<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS redudancy in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117517#M436506</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, next things to check is whether the secondary TACACS server is realy setup correctly. You have authorization configured, check on the ACS that the EXEC is selected. Try to match the settings with those of the working server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ohter thing to check is to see that all the ACS services are indeed running on that server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this still doesn't resolve the issue, please send the 'sh ver' for the router and take a look at the details in the package.cab file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;yatin &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 03 Jun 2003 11:52:06 GMT</pubDate>
    <dc:creator>ywadhavk</dc:creator>
    <dc:date>2003-06-03T11:52:06Z</dc:date>
    <item>
      <title>ACS redudancy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117513#M436502</link>
      <description>&lt;P&gt;Greetings all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am tryin to configure an ACS redudancy model in our routers. We have 2 ACS servers runnin on W2K. In the router configuration I've made an "aaa group server tacacs+ test" and denoted our 2 ACS server from the global config.&lt;/P&gt;&lt;P&gt;However, when I shutdown the first ACS server, the whole thing don't work and I get a strange error from the debug (see bellow).&lt;/P&gt;&lt;P&gt;Bellow is a snap-shot from the config just in case a left something out.&lt;/P&gt;&lt;P&gt;Has anyone implement this ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanx in advance,&lt;/P&gt;&lt;P&gt;Kostas&lt;/P&gt;&lt;P&gt;-----------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server tacacs+ TEST&lt;/P&gt;&lt;P&gt; server 10.10.10.1&lt;/P&gt;&lt;P&gt; server 10.10.10.2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login telnet group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication login aux local&lt;/P&gt;&lt;P&gt;aaa authentication login console local&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ local &lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;tacacs-server host 10.10.10.1 key tes1t&lt;/P&gt;&lt;P&gt;tacacs-server host 10.10.10.2 key tes2t&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt; login authentication console&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt; login authentication aux&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; login authentication telnet&lt;/P&gt;&lt;P&gt; transport input telnet&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;-----------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug-error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jun  2 13:04:31.611: TPLUS: Queuing AAA Authentication request 12951 for processing&lt;/P&gt;&lt;P&gt;Jun  2 13:04:31.611: TPLUS: processing authentication start request id 12951&lt;/P&gt;&lt;P&gt;Jun  2 13:04:31.611: TPLUS: Authentication start packet created for 12951()&lt;/P&gt;&lt;P&gt;Jun  2 13:04:31.611: TPLUS: Using server 10.10.10.1&lt;/P&gt;&lt;P&gt;Jun  2 13:04:31.615: TPLUS(00003297): Select released but nopeername.. Failover&lt;/P&gt;&lt;P&gt;Jun  2 13:04:31.615: TPLUS: Choosing next server: 10.10.10.2&lt;/P&gt;&lt;P&gt;Jun  2 13:04:36.616: TPLUS(00003297): Select Timed out&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:19:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117513#M436502</guid>
      <dc:creator>-kostas-</dc:creator>
      <dc:date>2019-03-10T14:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: ACS redudancy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117514#M436503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since you have a tacacs group defined, you should change your aaa authen statement to select that group name rather then the tacacs+ keyword.  i.e.:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login telnet group TEST local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps...&lt;/P&gt;&lt;P&gt;Marcus&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jun 2003 12:53:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117514#M436503</guid>
      <dc:creator>msitzman</dc:creator>
      <dc:date>2003-06-02T12:53:11Z</dc:date>
    </item>
    <item>
      <title>Re: ACS redudancy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117515#M436504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Couple of things to check;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. At the router, run the below test command to test the TACACS operation;&lt;/P&gt;&lt;P&gt;    test aaa group tacacs username password   &lt;/P&gt;&lt;P&gt;    for e.g test aaa group tacacs cisco cisco&lt;/P&gt;&lt;P&gt;2. Try to bump up the tacacs timeout value from the default 5 sec to 10 sec.&lt;/P&gt;&lt;P&gt;3. What is the version of the IOS? There could be a bug associated.   &lt;/P&gt;&lt;P&gt;     CSCdx41454&lt;/P&gt;&lt;P&gt;4. Are you using the command&lt;/P&gt;&lt;P&gt;    ip tacacs source-interface &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;yatin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jun 2003 12:56:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117515#M436504</guid>
