RADIUS failover not working in wired 802.1x (CATOS switch)

I am setting up a pilot group for wired 802.1x testing. I have it working correctly on a C2950 and C3550s. I am having trouble with the RADIUS failover on my CATOS C4006 series switches. When I disable the primary RADIUS Server to test failover, the switch never fails over to the backup RADIUS server and thus wired 802.1x fails. Am I missing something?
Any help is appreciated. Here is my config:
#version 8.4(7)GLX
#radius
set radius server 10.30.XX.XX auth-port 1812 primary
set radius server 10.18.XX.XX auth-port 1812
set radius timeout 30
set radius key EE08361
Set dot1x system-auth-control enable
set port dot1x 5/27 port-control auto
all radius and dot1x settings are at their default values
Any takers??!

I have the same setup as yours. I use Steelbelt
radius 6.0.1 on Linux and I have Cisco 2960
catalyst. I use 802.1x over Ethernet with
PEAP, as seen below:
C2960#sh run int g0/23
Building configuration...
Current configuration : 133 bytes
interface GigabitEthernet0/23
switchport mode access
dot1x pae authenticator
dot1x port-control auto
dot1x guest-vlan 668
end
C2960#
C2960#sh run | inc dot
aaa authentication dot1x default group radius
dot1x system-auth-control
dot1x guest-vlan supplicant
C2960#sh run | inc radius-
radius-server host 192.168.15.10 auth-port 1812 acct-port 1813 key xxx
radius-server host 10.250.97.26 auth-port 1812 acct-port 1813 key xxx
C2960#
Everything works and when I shutdown the
radius server process on host 192.168.15.10,
"sbrd stop", it still works with the secondary
radius server 10.250.97.26.
The difference between yours and mine is that
I am running IOS instead of CatOS.
System image file is "flash:c2960-lanbasek9-mz.122-25.SEE4.bin"
David

Similar Messages

  • My GoFlexPro for Mac external drive will not work and freeze Finder after I switched to Mountain Lion. Anyone same trouble?

    My GoFlexPro for Mac external drive will not work and freezes Finder after I switched to Mountain Lion. Anyone same trouble?

    Search this site for many reports of problems with GoFlex drives.

  • SAP ECC 6.0 SR3 Cluster failover not working in AIX with DB2 UDB V9.1 FP6

    Hi Gurus,
    We have installed the SAP ECC 6.0 SR3 High Availability  with DB2 UDB V9.1 FP6 in AIX cluster environment.
    After installation we are doing the cluster fail test.
    Node A
    Application Server
    Mount Points:
    /sapmnt/<SID>
    /usr/sap/<SID>
    /usr/sap/trans
    Node B
    Database Server
    Mount Points:
    /db2//<SID>
    The procedure followed to do the cluster failover:
    We have down the cluster on Node A and all the resources of the Node A has been moved to Node B.
    On Node B when we issued a command to start the SAP. It says u201Cno start profiles foundu201D
    WE have down the cluster on Node B and  moved the Resource from Node B to Node A .  There the db2 User IDu2019s are not available. We have crated the user Idu2019s manually on Node A. however it did not work.
    Please suggest the procedure to start the sap in cluster failover.
    Best Regards
    Sija

    Hi Sija,
    Can i have detailed scenario in your cluster configuration.
    Means you are saying that going to start cluster package manually, if it is right please make sure that you had the same copy of start, instance profiles of NodeA to Node B. Means you need to maintain two startup, two instance profiles for both nodes. In a normal situation it will picik the profile of node A to start databse from A node. But in a failover situation it will not pick node A profile to start, it should pick Node B s profiles.
    Just make a copy from node A and change the profile name accordingly to Node b. Then try to restart.
    Regards
    Nick Loy

  • WRTU54G-TM T Mobile, works fine in wireless but does not work in WIRED connection

    This is really weird. This router has worked fine for little over years. It has it's up's and downs but yesterday. It stopped working on the wired mode. I can see my computers connected on the DHCP list but it does not show internet. On my WIRED computers connected to the router, it says no internet access and cannot find gateway. it is setup as DHCP automatic like it has been for ages. I used the setup wizard with no success. IT SAYS NO ROUTER FOUND, please check connections. 
    The 4 ethernet lights are green and on completely on when nothing is connected to it at all on the wires. 
    Now wireless is completely fine and I can see the router and everything else but connecting WIRED just doesn't work. It can see my wired computers on the DHCP client list but anything wired has no internet or connection.
    I tried even wiring it directly to my laptop and it does the same thing. But connecting wireless is perfectly fine and dandy.

