IOS Access Point Bombards TACACS+ Server with Requests

Problem: When using the web GUI to manage an IOS access point such as the AP350, AP1100, or AP1200, and when using TACACS+ to authenticate the HTTP accesses, the access point will send numerous authentication requests to the TACACS+ server for each web page accessed.
Workaround given by cisco was to use single-connection tacacs server.
My question:
How to implement this command? Is it as below
"tacacs-server host x.x.x.x single-connection port 49 key test".
I've tried using this command but still getting numerous authentication request.
Any help?
regards,
Ganesh

We experienced similar problems. We were instructed to use local authentication at the current time. Something about HTTP requiring authentication for each part of the page that accesses data. The configuration line is:
ip http authentication local
The single connection did not help. We were also advised that if we required ACS HTTP authentication to use RADIUS because it scaled better than TACACS and would not be as impacted as TACACS. If neither of these are an option, another workaround is to, disable logging "passed authentications". We tested this and it prevented our ACS server from pegging the cpu, memory and I/O write queues. We opted for local authentication because the lack of "passed authentication" logs impacted our troubleshooting.
Good Luck
Gerry

Similar Messages

  • When I access a windows files server with the mac I am adding .apple (hidden files). How can I prevent this.

    When I access a windows files server with the mac I am adding .apple (hidden files). How can I prevent this?

    Look for a program called BlueHarvest. I'm not sure if it still works with Mountain Lion.
    I believe your file server can be set up to handle the metadata files, but I suppose that would depend on the Server software and your IT staff.

  • Wireless access point no longer working with ios7

    Upgraded to ios7 and did not change anything. Wireless access point still recognised in settings however no internet connection possible. What's wrong or different with iOS 7?

    1. Turn router or access point off for 30 seconds and on again.
    2. Settings>General>Reset>Reset Network Settings.

  • Access point as Dhcp Server

    is there a way to use the access point as a dhcp server?

    No The AP is a layer 2 bridge innetwork terms, (not to be confused with the WLAN bridge products.) Think of it as a hub with one ethernet ports and allow mutilple wireless devices
    You will need to have a DHCP server on the ethernet side to provide DHCP to your wireless clients

  • Have just found a hickup on the Lion software 10.7.2 When using a access point that you name with letters that is only in Norwegian æøå you will loose connections and only get time out. So the solution will be to rename the access point.

    Any solution beside to rename the wifi access point without the spesial Norwegian letters æøå?

    Your points match mine pretty well,though here are some thoughts:
    1. I thought about this theory myself this morning (iTunes possibly causing more issues), but I haven't been able to verify it.
    2. When I set up a new user it seemed better for a while, but the issue croppped back up. Yesterday I fully wiped the machine and reinstalled from scratch. I did not reimport my user from TimeMachine, but the problem has come back. My thinking was that I might have some really old software or prefs hanging around causing the issue. No dice.
    3. This is my current theory of the issue, so my next step will be to pull the RAM from Crucial and see how the system behves. IF that doesn't eliminate the problem, I'll pull the factory installed RAM and replace it with the 3rd party RAM. The odd thing is how many people seem to have similar issues - I know two personally, and have seen several posts on forums. I think the most common point for this happening was the 10.7.2 update, which would point to software as the culprit.
    4. That matches my experience.
    My hope is that this will be repaired in the forthcoming 10.7.3 release (current production version is 10.7.2), but otuside of what I noted above, I'm at a loss.

  • How to access data in different server  with flex3 remoteobject

    I am trying to access data from cfc that is in different pc
    through network and coldfusion 8, flex3 and sql server are in diff.
    pcs. So how can I access the cfc file in different pc using remote
    object which will return the data from another server using dsn? I
    can connect to the service if coldfusion and flex are kept in same
    pc. How can I access it in diff. pc?what will be destination and
    source param values?
    Any help is appreciated.

    Hi,
    You should be able to achieve this by changing the end point
    URL of the channel you are using in the services-config.xml. The
    end point URL should point to the server where your CF is deployed.
    Hope this helps.

