01-16-2004 06:55 AM - edited 03-02-2019 12:56 PM
Hello,
I would like to have more than one tacacs-server host commands in my config.
I'm wondering how the router will parse the server - in a round-robin fashion, it will go to the next server only if the first one is out of service and so on ... so far I haven't found anything in the docs.
Thank you,
Mihai Iancu
01-16-2004 07:07 AM
no the tacacs server that is listed first will act as you primary , the second server listed in the config will be the backup, If the first server is unavail the router will contact the 2nd sever , after the tacacs-server timeout period expires , I think it is 1 munute by default , I would recommend lowering that parameter.
01-16-2004 07:50 AM
That is correct. When you configure multiple TACACS servers, a connection is attempted to the first server (order in which they have been entered) and if it doesn't respond the next one is used.
Hope this helps,
01-16-2004 08:48 AM
If you have multiple authentication server groupings you want to use also, you can use "aaa group server" to help organize a bit...
01-29-2004 06:09 AM
what if the failed primary server comes back online?
will IOS still uses secondary server?
how IOS tests whether the primary server is back online?
or
will it comes back only after the secondary server fails and the primary is available?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide