<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The tacacs-server timeout  in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/switch-aaa-authentication-fallback-to-local-slow/m-p/2548206#M89705</link>
    <description>&lt;P&gt;The tacacs-server timeout &amp;nbsp;the default is 5 seconds and retries is 3, so for each server failover , 30 seconds is what it will take.&lt;/P&gt;&lt;P&gt;in total it will 60 seconds for each commands.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-weight: bold; color: rgb(84, 84, 84); font-family: arial, sans-serif; font-size: small; line-height: 18.200000762939453px;"&gt;tacacs&lt;/SPAN&gt;&lt;SPAN style="color: rgb(84, 84, 84); font-family: arial, sans-serif; font-size: small; line-height: 18.200000762939453px;"&gt;-&lt;/SPAN&gt;&lt;SPAN style="font-weight: bold; color: rgb(84, 84, 84); font-family: arial, sans-serif; font-size: small; line-height: 18.200000762939453px;"&gt;server timeout &amp;lt;seconds&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/en/US/products/ps5989/products_configuration_guide_chapter09186a008074a898.html#wp1737158&lt;/P&gt;&lt;P&gt;Tweak the retries and timeout to get a better time on the commands.&lt;/P&gt;&lt;P&gt;Rate if Useful &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Sharing knowledge makes you Immortal.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ed&lt;/P&gt;</description>
    <pubDate>Thu, 26 Jun 2014 16:31:44 GMT</pubDate>
    <dc:creator>edwardcollins7</dc:creator>
    <dc:date>2014-06-26T16:31:44Z</dc:date>
    <item>
      <title>Switch AAA authentication fallback to local slow</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-aaa-authentication-fallback-to-local-slow/m-p/2548205#M89704</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm testing ACS servers and aaa doing admin authentication on a test switch using tacacs+.&lt;/P&gt;&lt;P&gt;Everything works very well but I noticed when I block access from my test switch to our both ACS servers, local login works but is very slow. I'm doing authorization for all commands:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;aaa authorization commands 1 default group tacacs+ local&lt;BR /&gt;aaa authorization commands 15 default group tacacs+ local&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I enable debugging for tacacs events, I can see with every command the switch tries to connect to the 1st ACS server, then the 2nd and after 2x the timeout it tries local. I'm wondering why the state of the tacacs servers is not kept and with every command he tries both of them? In cases of severe network issues, I don't feel like waiting x seconds for every command I enter.&lt;/P&gt;&lt;P&gt;Is there a way I can speed this up without losing the functionality to perform authorization per command?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kr,&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:50:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-aaa-authentication-fallback-to-local-slow/m-p/2548205#M89704</guid>
      <dc:creator>askaerr</dc:creator>
      <dc:date>2019-03-11T04:50:04Z</dc:date>
    </item>
    <item>
      <title>The tacacs-server timeout</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-aaa-authentication-fallback-to-local-slow/m-p/2548206#M89705</link>
      <description>&lt;P&gt;The tacacs-server timeout &amp;nbsp;the default is 5 seconds and retries is 3, so for each server failover , 30 seconds is what it will take.&lt;/P&gt;&lt;P&gt;in total it will 60 seconds for each commands.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-weight: bold; color: rgb(84, 84, 84); font-family: arial, sans-serif; font-size: small; line-height: 18.200000762939453px;"&gt;tacacs&lt;/SPAN&gt;&lt;SPAN style="color: rgb(84, 84, 84); font-family: arial, sans-serif; font-size: small; line-height: 18.200000762939453px;"&gt;-&lt;/SPAN&gt;&lt;SPAN style="font-weight: bold; color: rgb(84, 84, 84); font-family: arial, sans-serif; font-size: small; line-height: 18.200000762939453px;"&gt;server timeout &amp;lt;seconds&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/en/US/products/ps5989/products_configuration_guide_chapter09186a008074a898.html#wp1737158&lt;/P&gt;&lt;P&gt;Tweak the retries and timeout to get a better time on the commands.&lt;/P&gt;&lt;P&gt;Rate if Useful &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Sharing knowledge makes you Immortal.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ed&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2014 16:31:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-aaa-authentication-fallback-to-local-slow/m-p/2548206#M89705</guid>
      <dc:creator>edwardcollins7</dc:creator>
      <dc:date>2014-06-26T16:31:44Z</dc:date>
    </item>
    <item>
      <title>Command Purpose Router(config</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-aaa-authentication-fallback-to-local-slow/m-p/2548207#M89706</link>
      <description>&lt;TABLE border="1" cellpadding="2" cellspacing="0" id="wp1000979table1000977" width="80%"&gt;&lt;TBODY&gt;&lt;TR align="left" valign="bottom"&gt;&lt;TH scope="col"&gt;&lt;DIV class="pCH1_CellHead1"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&lt;SPAN style="color: Black; font-style: normal; font-weight: bold; text-decoration: none; vertical-align: baseline;"&gt;Command&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/TH&gt;&lt;TH scope="col"&gt;&amp;nbsp;&lt;DIV class="pCH1_CellHead1"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;Purpose&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/TH&gt;&lt;/TR&gt;&lt;TR align="left" valign="top"&gt;&lt;TD&gt;&amp;nbsp;&lt;P class="pExT_ExampleTable"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;Router(config)#&amp;nbsp;&lt;B class="cBold"&gt;tacacs-server host&lt;/B&gt; &lt;EM class="cEmphasis"&gt;hostname&lt;/EM&gt; [&lt;B class="cBold"&gt;single-connection&lt;/B&gt;] [&lt;B class="cBold"&gt;port&lt;/B&gt; &lt;EM class="cEmphasis"&gt;integer&lt;/EM&gt;] [&lt;B class="cBold"&gt;timeout&lt;/B&gt; &lt;EM class="cEmphasis"&gt;integer&lt;/EM&gt;] [&lt;B class="cBold"&gt;key&lt;/B&gt; &lt;EM class="cEmphasis"&gt;string&lt;/EM&gt;]&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;P class="pB1_Body1"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;Specifies a TACACS+ host.