cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
670
Views
0
Helpful
2
Replies

LMS 4.2.5 - Slow Homepage login with TACACS+ module enabled

lo.mueller
Level 1
Level 1

Hi all,

having setup TACACS+ Login module Login into Homepage takes about 80 sec.

 

Reverting back to local-Login module Login into Homepage takes about 20 sec.

 

Anybody out there able to help in Tuning TACACS+ Login module for Performance.

 

During Troubleshooting we discovered that request from LMS to TACACS+-Server (ACS)

is done after 60 sec of Login attempt, it seems that LMS slows down Login Performance here.

 

Thanks for any feedback

 

Lothar

1 Accepted Solution

Accepted Solutions

lo.mueller
Level 1
Level 1

Update:

Digging deeper we discovered a DNS-Issue, dns-resover on server was configured to use two different dns-servers.

And also Prime seems to resolve hostname tacacs for ACS-Server configured in TACACS+ Login-Module -> adding an entry in /etc/hosts with IP of ACS and hostname tacacs also speeds up login-waittime from 80 sec to 20 sec.

I'm not quite sure why TACACS+ Login-Module depends so heavy on DNS?

View solution in original post

2 Replies 2

Ashok Kumar
Cisco Employee
Cisco Employee

Hi Lothar,

Although, this is not a very uncommon issue, but the remedies differs in each case.

You can try below things:-

1. Restart the daemon manager

2. If the windows server, check the services, these setting are never recommended to have in startup type of automatic except deamon manager, CSCW rsh/scp/syslog/tftp services.


- Ashok

******************************************************************************************************

Please rate the post or mark as correct answer as it will help others looking for similar information

******************************************************************************************************

 

 

lo.mueller
Level 1
Level 1

Update:

Digging deeper we discovered a DNS-Issue, dns-resover on server was configured to use two different dns-servers.

And also Prime seems to resolve hostname tacacs for ACS-Server configured in TACACS+ Login-Module -> adding an entry in /etc/hosts with IP of ACS and hostname tacacs also speeds up login-waittime from 80 sec to 20 sec.

I'm not quite sure why TACACS+ Login-Module depends so heavy on DNS?