Backup ACS server not used by switch.

I am experiencing a strange issue: During a primary ACS failure, our switches are not resorting to the backup ACS for login authentication, except for enable mode. This means we can only use the emergency local login, but once logged in we cannot enable due to the switch attempting to authenticate that to the backup ACS.
Once I created the local user in the backup ACS I was able to log in, and after I removed then re-addded the primary server as a TACACS host it worked as expected - using the backup only. I can't help but think there is some minor command I am missing so that the switches will recognize the failure of the primary ACS.
What am I missing that a failure of an ACS server does not cause the switches to use other configured servers?

Richard,
I have reviewed the information, however, the debugs are not clear enough as the only outputs displayed other than Accounting logs are the following lines:
012697: Jan  3 22:37:16.866 GMT: AAA/AUTHEN/LOGIN (0000094B): Pick method list 'default'
012698: Jan  3 22:37:24.743 GMT: AAA/AUTHEN/LOGIN (0000094B): Pick method list 'default'
There are known issues with IOS devices not triggering the fallback/failover to the secondary ACS/TACACS+ server when the primary returns an "ERROR" response. "ERROR" refers to a process failure on the server side dropping the request and would not be the same as User Invalid or Bad Password responses which are failures referring to the Authentication information and not the process itself.
Would it be possible for you to collect a capture on the Secondary ACS switchport while the primary is down in order to determine if the IOS device is reaching the secondary server at all?
Known issue:
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsd48175
Symptoms
AAA does not failover to the backup tacacs server defined when it receives ERROR
from the primary server .
Conditions
Occurs when tacacs is configured for authentication, and backup servers are
configured. When the primary server returns error due to csauth not running on
the primary server, in that case  authentication request does not fail over to
secondary server.
Frequency:
Not a common scenario.
Workaround:
None
NOTES
1) If you have an ACS for Windows (3.x or 4.x) then you can install Wireshark on the Windows Server and collect the capture.
2) If you have an ACS Appliance (3.x or 4.x) or an ACS 5.x you might need to configure a SPAN session on the switch.
After collecting the capture you can use Wireshark > Edit > Preferences > Protocols > TACACS+  > TACACS+ Encryption Key > type the shared secret value. This will  allow you to review the unencrypted packets.
You can filter the capture as well using ip.addr==x.x.x.x where x.x.x.x is the IOS device IP address.
Feel free to share the capture with me as well along with the shared secret key. I would gladly review the information.
NOTE: If the capture shows no traffic going to the secondary unit a useful test would be to configure the "Secondary" server as the primary on the IOS and verify if it works that way.
NOTE: If possible, a capture on the primary server switchport while it is down might be useful in order to verify how is the IOS determining that the primary server is down as I do not see it trying to contact the primary either... We should see atleast timeouts when contacting the primary ACS.
Regards.

Similar Messages

  • Ipad2 does not change orientation. I have not used the switch for lock rotation it is used for mute

    Ipad2 does not change orientation. I have not used the switch for lock rotation it is used for mute

    Is there a lock symbol at the top of the screen next to the battery indicator ? If so, and as you've got the switch set to notification mute, then have you checked the taskbar (the function that the switch isn't set to is controlled via the taskbar instead) : double-click the home button, slide the taskbar to the right, and it's the icon far left.
    If you havn't got the lock symbol at the top then try a reset : press and hold both the sleep and home buttons for about 10 to 15 seconds (ignore the red slider), after which the Apple logo should appear - you won't lose any content, it's the iPad equivalent of a reboot.

  • Backup schedule will not use faster backup method

    Hello,
    I am currently using Windows Server Backup in Windows Server 2008 R2 to make a copy of our Exchange server. When I initially set the schedule it was configured to use the normal backup method, but after noticing that it was taking an exceedingly long time
    I went into the Performance settings and selected the Faster backup option.
    The faster method works great if I use the Backup Once option, but for some reason the scheduled backups still try to run the normal, non-incremental backup. I can't find where to change this in the schedule. 
    **I know that the first time you run the faster backup it needs to make the full backup. It has done this(it takes about 3 days) and every time I have run it since using the Backup Once option it has worked fine(takes about 1 hour). Once again, the issue
    is that the schedule will not use the faster option and tries to use the normal backup every time.
    Thank you

    I am backing up to a network location. When I use the Backup Once option and assign it to use a network location it is able to do the Faster backup. It doesn't make sense that the faster backup works when I do it manually but doesn't work when if it is
    initiated by the schedule. They are both going over the network.

  • Server not found when switching from 4g to wifi and vice versa.

