermittent</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697590#M421656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If I am not wrong Tacacs+ threads hover around a maximum of 50.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vivek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2007 13:53:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697590#M421656</guid>
      <dc:creator>Vivek Santuka</dc:creator>
      <dc:date>2007-02-22T13:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ACS Intermittent</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697591#M421658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS Solution enginer will not reply to ping if CSA Agent is enabled. (System Configuration-&amp;gt;Appliance Configuration)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Increasing timeout is not always the answer but is a good first step in identifying the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We could be experiencing a delay from the external db or even from remote logging facility. All these and more would contribute to a delay is authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS running out of threads is not a common thing and not seen often.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Auth.log would be a very good place to look for problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vivek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2007 14:03:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697591#M421658</guid>
      <dc:creator>Vivek Santuka</dc:creator>
      <dc:date>2007-02-22T14:03:40Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ACS Intermittent</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697592#M421659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Vivek,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;our test-switch is now configured with:&lt;/P&gt;&lt;P&gt;tacas-server host [ip] single-connection&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we're testing the following way:&lt;/P&gt;&lt;P&gt;- log in&lt;/P&gt;&lt;P&gt;- send a cmd (for example: show tacacs) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with "single-connection" on, we have to send a command very often to reproduce the queue and the "authorisation failed"-message - without "single-connection" it was worse.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now we're comparing the number of requests in auth.log with the number of commands that the aaa client sent. it seems to us that there are no dropped requests in auth.log - just "Start RQ****" and "Done RQ****".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we'll keep you posted.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2007 14:25:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697592#M421659</guid>
      <dc:creator>smue_decm</dc:creator>
      <dc:date>2007-02-22T14:25:24Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ACS Intermittent</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697593#M421660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest setting the Log level to full (system configuration-&amp;gt;Service control) while testing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vivek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2007 14:37:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697593#M421660</guid>
      <dc:creator>Vivek Santuka</dc:creator>
      <dc:date>2007-02-22T14:37:29Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ACS Intermittent</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697594#M421661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vivek,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;our log level was, and still is, set to full.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Feb 2007 09:53:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697594#M421661</guid>
      <dc:creator>smue_decm</dc:creator>
      <dc:date>2007-02-23T09:53:07Z</dc:date>
    </item>
    <item>
      <title>Re: Secure ACS Intermittent</title>
      <link>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697595#M421662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;how many single-connections does a acs server handle? &lt;/P&gt;&lt;P&gt;Is there a limit? If so, could this limit be configured?&lt;/P&gt;&lt;P&gt;Can the active single-connections be monitored (how many open connections at a/one time?)&lt;/P&gt;&lt;P&gt;Is it possible to shut down active single-connections?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Feb 2007 10:32:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/secure-acs-intermittent/m-p/697595#M421662</guid>
      <dc:creator>smue_decm</dc:creator>
      <dc:date>2007-02-23T10:32:26Z</dc:date>
    </item>
  </channel>
</rss>

