Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Community Member

Tacacs Host

Hi

Wht really happens when i give 3 tacacs server host address on a AS5300 server.i.e

tacacs host server 10.0.0.1

tacacs host server 10.0.0.2

tacacs host server 10.0.0.3

When a dial-in user dials into the first ACS server,he gets autheticated via the first ACS,at wht point does he get authenticated via the the .2 & .3 ACS server....

Replies highly apprciated.

Thanks

Mark

2 REPLIES
Gold

Re: Tacacs Host

Router asks first tacacs 10.0.0.1 if doesnt reply in specified time (there is some default value - can be changed with command tacacs-server timeout) than continue to 10.0.0.2 if no response in timeout router goes to 10.0.0.3

M.

Hope that helps rate if it does

Cisco Employee

Re: Tacacs Host

Mark,

The user will only be authenticated by one ACS server. If 10.0.0.1 is offline or returns an "error" message, the NAS will proceed to .2, then to .3. However, if .1 returns a authentication fail message, the NAS stops, it will not ask .2 or .3 for authentication.

HTH

149
Views
0
Helpful
2
Replies
CreatePlease to create content