    All the 4 Ethernet port lights are lit up when nothing is connected to the router.
    I think the router is not working properly.
    Do you get a valid IP address like 192.168.1.xxx  on your wired computer?
    Try to ping the default gateway and see if you get replies from the router.
    You are able to access the Internet on the wireless computer?
    What IP address do you get on wired and wireless computer?

  • Failover not working while connecting to Oracle 11g database

    Hi,
    We have a J2EE application that connects to Oracle 11g database.
    The connection URL we are using is as below
    jdbc:oracle:thin:@(DESCRIPTION =(SDU=32768)(ADDRESS=(PROTOCOL=TCP)(HOST=abc.hostname.com)(PORT=1525))(ADDRESS=(PROTOCOL=TCP)(HOST= xyz.hostname.com)(PORT=1525))(CONNECT_DATA=(SERVICE_NAME=PQR)))
    The issue that we are facing is, the database failover is not working.The application only connects to the first host in the TNS entry.Evertime there is a failure in the connection to the first host,manual steps are required to swap the hosts.
    This started happening after we upgraded Oracle DB from 9i to 11g.
    We are using the client jar of 9i to connect to 11g. Could this be causing the problem?
    Thanks In Advance.
    -Tara

    889517 wrote:
    Yes, you are right. Nothing else was updated.
    The application still works as expected except the failover.If you are correct then I seriously doubt it has anything to do with java. It would be something to do with Oracle and/or network infrastructure.
    If not then it is some small problem with the driver. You can try updating the driver but I wouldn't expect a fix.

  • Refine Edge Radius Tool Not working

    Hi
    Today my refine edge is not working, although it used to work. When I select with the quick selection tool and click refine edge, when I pick the radius to smooth it out ,it makes a strange thing
    Please Help
    I made a screenshot for the screen,Note  this is still, although I change anything in the Refine Edge Options
    thnx in advance

    I ran into the same problem using the image you posted. Although there was something not right about the edge sharpness and color density where the car met the white surround I was able to get the result you are after.
    This was the sequence:
    1.  Toss the Background layer lock in the trash. It becomes Layer 0
    2.  Cmd + new layer symbol to place a blank layer below Layer 0
         Then, Edit > Fill the blank layer with white
    3, Choose Layer 0 and use the Quick Selection tool to select the car
    4. Choose Refine Edge in the Options bar:
         View Mode > View Mode > Marching Ants
         Brush Size (Options Bar): 200  This is humongous and counter-inuititve, but hang in there.
         Radius 0, Smart Radius
         Paint the white area keeping the + marker a fair distance from the marching ants
         Output: Decontaminate colors (50) New Layer with Layer Mask
    The result is a vastly improved result but the mask is a bit weak in the troubled area. sL
    Option click on the the mask in the Layers panel to reveal the mask
    Curves > Move straight line of Curve to increase contrast via black endpoint
    I think the root of the problem is the lack of edge sharpness in the image. Using Refine Edge when the edge is soft can be pain.

  • Failover not working in a cluster environment asks Relogin to Application

    Hi,
    I have setup cluster on weblogic and deployed CRM (ejb/ear) application.
    When I stop managed server which is handling request other managed server picks the request but it asks for relogin.
    I think failover is not working properly.
    Could you please help?
    Thanks,
    Vishal

    Hi Kalyan,
    Please See below Diagnostics:
    Managed Server1:
    ===================================================
    Date: Tue Sep 04 18:33:12 IST 2012
    DdCompnt=11,SessionContext=7,CurrJvmHeapMB=235,Bos=2,JForm=1,MaxBoRowCount=493,JApp=13,JField=1,JDdField=1,JSession=6,Sessions=7,JBaseBo=2,Misc=74,JPTrace=1,LpmErrors=1,Forms=1,Active Sessions=6,JDdTable=1021,MaxJvmHeapMB=467,MaxBos=18,BoRowCount=33,JError=1,JFields=1,UtlRecs=175,FlexAttr=-5,UserContext=3
    Managed Server2:
    ===================================================
    Date: Tue Sep 04 18:33:20 IST 2012
    DdCompnt=11,SessionContext=8,CurrJvmHeapMB=226,JForm=1,JApp=13,JSession=7,Sessions=8,Misc=148,JPTrace=1,Forms=1,Active Sessions=7,JDdTable=1124,MaxJvmHeapMB=472,UtlRecs=81,FlexAttr=-5,UserContext=4
    Free Java Heap Memory: 258400 KB
    Total Java Heap Memory: 495779 KB
    I tried to open many sessions. Its assigning randomly, but when I kill Managed Server2, its corresponding sessions are not working.
    System Error error executing LPoms.getUserContext()
    Also I found following warning in Weblogic logs.
    <Sep 4, 2012 6:26:15 PM IST> <Warning> <Socket> <BEA-000402> <There are: 5 active sockets, but the maximum number of socket reader threads allowed by the configuration is: 4. The configuration may need altered.>
    Thanks for your immediate help.

