cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
682
Views
0
Helpful
4
Replies

CCS 11506 Tacacs Source Interface.

tonysong
Level 1
Level 1

Hi,

We have 4 CSS 11506 and 2 Tacacs servers.

2 CSS with same ios version but behaves different. 1 talks to the ACS server via the management interface and the other talks with ACS server via the circuit interface. Are there any command like that on the Cisco routers to define the Tacacs source Interface?

Thanks!

Tony

4 Replies 4

Gilles Dufour
Cisco Employee
Cisco Employee

it depends on your routing table.

The CSS will select automatically the exit interface ip address as source.

There is no command to chose the interface.

Gilles.

In the past, TACACS was not a routable protocol over the management interface.

Has this changed? Can we now route TACACS packets to and from the server over the management interface?

Cheers, Dom

Tony,

The behavior you mention has not changed for TACACS.

j.poley
Level 1
Level 1

We typically use a loopback address for TACACS communication. Then any single failed interface will not interfere with communications back to TACACS.

Here is the command...

ip tacacs source-interface Loopback0

JDP

Review Cisco Networking for a $25 gift card