PDF(38.4 KB) View with Adobe Reader on a variety of devices
ePub(76.4 KB) View in various apps on iPhone, iPad, Android, Sony Reader, or Windows Phone
Mobi (Kindle)(71.1 KB) View on Kindle device or Kindle app on multiple devices
Updated:October 12, 2017
The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
This document describes how to clear hung sessions on StarOS when Terminal Access Controller Access-Control System (TACACS) failure happens and you are unable to log in to the Aggregation Services Router (ASR) 5500 / ASR 5000 / Virtual Port Channels (vPC).
You are unable to login into ASR 5500/ASR 5000/VPC after TACACS failure due to the "Max Connections Reached" error.
This error is constantly reported in show logs:
- [vpn 5902 error] [8/0/4484 <vpnmgr:1> luser_auth.c:681] [context: local, contextID: 1] [software internal system syslog] Localuser subsystem internal error: Unable to setup AAA session. MAX sessions reached/0.
The CLI show tacacs summary shows total of thirty active TACACS sessions of the chassis in-use but the actual users are disconnected from the chassis.
When a TACACS user enters the TACACS password; the chassis instantly fails the authentication without contacting the TACACS server.
Currently only the local account credential can access the chassis. Users are unable to connect via TACACS.
Step 1. Run show tacacs summary to find stale sessions.
Step 2. Log in via console connection with TACACS user. If you have 30 or fewer sessions from Step 1., then you can login with TACACS user to the chassis directly (no need for a console connection) and proceed with the next step.
Step 3. Navigate to the hidden mode and execute test tacacs force-logout <session-number>.