  • Range Extender not working on Wireless 802.11n

    I've started a new topic to ensure this gets the correct attention.  For the back story see this forum topic. http://community.linksys.com/t5/Range-Expanders/Can-t-find-Range-Extender-after-installing-firmware-...
    Long story short the RE1000 Range Extender is not working (connecting, extending) on Wireless 802.11n after the firmware upgrade.  As a result the device is not useful because the devices that attempt to connect to it are NOT expecting the wireless level to change and thus just get stuck in limbo land.
    My wifi network (as of writing this) SSID is called "SeriesOfTubez" and is broadcasting on b/g/n. However as you can see by the wireless network survey (from the router) all other devices connect on "n" but the RE1000 is only connecting/broadcasting on "b/g" (not "n")
    Is there a setting somewhere to force it to use "n" or does Cisco/Linksys need to fix the firmware again to get it right? or do I need to take the unit back to the store and buy another brand that properly supports 802.11n?

    Great to hear that, Steve. Keep your eyes open and observe your connection. Don't worry, Linksys Support is available 24/7. I've had a number of great support experiences from them even at ungodly hours! 

  • Volatile DLU will not work over wired interface.

    Hi all,
    I've got a weird one that has me stumped. We've got a DLU policy that is working well for our teacher accounts. It is set to user user source credentials, is not volatile, and hasn't caused us issues.
    We're starting to move over and get new Windows 7 machines on the student workstation side. For our students, attempting to get a volatile DLU user set up, with a cache. In testing on desktop machines, it is failing. I'm working now on testing with a laptop and the weirdest thing keeps happening. The DLU policy applies and logins work great with a test student user - but only when attached to the wireless network. Over the wired interface (with wireless completely off), it will not work. The novell client login works, then the dreaded Zen login box comes up, with the name of the volatile login account (that should be local) in the user box. It will not go forward from that point unless I put in a local user name/password. If I do this, I can login thru the zen icon all day long, over the wired interface. This is very similar to the issues we are having on the student workstation machines, or I would just call it odd and move on.
    I've simplified out my network locations to just be one network for now, so that is out as a cause. Completely disabling the wireless adapter, so that it does not show in the zmg-messages log at all did not help either. I can remote control it in that state, and it talks to ZCC.
    The servers are 11.2.2 - Vmware Appliances, have not applied the monthly updates but have them in the queue. Agent the same on the workstation. If anyone has any ideas, I'd love to hear them.
    Thanks
    Pete

    OK - Got this solved. Had applied a registry edit for teacher laptops in the summer based on this TID Support | How to configure "Computer Only Logon If Not Connected" functionality . The login issues only occurred after a teacher account had logged in. The student workstation image had the wired interface listed as 'Public', which caused the novell client to passthru and silently not attempt the login, hence the odd behavior. Oops. Have now limited that regedit to only applying to the teacher laptop workstations. Since these are some of our first student workstations, its not reared its head before. Oh well.
    Pete

  • CVP Failover Not working

    Hi,
    I have UCCE with CVP in my environment and also we are having 2 Call/VXML server for redundancy purpose. I have configured below command on VXML GW also created dialpeer towards my second call/vxml server to achieve redundancy but somehow my fail over is not working.
    My UCCE with primary CVP is working fine without having any issue.
    ip host mediaserver x.x.x.x
    ip host mediaserver-backup x.x.x.x
    Also I have used media_server ECC variable as 'mediaserver' to achieve redundancy.
    I'm not sure weather i am missing any other configuration to achieve the fail over.
    Please suggest.

