<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ASA delay in viewing command output in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-delay-in-viewing-command-output/m-p/2598429#M416080</link>
    <description>&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using ASA5520 in active/standby failover... when we connect through console or telnet and write ant "show" command, it is very slow in viewing the output !!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Majed&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 13:19:38 GMT</pubDate>
    <dc:creator>Majed Al-Masri</dc:creator>
    <dc:date>2020-02-21T13:19:38Z</dc:date>
    <item>
      <title>Cisco ASA delay in viewing command output</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-delay-in-viewing-command-output/m-p/2598429#M416080</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using ASA5520 in active/standby failover... when we connect through console or telnet and write ant "show" command, it is very slow in viewing the output !!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Majed&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:19:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-delay-in-viewing-command-output/m-p/2598429#M416080</guid>
      <dc:creator>Majed Al-Masri</dc:creator>
      <dc:date>2020-02-21T13:19:38Z</dc:date>
    </item>
    <item>
      <title>Hello Majed-Do you by any</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-delay-in-viewing-command-output/m-p/2598430#M416082</link>
      <description>&lt;P&gt;Hello Majed-&lt;/P&gt;&lt;P&gt;Do you by any chance have&amp;nbsp;&lt;STRONG&gt;aaa&amp;nbsp;&lt;/STRONG&gt;configured and your aaa servers are down or not available?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Nov 2014 06:09:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-delay-in-viewing-command-output/m-p/2598430#M416082</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-11-18T06:09:59Z</dc:date>
    </item>
    <item>
      <title>Hello Neno, actually yes, the</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-delay-in-viewing-command-output/m-p/2598431#M416084</link>
      <description>&lt;P&gt;Hello Neno,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;actually yes, the ASA is configured for AAA.&lt;/P&gt;&lt;P&gt;Through logging monitor logs, the asa recursively states that aaa server failed then it states the aaa server is alive !!!&lt;/P&gt;&lt;P&gt;does that cause any delay in the ASA? and what can be done to avoid this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In addition, checking the memory and CPU doesn't indicate any high CPU or over utilized memory.&lt;/P&gt;&lt;P&gt;thank you for your help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Majed&lt;/P&gt;</description>
      <pubDate>Tue, 18 Nov 2014 06:48:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-delay-in-viewing-command-output/m-p/2598431#M416084</guid>
      <dc:creator>Majed Al-Masri</dc:creator>
      <dc:date>2014-11-18T06:48:24Z</dc:date>
    </item>
    <item>
      <title>Yes, this can most likely</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-delay-in-viewing-command-output/m-p/2598432#M416086</link>
      <description>&lt;P&gt;Yes, this can most likely cause a delay because depending on how the device is configured. Can you post the output of the following command:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run aaa&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Also, what do you use for a AAA server?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Nov 2014 06:51:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-delay-in-viewing-command-output/m-p/2598432#M416086</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-11-18T06:51:28Z</dc:date>
    </item>
    <item>
      <title>yes sure, i will send the</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-delay-in-viewing-command-output/m-p/2598433#M416089</link>
      <description>&lt;P&gt;yes sure, i will send the customer to send me the output of the required command and i will share it with you as soon as i get the reply!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Majed&lt;/P&gt;</description>
      <pubDate>Tue, 18 Nov 2014 06:54:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-delay-in-viewing-command-output/m-p/2598433#M416089</guid>
      <dc:creator>Majed Al-Masri</dc:creator>
      <dc:date>2014-11-18T06:54:11Z</dc:date>
    </item>
    <item>
      <title>Hey, here is the</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-delay-in-viewing-command-output/m-p/2598434#M416090</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is the configuration of the aaa:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color:#008000;"&gt;aaa-server Radius-ACS protocol radius&lt;BR /&gt;aaa-server TACACS-ACS protocol tacacs+&lt;BR /&gt;aaa-server TACACS-ACS (inside) host 10.163.17.30&lt;BR /&gt;&amp;nbsp;key ******&lt;BR /&gt;aaa-server TACACS-ACS (inside) host 10.163.17.31&lt;BR /&gt;&amp;nbsp;key ******&lt;BR /&gt;aaa authentication ssh console TACACS-ACS LOCAL&lt;BR /&gt;aaa authentication telnet console TACACS-ACS LOCAL&lt;BR /&gt;aaa authentication enable console TACACS-ACS LOCAL&lt;BR /&gt;aaa authentication http console TACACS-ACS LOCAL&lt;BR /&gt;aaa authentication serial console TACACS-ACS LOCAL&lt;BR /&gt;aaa authorization command TACACS-ACS LOCAL&lt;BR /&gt;aaa authentication secure-http-client&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;Majed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Nov 2014 09:05:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-delay-in-viewing-command-output/m-p/2598434#M416090</guid>