    I've had this issue for a while across multiple phones and multiple versions of Firefox for Android, and it does not happen with any other browser (which is upsetting). Whenever I am surfing the web and have multiple tabs open, and I switch from 4g to wifi or vice versa, I always get a "Server not found" error on both existing tabs and new tabs. This is an annoying issue that I am surprised to see hasn't been fixed. The only way I've been able to fix it is to quit and relaunch the app. I have tried removing plug-ins and reinstalling, but it has not helped.
    Anything I could do to alleviate the issue?
    LG G2 and Samsung Galaxy Note 3. Both on Android 4.4.2
    Firefox for Android Ver. 35.0.1

    ''Roland Tanglao [[#answer-698502|said]]''
    <blockquote>
    Hi scruffy90:
    You wrote "LG G2 and Samsung Galaxy Note 3. Both on Android 4.4.2 Firefox for Android Ver. 35.0.1 "
    I just tried switching between HSPA+ aka 3G and WiFi on a Galaxy S5 running Android 5 and have had no issues but I think this may have been an issue in the past (I did a search for a bug in bugzilla.mozilla.org but couldn't find anything).
    Are there any other details you could provide that could help us debug?
    e.g.
    # Are you using a proxy?
    # Who is your WiFi provider?
    # Have you tried other WiFi (e.g. the Wifi both at home and work)
    Cheers!
    ...Roland
    </blockquote>
    Hello Roland,
    No proxy on the phone or wi-fi network.
    My ISP is Time Warner, but I supply my own router (Linksys e4200)
    And this happens on every wi-fi network, at home and away from home.

  • HT4085 How to not use side switch or mute

    How do you not use lock rotation or mute at the same time, my iPad only lets me do one at a time, and I don't want mute but I want my iPad to be able to rotate, is there a setting to get rid of both? I have IPad with retina display (newest)

    The function that isn't being controlled by the side switch above the volume control is instead controlled via the left-hand end of the taskbar - so if the switch on the side of the iPad is controlling rotation lock, then double-click the home button to open the taskbar at the bottom of the iPad's screen, swipe that to the right, and the icon at the left-hand end of that will be for notification mute.
    If you want both 'off', then make sure that the switch on the side is off, and the icon at the elft-hand end of the taskbar is 'off'.

  • How to start App Server not using root

    Hi,
    I installed BEA Platform 7.0 with user root on Solaris. Wondering if there's
    a way to start the Application Server from another user?
    Thanks.
    Steve

    "Steven Ma" <[email protected]> schrieb im Newsbeitrag
    news:3d640873$[email protected]..
    >
    Hi,
    I installed BEA Platform 7.0 with user root on Solaris. Wondering ifthere's
    a way to start the Application Server from another user?
    Thanks.
    Steveif you do a "chown -Rh myuser:mygrp <WLS_Inst_dir> and use a Port above 1024
    as Server Listen Port, it should work with another user.
    I haven't tried in WLS 7 but with WLS 6.x it works fine.
    alexander

  • I can not use  camera switch control of accessibility. Ios8.1

    hi, i have iPad Air with Ios 8.1  but i want to use my camera for siri or something...
    unfortunately the Button of switch control is Inactive totally.
    i don't know how can i use it.
    Regards
    M.oMMshi

    When you open your camera app, does it say "HDR on" at the top?
    HDR photos are better quality but take up much more space.
    Also, go to Settings>photos and camera.  Scroll down to "keep normal photo".  Is it on?  This feature saves a normal copy and an HDR copy of every photo you take.
    I bet your friend has this feature turned off along with the HDR as well.

  • How do I get rid of the Not Using SoftArtisan File UP notice that is slowing down my uploads to class where I teach?

    How do I get rid of the Not Using SoftArtisan File UP notice that is slowing down my uploads to class where I teach? A notice now appears every time I upload an image to class as an attachment that says, Not Using SoftArtisan File UP, and this appears to be slowing down my uploads tremendously. I want to get rid of this. I never used it before and don't need it and don't want it. I just want the uploads to work like they did before this idiotic notice started slowing things down.

    Hello,
    '''Try Firefox Safe Mode''' to see if the problem goes away. Safe Mode is a troubleshooting mode, which disables most add-ons.
    ''(If you're not using it, switch to the Default theme.)''
    * On Windows you can open Firefox 4.0+ in Safe Mode by holding the '''Shift''' key when you open the Firefox desktop or Start menu shortcut.
    * On Mac you can open Firefox 4.0+ in Safe Mode by holding the '''option''' key while starting Firefox.
    * On Linux you can open Firefox 4.0+ in Safe Mode by quitting Firefox and then going to your Terminal and running: firefox -safe-mode (you may need to specify the Firefox installation path e.g. /usr/lib/firefox)
    * Or open the Help menu and click on the '''Restart with Add-ons Disabled...''' menu item while Firefox is running.
    [[Image:FirefoxSafeMode|width=520]]
    ''Once you get the pop-up, just select "'Start in Safe Mode"''
    [[Image:Safe Mode Fx 15 - Win]]
    '''''If the issue is not present in Firefox Safe Mode''''', your problem is probably caused by an extension, and you need to figure out which one. Please follow the [[Troubleshooting extensions and themes]] article for that.
    ''To exit the Firefox Safe Mode, just close Firefox and wait a few seconds before opening Firefox for normal use again.''
    ''When you figure out what's causing your issues, please let us know. It might help other users who have the same problem.''
    Thank you.

