[tac_plus] Re: single connection

Dan Schmidt dan.schmidt at uplinkdata.com
Thu May 29 21:32:18 UTC 2008


Thanks for kindly for your reply.

The symptoms are that, if multiple sessions are opened - one right after
the other, exactly every other session fails to contact the tacacs
server (defaults to local authentication) spitting out that debug
message.  Perhaps it is a bug on the 7600's, as the 6500's in that city
are completely fine.  (And 3750's, ect.)

Single-connection was implemented in CiscoSecure Release 1.0.1 - is it
fully supported in tac_plus?  

Obviously, the work around is to disable single connection, but that
creates more connections to the tacacs server. 

-----Original Message-----
From: john heasley [mailto:heas at shrubbery.net] 
Sent: Thursday, May 29, 2008 3:04 PM
To: Dan Schmidt
Cc: tac_plus at shrubbery.net
Subject: Re: [tac_plus] single connection

Thu, May 29, 2008 at 02:01:18PM -0600, Dan Schmidt:
> Has anybody ever seen this error with tac_plus?  I only get it on some
> routers, and only when using single-connection
> 
> May 28 22:39:06: TPLUS: Error occurs in reading packet header,
shutdown
> the single connection 
> May 28 22:39:49: TPLUS: Error occurs in reading packet header,
shutdown
> the single connection
> _______________________________________________
> tac_plus mailing list
> tac_plus at shrubbery.net
> http://www.shrubbery.net/mailman/listinfo.cgi/tac_plus

I'd guess that the server times-out, or one side or the other gets
confused
(ie: FSM error).


More information about the tac_plus mailing list