      <dc:creator>Majed Al-Masri</dc:creator>
      <dc:date>2014-11-18T09:05:48Z</dc:date>
    </item>
    <item>
      <title>Ok, so the ASA is configured</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-delay-in-viewing-command-output/m-p/2598435#M416092</link>
      <description>&lt;P&gt;Ok, so the ASA is configured with AAA, more specifically TACACS+ Moreover, you reported that the AAA server keeps showing up as DOWN and then UP again. I believe that is the root cause of your problem. When you try to execute a command, the ASA is first trying to check against the AAA server and after it times out it references the secondary database, which in your case is the local database. So the eliminate this you can do one of the following:&lt;/P&gt;&lt;P&gt;1. Remove TACACS+ related configs and rely on the local database for authentication and authorization&lt;/P&gt;&lt;P&gt;2. Figure out why the TACACS+ server is unavailable/bouncing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Nov 2014 06:52:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-delay-in-viewing-command-output/m-p/2598435#M416092</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-11-19T06:52:42Z</dc:date>
    </item>
    <item>
      <title>hello Neno,regarding the</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-delay-in-viewing-command-output/m-p/2598436#M416095</link>
      <description>&lt;P&gt;hello Neno,&lt;/P&gt;&lt;P&gt;regarding the TACACS+ server, it was configured for other devices in the network and this ASA is removed from the ACS...&lt;/P&gt;&lt;P&gt;now, regarding removing the configuration; i have tried removing only the "&lt;SPAN style="color: rgb(0, 128, 0); font-size: 14px;"&gt;aaa authentication telnet console TACACS-ACS LOCAL" command.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="color:#000000;"&gt;but as you suggestion, i believe you mean to replace all the aaa commands with only the local database right?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color:#000000;"&gt;thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color:#000000;"&gt;Majed&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Nov 2014 07:12:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-delay-in-viewing-command-output/m-p/2598436#M416095</guid>
      <dc:creator>Majed Al-Masri</dc:creator>
      <dc:date>2014-11-19T07:12:16Z</dc:date>
    </item>
    <item>
      <title>Well that would depend on how</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-delay-in-viewing-command-output/m-p/2598437#M416097</link>
      <description>&lt;P&gt;Well that would depend on how you would want administrators to authenticate and authorize on the ASA. But yes, removing the TACACS+ reference out of the AAA commands instruct the ASA not to check the ACS server for authentication/authorization. Depending on what version of code you are running, I would recommend consulting the ASA CLI configuration guide:&lt;/P&gt;&lt;P&gt;v8.2&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/access_nw.html"&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/access_nw.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Also, if the ASDM is available and you are more comfortable with it, then I would recommend using it. The ASDM makes it very simple when it comes to configuring such services and from there it is a lot easier to tell the device if it should use tacacs+, local etc&lt;/P&gt;&lt;P&gt;I hope this helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Nov 2014 08:04:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-delay-in-viewing-command-output/m-p/2598437#M416097</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-11-19T08:04:33Z</dc:date>
    </item>
    <item>
      <title>Hello Neno,thank you very</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-delay-in-viewing-command-output/m-p/2598438#M416099</link>
      <description>&lt;P&gt;Hello Neno,&lt;/P&gt;&lt;P&gt;thank you very much for your help and support. your advice worked with us perfectly and the ASA is now working properly without any delay in viewing the commands &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Problem Description:&lt;/U&gt;&lt;/STRONG&gt;&amp;nbsp;We were facing delays and very slow response from the ASA to view any output for all show commands!&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;Analysis (By Neno Spasov):&lt;/U&gt;&lt;/STRONG&gt;&amp;nbsp;the ASA is configured for AAA authentication/authorization, while the ACS "AAA server" is not configured for ASA! this causes the ASA to check with the AAA each time you type a command but with no response from the ASA, after timeout ASA checks with the local database and view the output&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Solution (By Neno Spasov):&lt;/STRONG&gt;&lt;/U&gt;&amp;nbsp;remove the aaa server commands from the ASA configuration&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you again Neno &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;kind regards,&lt;/P&gt;&lt;P&gt;Majed&lt;/P&gt;</description>
      <pubDate>Thu, 20 Nov 2014 06:43:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-delay-in-viewing-command-output/m-p/2598438#M416099</guid>
      <dc:creator>Majed Al-Masri</dc:creator>
      <dc:date>2014-11-20T06:43:29Z</dc:date>
    </item>
  </channel>
</rss>

