cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
764
Views
0
Helpful
1
Replies

ACS 5.1 - Can't contact AD server, slow TACACS auth response

rolandgentile
Level 1
Level 1

Running ACS 5.1 appliance, and am seeing slow repsonse on TACACS authentications due to the ACS trying to reach overseas AD servers and failing.  Is there any way to configure a /etc/host/ file locally on the ACS in order to force the appliance to use specific AD servers for authentication?  As I understand the process currently, the ACS appliance will query the top-level domain and get a list of all the AD servers in DNS.  In my case, this would include the AD servers overseas that we do not want to use. Can anyone suggest a workaround for this?

1 Reply 1

antero
Level 1
Level 1

rolandgentile.

i had the same problem with authentication in AD overseas,  talked with the guys from AD and they managed a way to configure a round robin selection for only selected Domain controlers with high wan bandwith connections.

hope this help

antero