Successful Previous Authentication With The Primary Ldap Server; Unsuccessful Previous Authentication With The Primary Ldap Server - Cisco 2509 - Router - EN User Manual

User guide
Hide thumbs Also See for 2509 - Router - EN:
Table of Contents

Advertisement

Chapter 11
Working with User Databases

Successful Previous Authentication with the Primary LDAP Server

Unsuccessful Previous Authentication with the Primary LDAP Server

78-14696-01, Version 3.1
If, on the previous LDAP authentication attempt, Cisco Secure ACS successfully
connected to the primary LDAP server, Cisco Secure ACS attempts to connect to
the primary LDAP server. If Cisco Secure ACS cannot connect to the primary
LDAP server, Cisco Secure ACS attempts to connect to the secondary LDAP
server.
If Cisco Secure ACS cannot connect with either LDAP server, Cisco Secure ACS
stops attempting LDAP authentication for the user. If the user is an unknown user,
Cisco Secure ACS tries the next external user database listed in the Unknown
User Policy list. For more information about the Unknown User Policy list, see
Unknown User Processing, page
If, on the previous LDAP authentication attempt, Cisco Secure ACS could not
connect to the primary LDAP server, whether Cisco Secure ACS first attempts to
connect to the primary server or secondary LDAP server for the current
authentication attempt depends on the value in the Failback Retry Delay box. If
the Failback Retry Delay box is set to 0 (zero), Cisco Secure ACS always attempts
to connect to the primary LDAP server first. And if Cisco Secure ACS cannot
connect to the primary LDAP server, Cisco Secure ACS then attempts to connect
to the secondary LDAP server.
If the Failback Retry Delay box is set to a number other than zero,
Cisco Secure ACS determines how many minutes have passed since the last
authentication attempt using the primary LDAP server occurred. If more minutes
have passed than the value specified in the Failback Retry Delay box,
Cisco Secure ACS attempts to connect to the primary LDAP server first. And if
Cisco Secure ACS cannot connect to the primary LDAP server,
Cisco Secure ACS then attempts to connect to the secondary LDAP server.
If fewer minutes have passed than the value specified in the Failback Retry Delay
box, Cisco Secure ACS attempts to connect to the secondary LDAP server first.
And if Cisco Secure ACS cannot connect to the secondary LDAP server,
Cisco Secure ACS then attempts to connect to the primary LDAP server.
12-1.
User Guide for Cisco Secure ACS for Windows Server
Generic LDAP
11-21

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Secure acs

Table of Contents