  • Access Mail on Mac Server with non-Apple device

    I currently have a Windows server with Exchange installed and am considering replacing it with a Mac Server. IF I do that, can my non-Apple Windoes 7 & XP computers access Mail on the Mac Server as they now do with Exchange?

    Yes and no.  You will be able to access mail via IMAP but you will have a dickens of a time getting Address Book and Calendars to work.  Apple uses CardDAV and CalDAV respectively for these services.  Your options on WIndows are limited.  See here for options:
    http://caldav.calconnect.org/implementations/clients.html
    http://carddav.calconnect.org/implementations/clients.html
    If you are looking for something to "replace" Exchange, then check out Kerio Connect.

  • Firewall considerations ZfH Access point to MGT server

    Hi there,
    According to the TID10095278 the ZfH access point talks to the ZfH
    Management server on port 2398. I presume the Access point does all the
    initiating to the Management Server.
    I know to can use HTTP encapsulation on port 80 but I've never got that to
    work.
    In the case where you want to locate an Access point on the public side of
    a firewall and the Management Server on the private side. I presume an
    inbond rule of 2398 needs to be allowed using TCP.
    In the paragraph in the TID "In some cases the ZfH will send a UDP packet
    to the Access Points over port 2398, but this is to optimize some things,
    and will work correctly if this packet isn't delivered correctly." I'm
    presuming this means from the handheld to the access point.
    Does anyone have any thoughts on this?
    Thanks,
    Fred.

    Fred,
    It appears that in the past few days you have not received a response to your posting. That concerns us, and has triggered this automated reply.
    Has your problem been resolved? If not, you might try one of the following options:
    - Do a search of our knowledgebase at http://support.novell.com/search/kb_index.jsp
    - Check all of the other support tools and options available at http://support.novell.com in both the "free product support" and "paid product support" drop down boxes.
    - You could also try posting your message again. Make sure it is posted in the correct newsgroup. (http://support.novell.com/forums)
    If this is a reply to a duplicate posting, please ignore and accept our apologies and rest assured we will issue a stern reprimand to our posting bot.
    Good luck!
    Your Novell Product Support Forums Team
    http://support.novell.com/forums/

  • Access Points not being associated with Controller

    I have a 4400 series controller capable of 25 access points. I currently have 11 deployed and the controller is only seeing 10. Also if I have the need to reset a switch the AP is hanging from it can take days for the AP to find itself again, if it finds itself at all. Any Thoughts? I am new to this technology.

    I double checked and it is set to Auto/Auto. It is connected to a Cisco Catalyst 6513 on a WS-X6454-ge-tx board. It's port is setup as a trunk but I am having difficulities setting it to a dot1q trunk. I was trying to use the "switchport trunk encapsulation dot1q" command but the only command that board will give me is a "switchport dot1q ethertype 600-FFFF" command. When I type in "switchport trunk ?" I get no encapulation only Allowed, Native and Pruning. I am using an unused VLAN for my trunk.I also double checked my ports my AP's are on and they too are set to Auto speed / duplex. As far as performance Since this is a new setup we have had limited users at a time testing but all have been getting about 54Mbps. Any other thoughts or guidance would be greatly appreciated. I have tried getting onto the Cisco site again this morning but it is DOG SLOW. Not sure what that is about. Everything else seems fine.

  • 2702-UX-K9 Access Point will not associate with controller.

    Hi,
    I recently purchased nine new 2702 APs.  Two of them will not associate with the controller.  I realized they they had a different part number.  They ended with UX-K9 instead of -K9 like the others.  It turns out that these are new AP that are universal for any country.  They APs find the controller but need some sort of password to pull the config down.  I"m not sure what this could be? 
    From console of AP @ boot....
    examining image...
    ipv6 enable
      ^
    % Invalid input detected at '^' marker.
    ipv6 address autoconfig
      ^
    % Invalid input detected at '^' marker.
    ipv6 address dhcp
      ^
    % Invalid input detected at '^' marker.
    %Error opening capwap:/ap3g2 (Incorrect Login/Password)
    Download image failed, notify controller!!! From:8.0.110.0 to 0.0.0.0, FailureCode:4
    archive download: takes 0 seconds
    *Mar 18 20:16:49.000: %CAPWAP-5-DTLSREQSEND: DTLS connection request sent peer_ip: 192.168.12.10 peer_port: 5246
    *Mar 18 20:16:49.435: %CAPWAP-5-DTLSREQSUCC: DTLS connection created sucessfully peer_ip: 192.168.12.10 peer_port: 5246
    *Mar 18 20:16:49.435: %CAPWAP-5-SENDJOIN: sending Join Request to 192.168.12.10perform archive download capwap:/ap3g2 tar file
    *Mar 18 20:16:49.439: %CAPWAP-6-AP_IMG_DWNLD: Required image not found on AP. Downloading image from Controller.
    *Mar 18 20:16:49.439: %DTLS-5-SEND_ALERT: Send FATAL : Close notify Alert to 192.168.12.10:5246
    *Mar 18 20:16:49.443: %LWAPP-3-CLIENTERRORLOG: Config load from flash failed. Initialising Cfg
    *Mar 18 20:16:49.451: %LWAPP-3-CLIENTERRORLOG: Config load from flash failed. Initialising Cfg
    *Mar 18 20:16:49.455: capwap_image_proc: unable to open tar file
    *Mar 18 20:16:49.715: %CDP_PD-4-POWER_OK: Full power - NEGOTIATED inline power source
    .... Check out the attached log file for more details.  
    Thanks in advance for the replies! 

    Rasika,
    I have the same issue on my home 2504 with these 2700 UX, I have tried code 8.0.100.0, 8.0.110.0 (Docs say this is the min version supported), and even 8.0.115.0 (latest available) still no dice. The AP won't register, and gives the error stated above. I am seeing 2 images available for the AP, the AP shipped with the later image but  I AP recovery isn't working because it say's unable to find image with XX in the name? I see the TFTP logs, and name the file accordingly no dice, then the unable to find file name -XX pops up too. As you know I am busy during the day this week, but let's jump on a skype and take a look later maybe you have seen something I haven't?
    For good measure, also attempted to join a 3650 here at the house IOS-XE 3.6 no dice, going to try 3.7 too tomorrow, It worked for the 3700 UX AP's we had??

  • Access MySQL Database on Server with PHP Services

    Hi there
    There are lots of tutorials on how to connect to a MySQL database on your local machine but I'd like to access a database on my server.
    When creating a new Flex Project the wizard asks me to define a Web root and a Root URL. I used '/home/ecoflexer/public_html' as Web root and 'http://ecoflexer.com' as Root URL. However, the Web root coudn't be validated. So I've chosen the local folder 'C:\ecoflexer' as Web root. Though it was possibly wrong Flash Builder generated a debug folder at the defined location. After that I went to "Connect to Data/Service" and selected "PHP Service". I tried to generate a sample using the same credentials I use for a standard PHP login script ("Server Port" was left empty). After clicking on "Connect to Database" Zend was installed and returned an error. 'gateway.php' couldn't be found on 'http://ecoflexer.com/testProject-debug/gateway.php'.
    So I went into my local Web root and copied the 'testProject-debug' folder to my server to the destination the previous error mentioned. Then another error occured concerning a Zend file. So I went back and copied the whole 'ZendFramework' folder as well to my server. It connects now successfully to my database. I can chose a table but soon after that the introspection of the service fails. I modified the 'amf_config.ini' by adding 'webroot =/home/ecoflexer/public_html' and 'zend_path =/home/ecoflexer/public_html/ZendFramework/library' but it's still not working. Anithing I've done wrong or forgot to do?
    Cheers!
    ecoFLEXER

    iam doing client server application,the database is on the server,and iam doing the log in part,so i need to access the database to match the entered user name and password?so i should implement the accessing database part on the server side with the above code,right?i didn't test that i will test it now,but i thought that it's a different way

  • Remote access files on remote server with KM iview

    Hello experts,
    We want that user can upload and download files via a KM iview which point to a remote server folder.
    I know some about webdav.
    Could you please tell which method is the best way?
    BR,
    Jianguo Chen

    Hi,
    first of all you would have to make the files from the remote server available in the portal. Depending on what your remote server supports you can integrate it via WebDAV or FileSystem Repository Manager (see http://help.sap.com/saphelp_nw70/helpdata/en/e3/923227b24e11d5993800508b6b8b11/frameset.htm for further details).
    When this is done you can simply use KM Navigation iViews to allow your users to upload/download files.
    Regards,
    Holger.