      <dc:creator>ywadhavk</dc:creator>
      <dc:date>2003-06-02T12:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: ACS redudancy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117516#M436505</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well I did all these things but no luck.&lt;/P&gt;&lt;P&gt;I checked for the bug id. The thing is that I am not using ip tacacs-source interface loopback 0 on my router that I have for testing reasons. I have a single FastEth, and this is what I have also configured in the ACS server.&lt;/P&gt;&lt;P&gt;Any more ideas ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Kostas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2003 06:53:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117516#M436505</guid>
      <dc:creator>-kostas-</dc:creator>
      <dc:date>2003-06-03T06:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: ACS redudancy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117517#M436506</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, next things to check is whether the secondary TACACS server is realy setup correctly. You have authorization configured, check on the ACS that the EXEC is selected. Try to match the settings with those of the working server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ohter thing to check is to see that all the ACS services are indeed running on that server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this still doesn't resolve the issue, please send the 'sh ver' for the router and take a look at the details in the package.cab file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;yatin &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2003 11:52:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117517#M436506</guid>
      <dc:creator>ywadhavk</dc:creator>
      <dc:date>2003-06-03T11:52:06Z</dc:date>
    </item>
    <item>
      <title>Re: ACS redudancy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117518#M436507</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yatin,&lt;/P&gt;&lt;P&gt;Well, the secondary TACACS is working properly. I configured the router first only with the main TACACS, then only with the secondary, and they both worked well.&lt;/P&gt;&lt;P&gt;Only the redudancy model doesn't seem to work.&lt;/P&gt;&lt;P&gt;The IOS is 12.1.(3)T1.&lt;/P&gt;&lt;P&gt;What I don't understand is the thing about the package.cab file.&lt;/P&gt;&lt;P&gt;Could you please explain ?&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;/kostas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2003 12:06:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117518#M436507</guid>
      <dc:creator>-kostas-</dc:creator>
      <dc:date>2003-06-03T12:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: ACS redudancy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117519#M436508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kostas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What if you reverse the order of the tacacs server from&lt;/P&gt;&lt;P&gt;tacacs-server host 10.10.10.1 key tes1t &lt;/P&gt;&lt;P&gt;tacacs-server host 10.10.10.2 key tes2t &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to&lt;/P&gt;&lt;P&gt;tacacs-server host 10.10.10.2 key tes1t &lt;/P&gt;&lt;P&gt;tacacs-server host 10.10.10.1 key tes2t &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for the package.cab file, here's the procedure; looks lengthy but it is simple.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Follow these instructions even if your server is already running in detailed logging mode.  This&lt;/P&gt;&lt;P&gt; will ensure that all the proper service startup information is included in the package.cab file. &lt;/P&gt;&lt;P&gt;If&lt;/P&gt;&lt;P&gt; these instructions are not followed properly, we will need to request the information again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; - Log onto the ACS server itself as the local administrator.&lt;/P&gt;&lt;P&gt; - Browse to the UTILS directory in the ACS program directory.&lt;/P&gt;&lt;P&gt; - Run the program there called CSSupport.&lt;/P&gt;&lt;P&gt; - Select "Set Log Levels Only" and click Next.&lt;/P&gt;&lt;P&gt; - Select "Set Diagnostic Log Verbosity to Maximum."&lt;/P&gt;&lt;P&gt; - Check "Keep TACACS+ Packet Capture."&lt;/P&gt;&lt;P&gt; - Check "Keep RADIUS Packet Capture."&lt;/P&gt;&lt;P&gt; - Click Next, then click Finish.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; At this point we need to duplicate the issue.  Do whatever is causing the problem, or wait for the&lt;/P&gt;&lt;P&gt; problem to occur again if it's not triggered by a direct sequence of events.  Once that's done, we&lt;/P&gt;&lt;P&gt; need to gather the verbose logs created.  To do so, follow the instructions below AFTER the problem&lt;/P&gt;&lt;P&gt; has been recreated and recorded:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; - Log onto the ACS server itself as the local administrator.