&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="pB1_Body1"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;Using the &lt;B class="cBold"&gt;tacacs-server host&lt;/B&gt; command, you can also configure the following options:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;•&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="19" /&gt;Use the &lt;B class="cBold"&gt;single-connection&lt;/B&gt; keyword to specify single-connection (only valid with CiscoSecure Release&amp;nbsp;1.0.1 or later). Rather than have the router open and close a TCP connection to the daemon each time it must communicate, the single-connection option maintains a single open connection between the router and the daemon. This is more efficient because it allows the daemon to handle a higher number of TACACS operations.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="Note3"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&lt;IMG alt="" src="http://www.cisco.com/c/dam/en/us/td/i/templates/note.gif" /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;HR class="Note3" /&gt;&lt;P class="pN3_Note3"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&lt;B&gt;Note &lt;/B&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="6" /&gt;The daemon must support single-connection mode for this to be effective, otherwise the connection between the network access server and the daemon will lock up or you will receive spurious errors.&lt;/SPAN&gt;&lt;/P&gt;&lt;HR class="Note3" /&gt;&lt;P class="pBu1_Bullet1"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;•&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="19" /&gt;Use the &lt;B class="cBold"&gt;port&lt;/B&gt; &lt;EM class="cCi_CmdItalic"&gt;integer&lt;/EM&gt; argument to specify the TCP port number to be used when making connections to the TACACS+ daemon. The default port number is 49.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="pBu1_Bullet1"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;•&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="19" /&gt;Use the &lt;B class="cBold"&gt;timeout&lt;/B&gt; &lt;EM class="cCi_CmdItalic"&gt;integer&lt;/EM&gt; argument to specify the period of time (in seconds) the router will wait for a response from the daemon before it times out and declares an error.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="Note3"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&lt;IMG alt="" src="http://www.cisco.com/c/dam/en/us/td/i/templates/note.gif" /&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;HR class="Note3" /&gt;&lt;P class="pN3_Note3"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&lt;B&gt;Note &lt;/B&gt;&lt;IMG alt="" border="0" height="2" src="http://www.cisco.com/c/dam/en/us/td/i/templates/blank.gif" width="6" /&gt;Specifying the timeout value with the &lt;B class="cBold"&gt;tacacs-server host&lt;/B&gt; command overrides the default timeout value set with the &lt;B class="cBold"&gt;tacacs-server timeout&lt;/B&gt; command for this server only.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2014 16:58:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-aaa-authentication-fallback-to-local-slow/m-p/2548207#M89706</guid>
      <dc:creator>mohanak</dc:creator>
      <dc:date>2014-06-26T16:58:44Z</dc:date>
    </item>
    <item>
      <title>Re: Command Purpose Router(config</title>
      <link>https://community.cisco.com/t5/network-access-control/switch-aaa-authentication-fallback-to-local-slow/m-p/3327438#M89707</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;i tried this on our 2960 switch and below is my config. and response was fast after testing failed reachability to tacacs server&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;aaa group server tacacs+ ise_server&lt;BR /&gt;server name ise01.company.org&lt;BR /&gt;server name ise02.company.org&lt;BR /&gt;!tacacs-server timeout 1 -------&amp;gt;not required &amp;lt;--------&lt;BR /&gt;tacacs server ise01.company.org&lt;BR /&gt;address ipv4 x.x.x.x&lt;BR /&gt;key cisco123&lt;BR /&gt;timeout 1 &amp;lt;-----------------------------&amp;nbsp;&lt;BR /&gt;single-connection&lt;BR /&gt;tacacs server ise02.company.org&lt;BR /&gt;address ipv4 y.y.y.y&lt;BR /&gt;key cisco123&lt;BR /&gt;timeout 1 &amp;lt;-------------------------------&lt;BR /&gt;single-connection&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since we are using ISE as our tacacs server, another way to speed up is to&amp;nbsp;remove authorization on your vty lines. i noticed this&amp;nbsp;on line vty&amp;nbsp;0, we didnt&amp;nbsp;put other AAA commands but on line&amp;nbsp;vty 1 4. on my first login (vty 0) response was fast, on second and consecutive login response had little delay.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;line vty 0&lt;BR /&gt;exec-timeout 15 0&lt;BR /&gt;password 7 0508151D2E435A&lt;BR /&gt;authorization exec AAA&lt;BR /&gt;logging synchronous&lt;BR /&gt;login authentication AAA&lt;BR /&gt;transport input ssh&lt;/P&gt;
&lt;P&gt;line vty&amp;nbsp;1 4&lt;BR /&gt;exec-timeout 15 0&lt;BR /&gt;password 7 0205174904091B&lt;BR /&gt; &lt;FONT color="#000000"&gt;&lt;STRONG&gt;authorization commands 0 AAA&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt; authorization commands 1 AAA&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt; authorization commands 15 AAA&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;authorization exec AAA&lt;BR /&gt;logging synchronous&lt;BR /&gt;login authentication AAA&lt;BR /&gt;line vty 7 15&lt;BR /&gt;&lt;BR /&gt;thank you and regards,&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2018 12:33:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/switch-aaa-authentication-fallback-to-local-slow/m-p/3327438#M89707</guid>
      <dc:creator>bbb bbb</dc:creator>
      <dc:date>2018-02-08T12:33:26Z</dc:date>
    </item>
  </channel>
</rss>