  • Netware Access Point won't connect with Windows, but will connect to Macs

    Recently we acquired Cable Internet Service, which was brought into the X Serve Network Card. After that it is transfered onto the second network card which then dishes out DHCP to all our client computers (including laptops). However, it appears that only the Macintosh laptops are obtaining internet, while the windows laptops show they have a wifi connection, but the browser applications refuse to launch on everyone of them. Any suggestions would be very helpful. Thank you.

    When you reinstalled iTunes, you may not have done it correctly. It needs to be done in a specific order, or it will just compound your problems. There is a problem with the latest iTunes in Windows, and it has been requiring a removal and reinstallation. See this support document support.apple.com/kb/HT1923 and remove and reinstall by following these instructions exactly. This should fix your problem.

  • Pls recommend a "n" access point that plays nice with APEn. THANKS

    Good day.
    I wish to use my newly purchased SlingBox on the ''n" side of my g/n dual band network.
    So, I need to get the slingbox and my desktop, G5, presently using the APexpress 'g'.
    Thanks tons.
    P.S. The slingBox is outstanding!!!!

    Hello, here in forum are several threads with discussing same issue, for example here. The result is, that using 2.0.7.4 Firmware on both AP and Repeater breaks Repeater functionality. With 2.0.6.1 firmware on AP and 2.0.7.4 on Repeater connectivity should work.

  • Need some advice for AP IOS upgrade (Wireless Access Point 3702 Series) ?

    Hi to all
    I recently purchase a Wireless Access Point (AIRCAP 3702E-E) with 4 antenna, i will use this device like wifi hotspot in my home.
    I would like to upgrade it but i see two kind of AP IOS :
    Lightweight AP IOS Software
    Autonomous AP IOS
    What are the difference ?
    In case of Lightweight AP IOS Software will be the one to choose, i have multiple IOS :
    Wireless Lan, ap3g2-k9w8-tar.152-4.JB4.tar
    Wireless Lan Recovery, ap3g2-rcvk9w8-tar.152-4.JB4.tar
     Someone can tell me what is the difference between these two versions ?
    Best Regards.
    Elrick.

    Hi Elrick,
    Cisco AP AIRCAP3702E is Cisco enterprise unit.  Cisco small business support WAP4410N, WAP121, WAP321, WAP551, and WAP561 AP. However I will answer your questions.
    Lightweight AP ISO you can use it ONLY if you connect AP to wireless controller
    Autonomous AP ISO for manage and modify AP  by it self not required wireless controller.
    Thanks,
    Moh

Maybe you are looking for

  • Extending Wi-Fi with 2nd base station

    I just upgraded to an Airport Extreme base station. I also use 2 AE's to print wirelessly and also a 3rd to play my stereo remotely. The printers work fine, but the stereo apparently is borderline for distance and skips a lot. I still have my origina

  • WLP Tech Preview

    This newsgroup was created to facilitate on-line discussion of questions and issues pertaining to the WLP / WLW 9.2 Tech Preview. For more information on the Tech Preview program, visit: http://wlp.bea.com/WLP92TechPreview/ To enroll in the Tech Prev

  • Vendor Master changes-Notification

    Is there any standard way where,a notification can be generated for any changes done in vendor master???? Apperciating ur immediate feedback.

  • ZEN SLEEK PHOTO & WINDOWS 98 SE!! AAAAAARGGH!

    Hi! Apologies in advance if this problem has already been raised and addressed, but due to a mismatch of information, I find I have now invested in a lovely mp3 player (namely ZEN SLEEK PHOTO) I can't use. The problem? It's mimimum OE requirement is

  • Form Customization

    Hi to all, i am facing a problem regarding FORM CUSTMIZATION in my form 2 date columns is there start_date_active and end_date_active for this column i used the trigger KEY-LISTVAL IF :SYSTEM.MODE != 'ENTER-QUERY' THEN CALENDAR.SHOW; END IF; AND IN P