[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
The state of TACACS+
- Subject: The state of TACACS+
- From: javier at kjsl.org (Javier Henderson)
- Date: Mon, 30 Dec 2013 19:05:04 -0500
- In-reply-to: <CAAAwwbXt69e=TqYif=jXLPcOMPBwG_Fu5R3TDhZ-8LXS7Rwt5Q@mail.gmail.com>
- References: <[email protected]> <[email protected]> <CAL9jLaZnqWMrrsOFoEUWsHHUEVSYRythhHQZzPNdD=1R406A-w@mail.gmail.com> <[email protected]> <[email protected]> <CAAAwwbXt69e=TqYif=jXLPcOMPBwG_Fu5R3TDhZ-8LXS7Rwt5Q@mail.gmail.com>
On Dec 30, 2013, at 6:42 PM, Jimmy Hess <mysidia at gmail.com> wrote:
> How do you feel about having to wait 30 seconds between every command you enter to troubleshoot, to fail to the second server, if the TACACS or RADIUS system is nonresponsive, because the dumb router can't remember which TACACS servers are up and which ones are down, and always tries the first one in the list first? At least RADIUS has the concept of a "dead timer" :)
Are you talking about Cisco routers? The default timeout value for TACACS+ is five seconds, so I?m not sure where you?re coming up with thirty seconds, unless you have seven servers listed on the router and the first six are dead/unreachable.
-jav