<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WLC TACACS+ fall backfeature in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/wlc-tacacs-fall-backfeature/m-p/3414240#M111697</link>
    <description>&lt;P&gt;Hi Flavio&lt;/P&gt;
&lt;P&gt;I have set auth order as mentioned in attached Snap. If tacacs is down , local user database will be used.&lt;/P&gt;
&lt;P&gt;Now when tacacs is restored , i want user to be authenticated by tacacs server.&lt;/P&gt;
&lt;P&gt;For that tacacs+ fall back parameter has only two value. enable/disable.&lt;/P&gt;
&lt;P&gt;What should I choose ?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Jul 2018 18:50:28 GMT</pubDate>
    <dc:creator>umeshunited</dc:creator>
    <dc:date>2018-07-11T18:50:28Z</dc:date>
    <item>
      <title>WLC TACACS+ fall backfeature</title>
      <link>https://community.cisco.com/t5/wireless/wlc-tacacs-fall-backfeature/m-p/3414217#M111695</link>
      <description>&lt;P&gt;We are using&amp;nbsp;aaa login method list on wlc , for which TACACS will be first and local will be second method.&lt;/P&gt;
&lt;P&gt;What should be the tacacs fall back parameter ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 15:50:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-tacacs-fall-backfeature/m-p/3414217#M111695</guid>
      <dc:creator>umeshunited</dc:creator>
      <dc:date>2021-07-05T15:50:38Z</dc:date>
    </item>
    <item>
      <title>Re: WLC TACACS+ fall backfeature</title>
      <link>https://community.cisco.com/t5/wireless/wlc-tacacs-fall-backfeature/m-p/3414233#M111696</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;If I understood you right, fallback means what you want to happen when you server become unavailable:&lt;/P&gt;
&lt;UL class="ul"&gt;
&lt;LI id="ID214__li_3DB4DEC62E2045C49E33E4D8EFEF8C60" class="li"&gt;
&lt;P class="p"&gt;&lt;SPAN class="ph uicontrol B_Bold-7204837A"&gt;Off&lt;/SPAN&gt;—Disables RADIUS server fallback. This is the default value. Same for TACACS.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI class="li"&gt;&lt;/LI&gt;
&lt;LI id="ID214__li_7D6D29DE26F043D9B9AF9BFC9071556D" class="li"&gt;
&lt;P class="p"&gt;&lt;SPAN class="ph uicontrol B_Bold-7204837A"&gt;Passive&lt;/SPAN&gt;—Causes the controller to revert to a server with a lower priority from the available backup servers without using extraneous probe messages. The controller ignores all inactive servers for a time period and retries later when a RADIUS message needs to be sent.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI id="ID214__li_76B87F1F59804C9AAF90033368F9F3B2" class="li"&gt;
&lt;P class="p"&gt;&lt;SPAN class="ph uicontrol B_Bold-7204837A"&gt;Active&lt;/SPAN&gt;—Causes the controller to revert to a server with a lower priority from the available backup servers by using RADIUS probe messages to proactively determine whether a server that has been marked inactive is back online. The controller ignores all inactive servers for all active RADIUS requests.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph"&gt;If probing is enabled, the RADIUS server will be probed at every probing time interval irrespective of the probe response having been received or not. For more information, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="xref" href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvc01761" target="_blank"&gt;CSCvc01761&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="ph"&gt;-If I helped you somehow, please, rate it as useful.-&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 18:35:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-tacacs-fall-backfeature/m-p/3414233#M111696</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2018-07-11T18:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: WLC TACACS+ fall backfeature</title>
      <link>https://community.cisco.com/t5/wireless/wlc-tacacs-fall-backfeature/m-p/3414240#M111697</link>
      <description>&lt;P&gt;Hi Flavio&lt;/P&gt;
&lt;P&gt;I have set auth order as mentioned in attached Snap. If tacacs is down , local user database will be used.&lt;/P&gt;
&lt;P&gt;Now when tacacs is restored , i want user to be authenticated by tacacs server.&lt;/P&gt;
&lt;P&gt;For that tacacs+ fall back parameter has only two value. enable/disable.&lt;/P&gt;
&lt;P&gt;What should I choose ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 18:50:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-tacacs-fall-backfeature/m-p/3414240#M111697</guid>
      <dc:creator>umeshunited</dc:creator>
      <dc:date>2018-07-11T18:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: WLC TACACS+ fall backfeature</title>
      <link>https://community.cisco.com/t5/wireless/wlc-tacacs-fall-backfeature/m-p/3414266#M111698</link>
      <description>&lt;P&gt;I think you are misunderstanding&amp;nbsp; the feature. When you have TACACS and Local this means that if TACACS is not available, you can use local user. If TACACS is available you should use TACACS. This is it, you don't need to setup anything besides that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Fallback mode is a different thing. This work like a preempt. Let´s say you have two server: A an B.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;If server A becomes unavailable, the WLC will send TACACS request to server B.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;If&amp;nbsp;Fallback Mode is disabled, when server A come back to life, WLC will continue to send TACACS request to B and A will be a backup server.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;If&amp;nbsp;Fallback Mode is Enabled, when server A come back to life, WLC will stop send TACACS request to B and will start send TACACS request to server A.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Hope I was clear.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-If I helped you somehow, please, rate it as useful.-&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2018 19:51:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-tacacs-fall-backfeature/m-p/3414266#M111698</guid>
      <dc:creator>Flavio Miranda</dc:creator>
      <dc:date>2018-07-11T19:51:54Z</dc:date>
    </item>
    <item>
      <title>Re: WLC TACACS+ fall backfeature</title>
      <link>https://community.cisco.com/t5/wireless/wlc-tacacs-fall-backfeature/m-p/3414671#M111699</link>
      <description>&lt;P&gt;Thank you Flavio, I get it now.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2018 11:07:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/wlc-tacacs-fall-backfeature/m-p/3414671#M111699</guid>
      <dc:creator>umeshunited</dc:creator>
      <dc:date>2018-07-12T11:07:23Z</dc:date>
    </item>
  </channel>
</rss>