    Thanks Chaitan for your reply.
    Yes, I am looking for redundancy as if CVP1 goes down, then calls should go to CVP2.
    We are not using SIP proxy in our environment. Please find dial-peer configuration which are targeting to CVP1 & CVP2
    dial-peer voice 7701 voip
     destination-pattern 77..
     translate-outgoing called 1
     session protocol sipv2
     session target ipv4:168.167.0.162 (CVP1)
     session transport tcp
     voice-class codec 1  
     voice-class h323 1
     dtmf-relay rtp-nte h245-signal h245-alphanumeric
     no vad
    dial-peer voice 7702 voip
     destination-pattern 77..
     translate-outgoing called 1
     session protocol sipv2
     session target ipv4:168.167.0.163 (CVP2)
     session transport tcp
     voice-class codec 1  
     voice-class h323 1
     dtmf-relay rtp-nte h245-signal h245-alphanumeric
     no vad
    Thanks

  • Not Working-central web-authentication with a switch and Identity Service Engine

    on the followup the document "Configuration example : central web-authentication with a switch and Identity Service Engine" by Nicolas Darchis, since the redirection on the switch is not working, i'm asking for your help...
    I'm using ISE Version : 1.0.4.573 and WS-C2960-24PC-L w/software 12.2(55)SE1 and image C2960-LANBASEK9-M for the access.
    The interface configuration looks like this:
    interface FastEthernet0/24
    switchport access vlan 6
    switchport mode access
    switchport voice vlan 20
    ip access-group webauth in
    authentication event fail action next-method
    authentication event server dead action authorize
    authentication event server alive action reinitialize
    authentication order mab
    authentication priority mab
    authentication port-control auto
    authentication periodic
    authentication timer reauthenticate server
    authentication violation restrict
    mab
    spanning-tree portfast
    end
    The ACL's
    Extended IP access list webauth
        10 permit ip any any
    Extended IP access list redirect
        10 deny ip any host 172.22.2.38
        20 permit tcp any any eq www
        30 permit tcp any any eq 443
    The ISE side configuration I follow it step by step...
    When I conect the XP client, e see the following Autenthication session...
    swlx0x0x#show authentication sessions interface fastEthernet 0/24
               Interface:  FastEthernet0/24
              MAC Address:  0015.c549.5c99
               IP Address:  172.22.3.184
                User-Name:  00-15-C5-49-5C-99
                   Status:  Authz Success
                   Domain:  DATA
           Oper host mode:  single-host
         Oper control dir:  both
            Authorized By:  Authentication Server
               Vlan Group:  N/A
         URL Redirect ACL:  redirect
             URL Redirect: https://ISE-ip:8443/guestportal/gateway?sessionId=AC16011F000000510B44FBD2&action=cwa
          Session timeout:  N/A
             Idle timeout:  N/A
        Common Session ID:  AC16011F000000490AC1A9E2
          Acct Session ID:  0x00000077
                   Handle:  0xB7000049
    Runnable methods list:
           Method   State
           mab      Authc Success
    But there is no redirection, and I get the the following message on switch console:
    756005: Mar 28 11:40:30: epm-redirect:IP=172.22.3.184: No redirection policy for this host
    756006: Mar 28 11:40:30: epm-redirect:IDB=FastEthernet0/24: In epm_host_ingress_traffic_qualify ...
    I have to mention I'm using an http proxy on port 8080...
    Any Ideas on what is going wrong?
    Regards
    Nuno

    OK, so I upgraded the IOS to version
    SW Version: 12.2(55)SE5, SW Image: C2960-LANBASEK9-M
    I tweak with ACL's to the following:
    Extended IP access list redirect
        10 permit ip any any (13 matches)
    and created a DACL that is downloaded along with the authentication
    Extended IP access list xACSACLx-IP-redirect-4f743d58 (per-user)
        10 permit ip any any
    I can see the epm session
    swlx0x0x#show epm session ip 172.22.3.74
         Admission feature:  DOT1X
         ACS ACL:  xACSACLx-IP-redirect-4f743d58
         URL Redirect ACL:  redirect
         URL Redirect:  https://ISE-ip:8443/guestportal/gateway?sessionId=AC16011F000000510B44FBD2&action=cwa
    And authentication
    swlx0x0x#show authentication sessions interface fastEthernet 0/24
         Interface:  FastEthernet0/24
         MAC Address:  0015.c549.5c99
         IP Address:  172.22.3.74
         User-Name:  00-15-C5-49-5C-99
         Status:  Authz Success
         Domain:  DATA
         Oper host mode:  multi-auth
         Oper control dir:  both
         Authorized By:  Authentication Server
         Vlan Group:  N/A
         ACS ACL:  xACSACLx-IP-redirect-4f743d58
         URL Redirect ACL:  redirect
         URL Redirect:  https://ISE-ip:8443/guestportal/gateway?sessionId=AC16011F000000510B44FBD2&action=cwa
         Session timeout:  N/A
         Idle timeout:  N/A
         Common Session ID:  AC16011F000000160042BD98
         Acct Session ID:  0x0000001B
         Handle:  0x90000016
         Runnable methods list:
         Method   State
         mab      Authc Success
    on the logging, I get the following messages...
    017857: Mar 29 11:27:04: epm-redirect:IDB=FastEthernet0/24: In epm_host_ingress_traffic_qualify ...
    017858: Mar 29 11:27:04: epm-redirect:epm_redirect_cache_gen_hash: IP=172.22.3.74 Hash=271
    017859: Mar 29 11:27:04: epm-redirect:IP=172.22.3.74: CacheEntryGet Success
    017860: Mar 29 11:27:04: epm-redirect:IP=172.22.3.74: Ingress packet on [idb= FastEthernet0/24] matched with [acl=redirect]
    017861: Mar 29 11:27:04: epm-redirect:IDB=FastEthernet0/24: Enqueue the packet with if_input=FastEthernet0/24
    017862: Mar 29 11:27:04: epm-redirect:IDB=FastEthernet0/24: In epm_host_ingress_traffic_process ...
    017863: Mar 29 11:27:04: epm-redirect:IDB=FastEthernet0/24: Not an HTTP(s) packet
    What I'm I missing?

  • Windows Radius / NPS not working with mac book pro 10.9.4 wired

    Hi,
    I'm trying to get my Radius windows server 2012 working with the correct setting for using 802.1x wired connection for the mac book pro. The only issue I'm having is there is not much setting in the mac book pro. I'm not sure what need to setup on the sever to make it connect correctly and assign it to the correct vlan when it's authenticated.
    Here are some screen shoots for my mac book pro
    So I've got it up to a point where I have this issue and here is my screen shots setting:
    So the above are my windows 2012 screen shot settings.
    On the mac book pro, I'm getting a prompted about adding certificate and I've added that into the laptop and then I need to put the username and password information. I put the following:
    [email protected] and the password.
    I'm current working with someone at HP on the switch settings, everything looks good.
    I know the following:
    1. Wireshark: shows server is getting request from the switch but it's not accepting them here are my logs on the NPS:
    RAD01  6274    Information      Microsoft Windows security auditing.   Security            2014-08-21 12:40:24 PM
    Here is the detail of the machine:
    Network Policy Server discarded the request for a user.
    Contact the Network Policy Server administrator for more information.
    User:
    Security ID:                              S-1-5-21-2690993882-1154983957-2264505580-1328
    Account Name:                         [email protected]
    Account Domain:                                  LCS
    Fully Qualified Account Name:  LCS\username
    Client Machine:
    Security ID:                              S-1-0-0
    Account Name:                         -
    Fully Qualified Account Name:  -
    OS-Version:                             -
    Called Station Identifier:                      b4-39-d6-ec-2c-00
    Calling Station Identifier:                     ac-7f-3e-e6-32-34
    NAS:
    NAS IPv4 Address:                   xx.xx.xx.xx
    NAS IPv6 Address:                   -
    NAS Identifier:                         5412zl-xxx-xxxxswithname
    NAS Port-Type:                                    Ethernet
    NAS Port:                                 170
    RADIUS Client:
    Client Friendly Name:               HP Procurve 5412zl switch
    Client IP Address:                                xx.xx.xx.xx
    Authentication Details:
    Connection Request Policy Name:       Secure Wired (Ethernet) Connections
    Network Policy Name:              Secure Wired (Ethernet) Connections
    Authentication Provider:                      Windows
    Authentication Server:             rad01.xxx.xxx.ca
    Authentication Type:                EAP
    EAP Type:                                -
    Account Session Identifier:                  -
    Reason Code:                          1
    Reason:                                               An internal error occurred. Check the system event log for additional information.
    Again I don't know what's the correct setting the default 802.1x for mac book pro, but it should correct.
    I'm also not sure what the internal error message is regarding about. The switch should automatically put me to vlan 7
    Can you some please help out what the correct authentication method for mac 10.9.4.
    Thanks

