<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA and local user authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-and-local-user-authentication/m-p/2373828#M118979</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ismail,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is your answer:&lt;/P&gt;&lt;P&gt;aaa authentication login default local group radius/tacacs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="active_link"&gt;Parthapratim&lt;/SPAN&gt; - A little correction,it will go to radius or tacacs + if the user is not present locally.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The local DB differs in the way fallback works which is the exception.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**Share your knowledge. It’s a way to achieve immortality. &lt;BR /&gt;--Dalai Lama** &lt;BR /&gt; &lt;BR /&gt;Please Rate if helpful. &lt;BR /&gt;Regards &lt;BR /&gt;Ed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 09 Dec 2013 11:02:17 GMT</pubDate>
    <dc:creator>edwjames</dc:creator>
    <dc:date>2013-12-09T11:02:17Z</dc:date>
    <item>
      <title>AAA and local user authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-local-user-authentication/m-p/2373826#M118977</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already have AAA authentication setup on my switch. And I can use local users to login when the AAA server is unreachable.&lt;/P&gt;&lt;P&gt;But I want to know if it is possible to use local users even when the AAA server is reachable. Something like first it checks the local users databse and if the user does not exists then fallback to AAA or vice versa.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:10:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-local-user-authentication/m-p/2373826#M118977</guid>
      <dc:creator>ismailfayaz</dc:creator>
      <dc:date>2019-03-11T04:10:03Z</dc:date>
    </item>
    <item>
      <title>AAA and local user authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-local-user-authentication/m-p/2373827#M118978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ismail, the authentication method you define act as a service. So only when the service is not avilable the method fallback to the next methond you define. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So in your case if the user account is not present in the local data base it will not fallback to aaa server.&lt;/P&gt;&lt;P&gt;aaa authentication login default local group radius &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; The same holds true if the user account is not there in the aaa server&lt;/P&gt;&lt;P&gt; aaa authentication login default group radius local&lt;/P&gt;&lt;PRE&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt; Only when the aaa server is not responding (service downe or not reachable) it will fallback to the local database. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Dec 2013 05:28:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-local-user-authentication/m-p/2373827#M118978</guid>
      <dc:creator>parsahoo</dc:creator>
      <dc:date>2013-12-09T05:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: AAA and local user authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-local-user-authentication/m-p/2373828#M118979</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ismail,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is your answer:&lt;/P&gt;&lt;P&gt;aaa authentication login default local group radius/tacacs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="active_link"&gt;Parthapratim&lt;/SPAN&gt; - A little correction,it will go to radius or tacacs + if the user is not present locally.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The local DB differs in the way fallback works which is the exception.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**Share your knowledge. It’s a way to achieve immortality. &lt;BR /&gt;--Dalai Lama** &lt;BR /&gt; &lt;BR /&gt;Please Rate if helpful. &lt;BR /&gt;Regards &lt;BR /&gt;Ed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Dec 2013 11:02:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-local-user-authentication/m-p/2373828#M118979</guid>
      <dc:creator>edwjames</dc:creator>
      <dc:date>2013-12-09T11:02:17Z</dc:date>
    </item>
    <item>
      <title>AAA and local user authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-local-user-authentication/m-p/2373829#M118980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Edward,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;It works perfectly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Dec 2013 11:49:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-local-user-authentication/m-p/2373829#M118980</guid>
      <dc:creator>ismailfayaz</dc:creator>
      <dc:date>2013-12-09T11:49:22Z</dc:date>
    </item>
  </channel>
</rss>

