Forum Discussion

Alex_6417's avatar
Alex_6417
Icon for Nimbostratus rankNimbostratus
Sep 05, 2012

F5 BIG-IP 10.1.0 TACACS authentication ACS 5.3 taking too long to login when first TACACS server is down

Hi All,

 

I am running the BIG IP 10.1.0 LTM virtual edition and I have successfully configured it to authenticate against a couple of TACACS servers deployed in our Cisco ACSes 5.3.

 

When the primary TACACS server is up, all works perfect, GUI and console (tmsh) access. However, while doing some testing, I shutted down the primary TACACS server, and tried to authenticate the BIG-IP against the secondary TACACS server. This also works fine but takes between 3 to 4 minutes to grant access, which is of course excesive.

 

I ruled out as the cause of this issue the secondary TACACS server by configuring it as primary in the BIG IP and everything worked pretty well.

 

Has anyone experienced this? If so, how did you fix it?

 

Thanks,

 

Alex.

 

  • Hi Alex,

     

     

    May you can need your Help. i configured ACS 4.2 for LTM. but it not working with ACS 5.3 . how do we configure this. can you help in this.

     

     

     

    In ACS 4.2 we give in PPP-IP tab and custome attribute. we define these . how we do in ACS 5.3