<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TACACS in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs/m-p/3567342#M529990</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Arron-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In single connection mode, multiple requests from a network device are multiplexed over a single TCP session. By default, this check box is unchecked.&amp;nbsp; (if it was Cisco recommendation, it wouldn't be unchecked by default) &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/wink.png" /&gt;&lt;/P&gt;&lt;P&gt;as for mismatch, i don't usually specify that on the device side.&amp;nbsp; I would image it depend on the accounting stop-start commands sent back to ISE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vince&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 27 Apr 2017 21:47:01 GMT</pubDate>
    <dc:creator>vrostowsky</dc:creator>
    <dc:date>2017-04-27T21:47:01Z</dc:date>
    <item>
      <title>TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs/m-p/3567341#M529988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt;Hi team, &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;SPAN class="s1"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;My customer is asking on Cisco’s recommendation on using a ‘single-connection’ in TACACS+. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;SPAN class="s1"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;“We know that single connection will use a lower number of sockets/resources on the tacacs server, and single-connection seems to be referred to as “legacy” but we couldn’t find confirmation of the recommendation from Cisco”. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;SPAN class="s1"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;“If there is a mismatch between single-connection settings (on the tacacs server and the network device), what would happen in either case?” &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;SPAN class="s1"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Can you help me? &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&lt;SPAN class="s1"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Thank you, &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Arron &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Apr 2017 08:10:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs/m-p/3567341#M529988</guid>
      <dc:creator>kerai08</dc:creator>
      <dc:date>2017-04-27T08:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs/m-p/3567342#M529990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Arron-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In single connection mode, multiple requests from a network device are multiplexed over a single TCP session. By default, this check box is unchecked.&amp;nbsp; (if it was Cisco recommendation, it wouldn't be unchecked by default) &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/wink.png" /&gt;&lt;/P&gt;&lt;P&gt;as for mismatch, i don't usually specify that on the device side.&amp;nbsp; I would image it depend on the accounting stop-start commands sent back to ISE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vince&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Apr 2017 21:47:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs/m-p/3567342#M529990</guid>
      <dc:creator>vrostowsky</dc:creator>
      <dc:date>2017-04-27T21:47:01Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs/m-p/3567343#M529995</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Arron,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Single Connect mode is for chatty devices. This is to minimize the number of TCP connections opened for duplicate transactions and retain the connection for AAA transactions. There are two modes legacy and TACACS+ draft, choose TACACS+ draft mode and not legacy for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no single connect mode on the network device. It is only on the server side. So if you think that you have a lot of unnecessary transactions from devices (or) any network device that is non-Cisco behaving incorrectly (or) using scripts to do administration that loops and is not controlled use this. Remember, this also consumes the TCP sockets so in a large environment you have to be careful to use this across network devices.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Apr 2017 17:14:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs/m-p/3567343#M529995</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2017-04-28T17:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4038069#M558471</link>
      <description>&lt;P&gt;&amp;gt;&amp;gt; There is no single connect mode on the network device. It is only on the server side.&lt;BR /&gt;&lt;BR /&gt;Really? This is from IOS XE device (from my lab):&lt;BR /&gt;&lt;BR /&gt;tacacs server ISE-01&lt;BR /&gt;&amp;nbsp; address ipv4 10.0.0.3&lt;BR /&gt;&amp;nbsp; key 7 ******&lt;BR /&gt;&amp;nbsp; &lt;STRONG&gt;single-connection&lt;/STRONG&gt;&lt;BR /&gt;tacacs server ISE-02&lt;BR /&gt;&amp;nbsp; address ipv4 10.0.0.4&lt;BR /&gt;&amp;nbsp; key 7 ******&lt;BR /&gt;&amp;nbsp; &lt;STRONG&gt;single-connection&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Feb 2020 21:54:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4038069#M558471</guid>
      <dc:creator>Alexey Savkin</dc:creator>
      <dc:date>2020-02-29T21:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4038220#M558474</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;"single connection" mode needs to be agreed upon the first packet exchange between the TACACS client and the TACACS server, if bot set the "Single Connect" Flag. IOS-XE has had this option since a very long time now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;</description>
      <pubDate>Sun, 01 Mar 2020 16:42:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs/m-p/4038220#M558474</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-03-01T16:42:57Z</dc:date>
    </item>
  </channel>
</rss>

