Forum Discussion

adamm's avatar
adamm
Icon for Altostratus rankAltostratus
Nov 08, 2018

VS for TACACS authentication

Has anyone created a VS for TACACS? Specifically, I have 4 TACACS servers and would like to load balance aaa requests to them. I have a few hundred NADs that I would like to configure for TACACS and remove the old NPS based radius logins.

 

The TACACS servers (Cisco ISE PSNs) are already in line to the f5s and used for other RADIUS purposes (MAB, etc.). The framework is there but I'm not sure if I need to do a particular irule based persistence such as with RADIUS.

 

  • Created a standard TCP VS with SourceAddr persistence and it seems to work fine. Still would like to hear any input or issues you've had.

     

    Thanks.