According to the tac+ draft:
If the status equals TAC_PLUS_AUTHEN_STATUS_ERROR, then the host is
indicating that it is experiencing an unrecoverable error and the
authentication should proceed as if that host could not be
contacted.
Alas, I'm under the impression that Cisco gear doesn't conform to
that. I've modified the latest snapshot accordingly, but at least my
test router didn't fall back to local authentication. YMMV.
http://www.pro-bono-publico.de/projects/src/DEVEL.201008111908.tar.bz2
(This fixes a potential segfault in the logging code, too.)
If anyone knows of a tac_plus server where local fallback in fact
works (without shutting down the daemon!) I'd be grateful to know.
Cheers,
Marc
On 11 Aug., 11:54, Savin Alexis <
alexis.sa...@gmail.com> wrote:
> Hi,
>
> Well the router doesn't fall back to the local authentication if the tacacs
> server is still up.
>
> I expected that it would be possible to send the router a timeout if the
> ldap query failed so that, at least, the authentication would fail.
> Currently, it's just stuck at the login prompt...
>
> My current solution is as you suggested, to kill the tacacs daemon and
> restart it using another LDAP server. However, in my opinion, this solution
> isn't the cleanest one.
>
> Thank you for your answer.
>
> >
event-driven-ser...@googlegroups.com<
event-driven-servers%2Bunsu...@googlegroups.com>
> > .