The issue described occurs when the fallback feature is disabled on the Cisco AireOS controller. When fallback is disabled, the controller does not attempt to reconnect to the primary TACACS+ server after it becomes available again following a failure. Instead, it continues to use the secondary server until it fails or the controller is rebooted. Enabling fallback would allow the controller to periodically attempt to reconnect to the primary server.