  • Change network address of acs server

    Put in a new backup ACS server and the senior guy put in temp host address. Now
    need to change the temp host address to its permanent address but need a little clarification. Do you just change it in the Windows srvr 2003 tcp/ip stack or do you need to change it also inside the CSACS app?? Can't find it in the manuals easily.

    Yes you'll need to change ACS config. Just locate the AAA Server entry for the server (in Network Config) and set the ip address to the new value.
    Or you can always just enter the server name instead in case the address changes again.
    tip: in network config you can enter DNS names instead of ip addresses for devices & aaa servers.

  • Can not add pdf files to my e-mail-it just grinds on a 851kb file (11kb worked)not using gmail. windows xp. recently wnld java update.

    downloaded some java update for downloading support from Ontrack. SInce then firefox will not attach pdf files to my e-mail. not using g-mail, using yahoo. Windows XP. It will add small files (11kb) but just grinds on a 851kb file and never attaches it.If I choose to unclick "enable java" - the "attach files" box disappears from the attach files menu.

    '''Try Firefox Safe Mode''' to see if the problem goes away. Safe Mode is a troubleshooting mode, which disables most add-ons.
    ''(If you're not using it, switch to the Default theme.)''
    * You can open Firefox 4.0+ in Safe Mode by holding the '''Shift''' key when you open the Firefox desktop or Start menu shortcut.
    * Or open the Help menu and click on the '''Restart with Add-ons Disabled...''' menu item while Firefox is running.
    ''Once you get the pop-up, just select "'Start in Safe Mode"''
    '''''If the issue is not present in Firefox Safe Mode''''', your problem is probably caused by an extension, and you need to figure out which one. Please follow the [[Troubleshooting extensions and themes]] article for that.
    ''To exit the Firefox Safe Mode, just close Firefox and wait a few seconds before opening Firefox for normal use again.''
    ''When you figure out what's causing your issues, please let us know. It might help other users who have the same problem.''

  • A tech company just set up a wifi network in my house and does not use my existing TC; how do I get it in the network to serve as backup for my iMac? (I don't need it as a wifi access point anymore)

    a tech company just set up a wifi network in my house and does not use my existing TC; how do I get it in the network to serve as backup for my iMac? (I don't need it as a wifi access point anymore) thanks

    Just bridge the TC and plug it by ethernet into the main router.
    Bridge in v5 airport utility.
    In v6 it is under network.. change it from DHCP and NAT to Off bridge mode.
    Turn off the wireless.

  • I purchased a time capsule last year and we have been using for our backup of our apple devices (iMac, laptop, iPad and now 5 iPhones).  we have not used it as our router for wifi but would like to now switch to it. need directions for switching please.

    i am using time capsule for backup only but would like to switch to it for our wifi.  directions on apple discuss original set up of time capsule for wi fi but not switching from existing wi fi router.  were can i get help with this?

    Well, it depends on what ISP you use.
    Reply back with your ISP and connection type (cable, ADSL). Also, do you use an ISP router or do you have a modem connected to a router that you provide?

  • Can I use DHCP snooping and IOS DHCP server on the same switch stack

    Hello,
    I am shortly going to be deploying a Cisco CallManager solution for a customer whose network comprises stacks of Catalyst 3850 switches.
    There is no separate core/server farm switch so the CallManager servers, voice gateways and IP phones will all plug into the same stack and be in the same VLAN (not my choice!).
    For security we want to enable DHCP snooping and were planning on using the IOS DHCP server on the Catalyst switch stack.
    Will this work? - when I enable DHCP snooping in networks with separate access layer switches I set the uplinks to the core as trusted links.
    I am not sure whether DHCP snooping will work in this case. Do I need to set the VLAN interface on the switch as trusted, is this even possible?
    Unfortunately I do not have access to a layer 3 switch to test this at the moment.
    Thanks

    Nope.  That's the issue.
    They'll sync on a third device acting as a hotspot, but the device sending a signal is not "on" the network it creates so the airport is all by itself on that network.  At least that is what it looks like to me.  Anyone have another take on it?  Seems pretty silly that an iPad can put out a wifi signal, an Airport Express can receive a wifi signal, and yet there is no simple way to get them to communicate under this particular condition.