    Flash Player is a browser add-on, not a standalone application.
    You can test if the player is correctly installed at http://www.adobe.com/software/flash/about/

  • WRVS4400N wireless does not work until wired computer is started

    Hi!
    I have a WRVS4400N and is overall very pleased with it. I have desktop computer which is connected by wire and a laptop which is wirelessly connected (WPA). I use DHCP for both computers and the router is connected to Internet with a static IP. Pretty much all settings are default and the router has the latest firmware.
    However I have a problem, sometimes I am unable to get a wireless connection with the laptop. The signal strength is always excellent or very good, but I am unable to get any connection. If I choose 'repair' (Windows XP) it seems to get stuck on "Getting new IP address". I have tried many many many things, rebooting router/laptop and so on but I am pretty sure it is not any problem with the laptop (it's been working great on several other WLANs).
    But...
    Now I have noticed a strange coincidence and that is 99% of the times when I am unable to connect wirelessly, the desktop computer is shut down. As soon as the desktop computer is started and I try to connected with the laptop again, it works!  (There are never any problems with the wired connection.)
    If anyone have the same problem or some suggestions/tips what to do please let me know.

    well yeah its my first time hearing that kind of problem..
    try enabling MAC address clone on the router.

  • RMI Failover not working in 9.2?

    Setup:
    RMI's RTD.xml
    <cluster
    clusterable="true"
    load-algorithm="round-robin"
    >
    </cluster>
    <method
    name="*"
    idempotent="true"
    timeout="3000"
    >
    </method>
    Cluster
    Srv1=RMI.instance1
    Srv2=RMI.instance2
    Srv3
    Servlet: gets Srv1 context and looks up RMI object, invokes its biz method;
    Loadbalancing works, according to logs.
    Shutdown Srv2 and Srv1 continues processing.
    Restart Srv2 and shutdown Srv1 and the failover should kick in here too, but the connection is now considered broken and results in a Host not reachable exception.
    Can't find any documentation as to what I should be doing different, but I must be missing something.
    Any ideas?
    Karoly

    It just started working, or very likely, it was working from the beginning, but some components were not build/deployed properly.

  • IE 9.0 proxy failover not working correctly - Is there a bug fix or IE setting to correct this behavior

    I am testing proxy pac file  failover using IE 9.0.8112 and testing three choices using an automatic configuration file.  I shut down the first proxy to test the fail over to the second. Firefox 20.0.1 and chrome work correctly, but IE 9.0 does
    not. My snip-it is as follows:
    return "PROXY 192.168.11.12:8080; PROXY 192.168.11.195:8080; DIRECT";
    With ie8, firefox and chrome the fail over to the next proxy entry during a PROXY 192.168.11.12 fail over works correct and as follows:
    Proxy 192.168.11.12 times out after about 25-30 seconds and then proxy 192.168.11.195 is attempted and the web page is displayed.
    Then all url lookups after this time are made through proxy 192.168.11.195 and are quick. This is how proxy fail over should work.
    When I test with ie9 it works as follows:
    Proxy 192.168.11.12 times out after about 25-30 seconds and then proxy 192.168.11.195 is attempted and the web page is displayed.
    Then all following url lookups take 30 -45 seconds because it always tries the first PROXY 192.168.11.12 first before attempting proxy 192.168.11.195
    because it does not remember first Proxy 192.168.11.12 is not available.
    Is there a setting or bug opened on this behavior????

    Not to be pedantic, but the proxy.pac file is JavaScript... :)
    You might be experiencing an issue with IE's automatic proxy caching, described here: http://support.microsoft.com/kb/271361 . Basically, the choice of which proxy to use is decided once per requested host, and the decision is cached. So, if you
    are testing failover by accessing resources on the same host before and after shutting off the first proxy, IE will still insist on using that proxy address for subsequent requests. If you test a second host and get a more timely response, then I would say
    this is what you are seeing.
    You can experimentally disable this feature by setting...
    [HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings]
    "EnableAutoProxyResultCache"=dword:00000000"
    ...in the registry for your test user. I imagine a reboot will be required.

Maybe you are looking for