TACACS works on TCP protocol port 49 or any customizable port in ISE. TCP is connection oriented and asynchronous.
So if you are using LB, suggest inline LB option. If not, then you need to find a way to deal with TCP property explained above.
Stickiness can be based on Source IP address ( Network device IP address).
Question: Can I use Anycast?
Anycast is used with UDP since it is connectionless. You can use this probably with HTTP since it is connection less even though the underlying protocol is TCP, may not be suitable to TACACS. It may be suitable for RADIUS.
For eg: if the Anycast instance is broken mid-way for some reason, the network devices need to open a TCP connection to PSN first before sending traffic. That means that there could be a lot of open TCP connections if the routes change. So rate limiting need to be done not to overwhelm PSN’s.
That said, TACACS+ is transactional that means that it opens a TCP connection every time it does a authentication or authorization or accounting, unlike RADIUS where these happen in the same transaction. These transactions are separate.
So this may work depending on how big is configuration request/change from a client machine when accessing CLI on the network device or browsing a UI.
In case of bursty traffic where there is a bunch of requests coming from one or many sources, you typically enable persistence(single connect mode) in TACACS configuration (in ISE Network device config) so that you can use same TCP connection.
However with Anycast, persistence may not be preferred due to the nature of Anycast if routes change.
Here is a resource related to TACACS LB in general is
BRRSEC-3699 – Cisco Live presentation – slide 192
Here is a note on Anycast LB. Note how to LB if ISE PSN is down. I think this is meant for RADIUS
Looking for Immigration or PR visa Service in Delhi? We are India's most trusted immigration consultants located in New Delhi. Best Immigration Consultants in Delhi, India's top Immigration Services for Canada. Top Visa services in Delhi & Canada PR C...
There are three methods that may be used to protect steel from corrosion. Passive barrier protection works by coating the steel with a protective coating system that forms a tight barrier to prevent exposure to oxygen, water, and salt (ions).
Best Way Limousine services cater to corporate travel, group transportation and transportation for meetings and events in the Bay Area. Contact at (800) 600-9981 for Bay Area Corporate Transportation - whether its a business meeting, a trip to the airport...
Limousine provides transportation and ground transportation solution to meet the needs of the San Mateo, San Mateo is an area of support services for high-quality. San Mateo requires transportation from a person to a large group. Offering the best and m...