&lt;/P&gt;&lt;P&gt; - Browse to the UTILS directory in the ACS program directory.&lt;/P&gt;&lt;P&gt; - Run the program there called CSSupport.&lt;/P&gt;&lt;P&gt; - Select "Run Wizard" and click Next.&lt;/P&gt;&lt;P&gt; - If we need more than today's logs:&lt;/P&gt;&lt;P&gt; -- Put a check in both "Previous Logs" checkbox.&lt;/P&gt;&lt;P&gt; -- Select the number of days to go back.&lt;/P&gt;&lt;P&gt; - Click Next four times.&lt;/P&gt;&lt;P&gt; - When the Finish button appears, click it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; The package.cab will be found in the UTILS\Support directory under the ACS program directory.  This&lt;/P&gt;&lt;P&gt; file contains all of the log information from ACS and limited information about the computer that&lt;/P&gt;&lt;P&gt; ACS is running on.  All collected information is essential for proper troubleshooting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Jun 2003 13:10:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117519#M436508</guid>
      <dc:creator>ywadhavk</dc:creator>
      <dc:date>2003-06-03T13:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: ACS redudancy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117520#M436509</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello again,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, I did reversed the TACACS servers in my routers but that didn't solved anything.&lt;/P&gt;&lt;P&gt;Once again let me give a short discription to what I am doing.&lt;/P&gt;&lt;P&gt;Configure 2 ACS servers in my routers.&lt;/P&gt;&lt;P&gt;After a successfully login with the primary server, I shutdown it (the primary ACS) and try to login with me secondary ACS. And there where is my problem.&lt;/P&gt;&lt;P&gt;I also tried two methods. The first is to simply add the ACS servers in the global config and the other, after putting them in global config also putting them in "aaa server group tacacs TEST" and change the aaa authentication, authorasation, properly. None of these worked.&lt;/P&gt;&lt;P&gt;Now for the package.cab, I produced. Which of the files is necessary for you and where can I sent them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kostas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jun 2003 09:13:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117520#M436509</guid>
      <dc:creator>-kostas-</dc:creator>
      <dc:date>2003-06-04T09:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: ACS redudancy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117521#M436510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kostas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Failed Attempts csv and the tcs.log would be a good starting point. How about the ACS services on this server? Are they all running fine? Has this server even once authenticated a login properly? What you need to confirm is that the server is functioning properly as a primary server. That's why I asked to put this server as the first entry.&lt;/P&gt;&lt;P&gt;What was the result of the "aaa test ......" command?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;yatin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Jun 2003 12:43:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117521#M436510</guid>
      <dc:creator>ywadhavk</dc:creator>
      <dc:date>2003-06-04T12:43:54Z</dc:date>
    </item>
    <item>
      <title>Re: ACS redudancy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117522#M436511</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yatin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well I am in a middle of a strange situation.&lt;/P&gt;&lt;P&gt;After checking the logs that you pointed out, I didn't find anything strange.&lt;/P&gt;&lt;P&gt;So I reversed one more time the configuration. I mean I put the active ACS (10.10.10.1) as an backup and the backup (10.10.10.2) as an active in the router configuration. &lt;/P&gt;&lt;P&gt;ip tacacs-server host 10.10.10.2&lt;/P&gt;&lt;P&gt;ip tacacs-server host 10.10.10.1&lt;/P&gt;&lt;P&gt;Then I unpluged the network cable from the current active ACS (10.10.10.2) and tried to login in my router and out of nowhere everything worked just fine !&lt;/P&gt;&lt;P&gt;Then I reconfigured my router as it was (reversed the ACS in the previous form) and it didn't worked. &lt;/P&gt;&lt;P&gt;ip tacacs-server host 10.10.10.1&lt;/P&gt;&lt;P&gt;ip tacacs-server host 10.10.10.2&lt;/P&gt;&lt;P&gt;The strange in all this is that my active ACS (10.10.10.1) is doing a FULL replication to the backup (10.10.10.2) in order to have both ACS the accurate configuration. So when I first thinking that there was something wrong in my active ACS (10.10.10.1) I end up in the conclusion that it couldn't be anything wrong at the active ACS since it's doing the replication. So, since the backup ACS has the total same configuration as the active (I tripled checked it!) it shouldn't worked when I did the reverse. Correct ?&lt;/P&gt;&lt;P&gt;I know it sounds a bit confusing but still this is the true story. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Any more good ideas ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;/kostas&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS1: If you still want the package.cab you can send me an e-mail and I will reply to it. I can't post them here since they contain sensitive information&lt;/P&gt;&lt;P&gt;PS2: Is it possible the problem occured because of a RADIUS distribution table ? But then again the backup ACS has the same distribution table....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2003 10:53:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117522#M436511</guid>
      <dc:creator>-kostas-</dc:creator>
      <dc:date>2003-06-05T10:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: ACS redudancy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117523#M436512</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kostas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me take a look at the package.cab.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:yatin@cisco.com"&gt;yatin@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2003 21:06:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117523#M436512</guid>
      <dc:creator>ywadhavk</dc:creator>
      <dc:date>2003-06-05T21:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: ACS redudancy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117524#M436513</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you make the following changes made by the first reply:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From,&lt;/P&gt;&lt;P&gt;aaa authentication login telnet group tacacs+ local&lt;/P&gt;&lt;P&gt;To,&lt;/P&gt;&lt;P&gt;aaa authentication login telnet group TEST local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this doesn't ressolve the problem, problem seems to be with the IOS code.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mynul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jun 2003 23:39:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117524#M436513</guid>
      <dc:creator>mhoda</dc:creator>
      <dc:date>2003-06-05T23:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: ACS redudancy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117525#M436514</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mynul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes I did that.&lt;/P&gt;&lt;P&gt;It was my first change and to tell you the truth I felt a completely idiot when I saw my obvious mistake.&lt;/P&gt;&lt;P&gt;Nevertheless that didn't solved my problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/kostas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jun 2003 05:23:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117525#M436514</guid>
      <dc:creator>-kostas-</dc:creator>
      <dc:date>2003-06-06T05:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: ACS redudancy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117526#M436515</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kostas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The standby/backup ACS server doesn't seem to be in the domain NOC, i.e. member of this domain. Please check that. If it is in a different domain, then there needs to be a proper trust relationship between those two domains.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Error in the log file ---------------&lt;/P&gt;&lt;P&gt;We are NOT a member of a domain =&amp;gt; we cannot authenticate accounts on other trusted domains.&lt;/P&gt;&lt;P&gt;---------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Because of this, it seems that there was no replication happening between the primary and secondary servers. The primary ACS in installed on the PDC of domain NOC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;yatin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Jun 2003 13:58:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117526#M436515</guid>
      <dc:creator>ywadhavk</dc:creator>
      <dc:date>2003-06-07T13:58:18Z</dc:date>
    </item>
    <item>
      <title>Re: ACS redudancy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117527#M436516</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This shouldn't cause any problem with the ACS replications.  But, its a problem if you want to authenticate users against the domain controller as the minumum requirement is to install ACS in a member server.  Have you intergrated ACS with the domain controller, i.e, are you trying to authenticate users with the domain accounts thru ACS.  If thats the case, may be primary acs is sending mal packets when cannot authenticate users against the domain controller.    To elimate the pssoibility that its no ACS, please stop the primary acs services all together, then see if router is falling back on the secondary server.  If that doesn't happen, then its the problem on IOS,   if you can share the vesrion info on the router, can suggest if this is bug on the code.  Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mynu;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Jun 2003 20:44:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117527#M436516</guid>
      <dc:creator>mhoda</dc:creator>
      <dc:date>2003-06-07T20:44:41Z</dc:date>
    </item>
    <item>
      <title>Re: ACS redudancy</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117528#M436517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mynu,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well no, that isn't the case. We are not trying to authenticate users with the domain accounts. Actually we don't have domain accounts at all. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We use ACS only for our NOC people for strictly telnet purposes, for some custom scripts and for some VoIP testing. But the main reason of the existence of ACS is for telnet reasons.&lt;/P&gt;&lt;P&gt;The case is the second example that you are giving.&lt;/P&gt;&lt;P&gt;I stop all the services from the primary ACS (even unpluged the network cable) and then try to login in the router with the backup ACS, and that doesn't work.&lt;/P&gt;&lt;P&gt;The thing with the replication cross my mind so what I did is to delete ALL the entries in the backup ACS and do a manual replication and all worked well.&lt;/P&gt;&lt;P&gt;As for the IOS bug, I read about the one (CSCdx41454) for the problem with routers that have loopbacks but the router which I experiment with don't have a loopback and has only one FastEthernet active with a default-gateway.&lt;/P&gt;&lt;P&gt;As for the version, well to tell you the truth we have many routers from GSR12000, 7200, 3640, AS5300, in different PoPs so it's kind difficult to get the IOS versions from all of them. In a statistically experiment, I tried to check the redudancy in various boxes in various PoPs (after stoping the active ACS) but none of them worked so I thought that couldn't be an IOS bug. Nevertheless if you think that there is a bug problem I can sent you a full list of the various IOS versions plus the package.cab files as I did with Yatin. Just for the records I will c/p the sh ver output of the router I am experiment.&lt;/P&gt;&lt;P&gt;Finally, the strange situation is that when the backup ACS take the place of the active ACS and the active ACS becomes backup everything seems to work well. At least in a couple of routers that I've tested it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;/kostas&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;#sh ver&lt;/P&gt;&lt;P&gt;Cisco Internetwork Operating System Software &lt;/P&gt;&lt;P&gt;IOS (tm) 5300 Software (C5300-JK8S-M), Version 12.2(11)T,  RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt;TAC Support: &lt;A class="jive-link-custom" href="http://www.cisco.com/tac" target="_blank"&gt;http://www.cisco.com/tac&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Copyright (c) 1986-2002 by cisco Systems, Inc.&lt;/P&gt;&lt;P&gt;Compiled Wed 31-Jul-02 20:11 by ccai&lt;/P&gt;&lt;P&gt;Image text-base: 0x60008938, data-base: 0x61730000&lt;/P&gt;&lt;P&gt;ROM: System Bootstrap, Version 12.0(2)XD1, EARLY DEPLOYMENT RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt;BOOTLDR: 5300 Software (C5300-BOOT-M), Version 12.0(4)T1,  RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt; uptime is 6 weeks, 6 days, 2 hours, 20 minutes&lt;/P&gt;&lt;P&gt;System returned to ROM by reload at 11:20:41 EDT Tue Apr 22 2003&lt;/P&gt;&lt;P&gt;System restarted at 11:21:31 EDT Tue Apr 22 2003&lt;/P&gt;&lt;P&gt;System image file is "flash:c5300-jk8s-mz.122-11.T.bin"&lt;/P&gt;&lt;P&gt;cisco AS5300 (R4K) processor (revision A.32) with 131072K/16384K bytes of memory.&lt;/P&gt;&lt;P&gt;Processor board ID 24710123&lt;/P&gt;&lt;P&gt;R4700 CPU at 150Mhz, Implementation 33, Rev 1.0, 512KB L2 Cache&lt;/P&gt;&lt;P&gt;Channelized E1, Version 1.0.&lt;/P&gt;&lt;P&gt;Bridging software.&lt;/P&gt;&lt;P&gt;X.25 software, Version 3.0.0.&lt;/P&gt;&lt;P&gt;SuperLAT software (copyright 1990 by Meridian Technology Corp).&lt;/P&gt;&lt;P&gt;TN3270 Emulation software.&lt;/P&gt;&lt;P&gt;Primary Rate ISDN software, Version 1.1.&lt;/P&gt;&lt;P&gt;Backplane revision 2&lt;/P&gt;&lt;P&gt;Manufacture Cookie Info:&lt;/P&gt;&lt;P&gt; EEPROM Type 0x0001, EEPROM Version 0x01, Board ID 0x30,&lt;/P&gt;&lt;P&gt; Board Hardware Version 3.2, Item Number 800-2544-04,&lt;/P&gt;&lt;P&gt; Board Revision B0, Serial Number 24710123,&lt;/P&gt;&lt;P&gt; PLD/ISP Version 0.0,  Manufacture Date 25-Feb-2001.&lt;/P&gt;&lt;P&gt;1 Ethernet/IEEE 802.3 interface(s)&lt;/P&gt;&lt;P&gt;1 FastEthernet/IEEE 802.3 interface(s)&lt;/P&gt;&lt;P&gt;128 Serial network interface(s)&lt;/P&gt;&lt;P&gt;4 Channelized E1/PRI port(s)&lt;/P&gt;&lt;P&gt;60 DSP(s), 120 Voice resource(s)&lt;/P&gt;&lt;P&gt;128K bytes of non-volatile configuration memory.&lt;/P&gt;&lt;P&gt;32768K bytes of processor board System flash (Read/Write)&lt;/P&gt;&lt;P&gt;8192K bytes of processor board Boot flash (Read/Write)&lt;/P&gt;&lt;P&gt;-----------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jun 2003 09:45:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-redudancy/m-p/117528#M436517</guid>
      <dc:creator>-kostas-</dc:creator>
      <dc:date>2003-06-09T09:45:11Z</dc:date>
    </item>
  </channel>
</rss>

