Previous Next Table of Contents

13. Dangers of TACACS accounting and leased lines

By: Gabriele Elia <gabriele.elia@cselt.stet.it>

I am using TacacsPlus to authenticate and account ISDN dial-up users. These users have TCP/IP on PPP on ISDN and connect to Cisco4500 with BRI ports. One of the NAS is connected to the corporate LAN via a leased line with PPP again as framing protocol. The tacacs plus server is accounting start and stop network events; this was intended to log PPP sessions of users.

        __NAS1_____                       NAS2_______
        |  cisco  |                      | cisco    |
        |  8 BRI  |-------leased line----| 8BRI,serial
        |_________|                      |_ethernet_|
                                                |
                                               ---------ethernet---

In one occasion, the leased line has many problems and started going up and down many times per second. The PPP with on the leased line was also going up and down; this was saturating the tacacs plus servers, inflating enormously the tacacs plus log file and preventing users to log in the NAS1 or the NAS2.

The lesson for me was: it is very dangerous to have PPP encapsulation on frame relay or leased line connected to a NAS were network accouting is enabled via tacacs plus.


Previous Next Table of Contents