<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA can reactive radius server in aaa group in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4616404#M1090355</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1277181"&gt;@Udupi Krishna.&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You mean Do I no need change configuration on ASA ? because ASA will&amp;nbsp;&lt;SPAN&gt;automatically reactivated AAA Server after 30 seconds.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;My understand is If 1st Server Fail . ASA go to 2nd Server and after 30 seconds If 1st server online. ASA will automatic go to 1st server but If 1st server not coming It go to 2nd server . My understand correct ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 24 May 2022 11:54:59 GMT</pubDate>
    <dc:creator>jewfcb001</dc:creator>
    <dc:date>2022-05-24T11:54:59Z</dc:date>
    <item>
      <title>ASA can reactive radius server in aaa group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4615986#M1090345</link>
      <description>&lt;P&gt;Hi All ,&lt;/P&gt;
&lt;P&gt;I try to test ASA authenticate with Radius Server . Incase AAA-Group We have 2 Radius server If the first radius fail .ASA will authenticate with the second radius server but If the first radius come back ASA not go back authenticate with the first radius.&lt;/P&gt;
&lt;P&gt;I see in document about command "&amp;nbsp;&lt;SPAN class="keyword kwd"&gt;reactivation-mode&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;{&lt;/SPAN&gt;&lt;SPAN class="keyword kwd"&gt;depletion&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;[&lt;/SPAN&gt;&lt;SPAN class="keyword kwd"&gt;deadtime&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;VAR&gt;minutes&lt;/VAR&gt;&lt;SPAN&gt;] |&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="keyword kwd"&gt;timed&lt;/SPAN&gt;&lt;SPAN&gt;} " I'm not sure I will waiting 10 minutes or not for ASA go back to the first radius server . Please advise me.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 07:52:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4615986#M1090345</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2022-05-24T07:52:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA can reactive radius server in aaa group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4616399#M1090353</link>
      <description>&lt;P&gt;By definition, when in depletion mode a failed server is activated only when all the other servers in the group fail/become inactive. You need to set the dead time internal if depletion mode is select.&lt;/P&gt;
&lt;P&gt;E.g. If the 1st server is considered inactive, requests go to 2nd server. Unless and until 2nd server is considered inactive, the 1st server is never re-activated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you select timed instead, an inactive server is automatically reactivated after 30 seconds&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 11:48:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4616399#M1090353</guid>
      <dc:creator>Udupi Krishna.</dc:creator>
      <dc:date>2022-05-24T11:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: ASA can reactive radius server in aaa group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4616404#M1090355</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1277181"&gt;@Udupi Krishna.&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You mean Do I no need change configuration on ASA ? because ASA will&amp;nbsp;&lt;SPAN&gt;automatically reactivated AAA Server after 30 seconds.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;My understand is If 1st Server Fail . ASA go to 2nd Server and after 30 seconds If 1st server online. ASA will automatic go to 1st server but If 1st server not coming It go to 2nd server . My understand correct ?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 11:54:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4616404#M1090355</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2022-05-24T11:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA can reactive radius server in aaa group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4616411#M1090357</link>
      <description>&lt;P&gt;Partially. If the reactivation mode is set to depletion, it wont reactivate an inactive server unless all servers within the AAA/RADIUS group is inactive.&lt;/P&gt;
&lt;P&gt;However if you set the reactivation mode to timed, an inactive server is automatically reactivated after 30 secs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 12:02:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4616411#M1090357</guid>
      <dc:creator>Udupi Krishna.</dc:creator>
      <dc:date>2022-05-24T12:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: ASA can reactive radius server in aaa group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4616421#M1090358</link>
      <description>&lt;P&gt;I see in configuration guide&amp;nbsp; default configuration set 10 minutes . In this case I waiting 2nd server fail 1st server will coming or not&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or&amp;nbsp;necessary 2nd server fail . asa go to 1st server by automatic. because I try to test asa still go to 2nd not change.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="13.JPG" style="width: 748px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/151845iCD9717E88233CF6B/image-size/large?v=v2&amp;amp;px=999" role="button" title="13.JPG" alt="13.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 12:12:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4616421#M1090358</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2022-05-24T12:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA can reactive radius server in aaa group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4616478#M1090362</link>
