[RADIATOR] [*** Newsletter ***] Re: [*** Newsletter ***] Re: Cisco NX-OS TACACS+ problems

Heikki Vatiainen hvn at open.com.au
Fri Oct 18 06:28:56 CDT 2013


On 10/18/2013 02:23 PM, Hartmaier Alexander wrote:

>> Have you tried with SingleSession option? This sets the
>> TAC_PLUS_SINGLE_CONNECT_FLAG flag as described in
>> http://tools.ietf.org/html/draft-grant-tacacs-02

> According to the Radiator ref.pdf it defaults to 1 (enabled) (we're
> running 4.11 + patches), should I try to disable it? Can this be done
> for some clients only too?

It's a server level flag but you can specify it on the client side. On
IOS something like this should do it:

   tacacs-server host ... single-connection

Thanks,
Heikki

-- 
Heikki Vatiainen <hvn at open.com.au>

Radiator: the most portable, flexible and configurable RADIUS server
anywhere. SQL, proxy, DBM, files, LDAP, NIS+, password, NT, Emerald,
Platypus, Freeside, TACACS+, PAM, external, Active Directory, EAP, TLS,
TTLS, PEAP, TNC, WiMAX, RSA, Vasco, Yubikey, MOTP, HOTP, TOTP,
DIAMETER etc. Full source on Unix, Windows, MacOSX, Solaris, VMS,
NetWare etc.


More information about the radiator mailing list