<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic limitations of Cisco ACS server in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/limitations-of-cisco-acs-server/m-p/599481#M426647</link>
    <description>&lt;P&gt;I want to ask about limitations of Cisco ACS server 3.3 . &lt;/P&gt;&lt;P&gt;I use ACS server for Radius authentication, and has a limit 80 authentications per second. But at peak time i need 150-200 authentications per second. Is this a software limitaion or changed due to hardware performance?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can i also solve this problem with a High Availability configuration.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 21:42:44 GMT</pubDate>
    <dc:creator>kayihanaltinoz</dc:creator>
    <dc:date>2019-03-10T21:42:44Z</dc:date>
    <item>
      <title>limitations of Cisco ACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/limitations-of-cisco-acs-server/m-p/599481#M426647</link>
      <description>&lt;P&gt;I want to ask about limitations of Cisco ACS server 3.3 . &lt;/P&gt;&lt;P&gt;I use ACS server for Radius authentication, and has a limit 80 authentications per second. But at peak time i need 150-200 authentications per second. Is this a software limitaion or changed due to hardware performance?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can i also solve this problem with a High Availability configuration.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:42:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limitations-of-cisco-acs-server/m-p/599481#M426647</guid>
      <dc:creator>kayihanaltinoz</dc:creator>
      <dc:date>2019-03-10T21:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: limitations of Cisco ACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/limitations-of-cisco-acs-server/m-p/599482#M426648</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS performance is a very complex issue and depends largely on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) auth protocol (anything eap is SLOW)&lt;/P&gt;&lt;P&gt;2) backend (anything external is SLOW)&lt;/P&gt;&lt;P&gt;3) server CPU&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We did some performance tests a few years ago and could get up to 1000 auths/sec for MSCHAP against internal DB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AD authentication/group mapping can take several seconds to complete.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACSs big problem is limited concurrency when authentication time is high. There are some bottlenecks that effectively limit the number of concurrent authentications to 20. This is the max number of tcp/ip connections between CSRadius/CSTacacs and CSAuth. Inside CSRadius there are 50 dedicated authentication threads multiplexing requests over the 20 tcp/ip connections to CSauth. Messages to CSauth are blocking - so 20 simultaneous authentications that took 1 second would cap performance to 20 auths/sec.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EAP-TLS and now EAP-FAST are really really slow becase they send multiple rounds over RADIUS using challenge/response marshalled between the device and the 802.1x supplicant.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Putting ACS onto a quad CPU server wont reduce back-end external db latency or increase concurrency.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only way to increase performance is to add more servers... and then you'll also have to get into load balancing &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IMHO Cisco needs to make a low cost "ACS on a blade" and have one in each device. Have the config pushed down from a central database. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Darran&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Aug 2006 08:59:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/limitations-of-cisco-acs-server/m-p/599482#M426648</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2006-08-15T08:59:26Z</dc:date>
    </item>
  </channel>
</rss>