      <description>&lt;P&gt;When in depletion mode and as highlighted in the image, it will not go back or reactivate the 1st inactive server unless the 2nd server is also considered inactive.&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 13:16:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4616478#M1090362</guid>
      <dc:creator>Udupi Krishna.</dc:creator>
      <dc:date>2022-05-24T13:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: ASA can reactive radius server in aaa group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4616490#M1090365</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1277181"&gt;@Udupi Krishna.&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your answer . As you mention this is behavior of ASA or not ?&amp;nbsp; Do you have solution ASA go to 1st server If 1st server active ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 13:28:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4616490#M1090365</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2022-05-24T13:28:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA can reactive radius server in aaa group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4616508#M1090368</link>
      <description>&lt;P&gt;This is an expected behaviour.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ASA doesn't have a mechanism to poll and check a server's status and make a decision to change its status.&lt;/P&gt;
&lt;P&gt;If you set the reactivation mode to "timed" instead of "depletion" it can automatically reactivate a server, however if the reactivated server is still down/not functioning at that point of time, there may be an increased delay in authentication.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Depletion mode is generally recommended to avoid such delays. You can always manually activate an inactive server once it's confirmed to be functioning and ready to accept authentication requests.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;e.g. command&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;aaa-server &amp;lt;radius-server group name&amp;gt; active host &amp;lt;server IP&amp;gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 13:52:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4616508#M1090368</guid>
      <dc:creator>Udupi Krishna.</dc:creator>
      <dc:date>2022-05-24T13:52:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA can reactive radius server in aaa group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4616522#M1090370</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1277181"&gt;@Udupi Krishna.&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your answer and advisory Oh! I just understand reactivation has 2 mode&amp;nbsp;&lt;SPAN&gt;"timed" and "depletion"&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;And as you mention below. If in that point 1st fail asa will go to 2nd server or not ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;if the reactivated server is still down/not functioning at that point of time, there may be an increased in delay in authentication.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 14:00:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4616522#M1090370</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2022-05-24T14:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA can reactive radius server in aaa group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4616533#M1090371</link>
      <description>&lt;P&gt;Happy to help!!&lt;/P&gt;
&lt;P&gt;If the reactivation mode is depletion and 1st server fails, ASA will automatically send authentication requests to 2nd server. 1st server is "not" activated until 2nd server fails (you can manually activate an inactive server)&lt;/P&gt;
&lt;P&gt;If the reactivation mode is timed and 1st server fails, ASA will automatically send authentication requests to 2nd server. ASA will also re-activate the 1st server after 30 secs but this can cause delays if the failed server hasn't recovered.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do rate helpful posts &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 14:07:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4616533#M1090371</guid>
      <dc:creator>Udupi Krishna.</dc:creator>
      <dc:date>2022-05-24T14:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA can reactive radius server in aaa group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4618122#M1090437</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1277181"&gt;@Udupi Krishna.&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for response.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If the reactivation mode is depletion and 1st server fails, ASA will automatically send authentication requests to 2nd server. 1st server is "not" activated until 2nd server fails (you can manually activate an inactive server)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;By the way. I see in document. about mode&amp;nbsp;&lt;SPAN&gt;is depletion . Will asa re-enable after 10minutes ?&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2022 07:15:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4618122#M1090437</guid>
      <dc:creator>jewfcb001</dc:creator>
      <dc:date>2022-05-26T07:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA can reactive radius server in aaa group</title>
      <link>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4619610#M1090464</link>
      <description>&lt;P&gt;The 10 mins dead interval is after the 2nd or the last server in the group fails and time it waits before activating all the servers again&lt;/P&gt;</description>
      <pubDate>Sat, 28 May 2022 10:26:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-can-reactive-radius-server-in-aaa-group/m-p/4619610#M1090464</guid>
      <dc:creator>Udupi Krishna.</dc:creator>
      <dc:date>2022-05-28T10:26:24Z</dc:date>
    </item>
  </channel>
</rss>

