cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1841
Views
0
Helpful
5
Replies

TACACS Server failover

networker99
Level 1
Level 1

We have 3x Cisco ACS servers that we are using for centralised authentication for our switches, routers, etc..  the authentication works when the first server is available, but the devices are not querying the other 2 if the primary is unavailable

aaa authentication login default group tacacs+ local

tacacs-server host 192.168.1.1

tacacs-server host 192.168.1.2

tacacs-server host 192.168.1.3

Can someone please advise?  Thanks in advance!

5 Replies 5

santosh.kotkar
Level 1
Level 1

Which Cisco ACS version you using ?

4.1

Can you verify that the second and third ACS servers do have correct configuration of the routers and switches as authentication clients?

Perhaps running debug aaa authentication when attempting the second and third server and posting the output would help us to find the problem.

HTH

Rick

HTH

Rick

The primary is replicating to the other 2 ACS servers so I know the information is correct.

Thanks for the information. Could you post the output of show tacacs and of show aaa server sg tacacs+

HTH

Rick

HTH

Rick