  • Mail does not use correct outgoing server

    Problem
    Mail in Mavericks (and also IOS6 snf 7) does not use the outgoing smtp server associated with the account being used. This results in either a failure to send or mail being put into the wrong "Sent" folder.
    Background
    I have most of my non-icloud mail pulled down to a home server from which my laptops and ios devices access various accounts using imap. The local home server also provides smtp and relays all mail to my ISP. Recently I have been switching from an old home server (Mac Mini) to a new one (Raspberry pi running the debian Raspbian version with fetchmail,  Dovecot and postfix setup).
    While making the changeover I had access to both the old server and the new server enabled on my laptop. Naturally the majority of the settings (Name, email address etc) were the same although the name and address of the server to be used for both incoming and outgoing mail were different. This seemed tp work fine for incoming. However when I tested outgoing mail the copy that should appear in the "sentt" box  went missing. This usually indicates some mistake in the setting of the sent mail folder on the accounts but this all checked out.
    I eventually found the missing outgoing mail intended to go through the new server in the sent box on the old server. Further trials showed that no matter what I did the outgoing would always default to the old (and therefore first set up) outgoing server.
    Deleting the old account and the old outgoing server of course should cure the problem and will eventually be the solution for me when I kill the old server. But i wanted to get to the bottom of the problem in case it reappeared in other contexts. Checking the "use only this server" box produced failure to send rather than the correct result.
    Trialing various alterntaive settings showed that the problem occurs when there are two outgoing servers with the email address in the settings and the user name on the outgoing server name being the same. I had assumed that changing the description field would distinguish between the various settings; however this did not work. Changing the Name Field did work eg by putting (O) after my name.
    It appears therefore that mail selects the outgoing server on the basis of email address (with the full name included) and user name (trrespective of the actual server or the Description that shows in the smtp server listing. In some ways this is logical but it produces problems in the context I have described and would also be a difficulty if you wanted to use an alternative server when in a different location.
    I have trawled support and elsewhere for any thing similar. Lots of mail problems (don't get me started on the way icloud loses outgoing each time you edit the list!) but I have not found any posts on precisiely this point.
    IOS devices seem to have similar problems, but a quick attempt at a similar solution does not work, and I cannot be bothered  to test the options. I will simply clean them out and put in the new accounts.
    Advice
    Grateful for any comments or advice from people who have encountered similar problems and whether my diagnosis if correct. Have I missed any obvious corrections that would clear this up. I do not know whether this is a Mavericks issue or also appears in earlier OSX versions.
    CPE

    Peter,
    Where ever the Sent and Trash folders show in the Sidebar, highlight first one, and then the other, followed by clicking on Mailbox in the Menubar, and choosing Use This Mailbox For, and choose the function.
    Keep us posted on your progress.
    Ernie

  • Even when I charge my Mac Pro to the full bar, the battery seems to be drained even when I am not using it. Example, after charging it full, i switched it on the next day and its 79% battery left. Is there something wrong? help please

    Even when I charge my Mac Pro to the full bar, the battery seems to be drained even when I am not using it. Example, after charging it full, i switched it on the next day and its 79% battery left. Is there something wrong? help please

    Assuming you are disconnecting from line power, when you say switched on, do you mean it was shutdown or in sleep mode?  If sleep mode the battery will still drain because sleep still keeps some things active and the battery does drain a little.  However, to go from 100% to 79% charge overnight is a bit excessive in sleep mode.  Unless you have some processes set to activate over night by the cron file and do things like backup the system.
    What are the statistics on the battery, the apple in the upper left corner, About This Mac, More Info, System Report, Hardware, Power...things like battery Condition, Capacity, remaining charge, voltage, current.

Maybe you are looking for

  • Has anyone solved or worked around the After Effects CC red flash frame glitch?

    I can't find any mention on any forums of the After Effects CC red flash frame glitch later than Feb. 2014. I just installed 12.2 (which was my first CC version) on my macpro and started getting the red flash frames randomly, but with increasing freq

  • OBIEE 10g - Ragged & Skip Level Hierarchy

    Hi Frnds, I'm aware of the fact that OBIEE 11g supports Ragged & Skip Level Hierarchy. But I'm looking for some heads up while implementing the same on OBIEE 10g using Oracle DB as source. I have done this before for Essbase Data Source but now waiti

  • Symbol for "per thousand" in smartforms

    Hi I need to print the symbol for "per thousand" (or "per mill" or whatever it is called in english) in a smartform textmodule -> ‰ But whenever I paste it from Word it is being replaced by an #. I also tried ALT-codes with no further success. Does a

  • How to see data records of idoc?

    Hi Can anybody tell me how can i see the data records of idoc.. i think its stored in EDID4 table..but i am not able to see the sdata field

  • Material on upgradation form 4.6 to ECC 6.0

    Hi, Can any one help me out with some material consisting on Upgration methodologies form 4.6 to ECC6.0 Regards, Karthick