<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Please usedebug aaa in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/unable-to-login-local-after-radius-server-down/m-p/2248941#M126187</link>
    <description>&lt;P&gt;Please use&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;debug aaa subsys&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;debug aaa authentication&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;to make sure the switch really does not attempt local authentication. Do you have local users defined?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is strongly recommended to add&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa authorization exec default group radius local&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;too.&lt;/P&gt;</description>
    <pubDate>Sun, 31 Aug 2014 12:49:28 GMT</pubDate>
    <dc:creator>Peter Koltl</dc:creator>
    <dc:date>2014-08-31T12:49:28Z</dc:date>
    <item>
      <title>Unable to login local after radius server down</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-login-local-after-radius-server-down/m-p/2248937#M126183</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am unable to login with local user when radius server is down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the switch configuration :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group radius local&lt;/P&gt;&lt;P&gt;aaa authentication login remote group radius local&lt;/P&gt;&lt;P&gt;aaa authentication enable default enable&lt;/P&gt;&lt;P&gt;aaa session-id common&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;radius-server host 192.168.150.22&lt;/P&gt;&lt;P&gt;radius-server deadtime 5&lt;/P&gt;&lt;P&gt;radius-server key 7 XXXXXXXXXXXXXXXXXX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;exec-timeout 5 0&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt;access-class 101 in&lt;/P&gt;&lt;P&gt;exec-timeout 5 0&lt;/P&gt;&lt;P&gt;login authentication remote&lt;/P&gt;&lt;P&gt;transport input ssh&lt;/P&gt;&lt;P&gt;line vty 5 15&lt;/P&gt;&lt;P&gt;access-class 101 in&lt;/P&gt;&lt;P&gt;exec-timeout 5 0&lt;/P&gt;&lt;P&gt;login authentication remote&lt;/P&gt;&lt;P&gt;transport input ssh&lt;/P&gt;&lt;P&gt;Output debug AAA and radius when radius server is down&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;9w0d: AAA/AUTHEN/LOGIN (000002B3): Pick method list 'remote' &lt;/P&gt;&lt;P&gt;9w0d: RADIUS/ENCODE(000002B3): ask "Password: "&lt;/P&gt;&lt;P&gt;9w0d: RADIUS/ENCODE(000002B3): send packet; GET_PASSWORD&lt;/P&gt;&lt;P&gt;9w0d: RADIUS/ENCODE(000002B3):Orig. component type = Exec&lt;/P&gt;&lt;P&gt;9w0d: RADIUS:&amp;nbsp; AAA Unsupported Attr: interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [221] 4&amp;nbsp;&amp;nbsp; 75560408&lt;/P&gt;&lt;P&gt;9w0d: RADIUS/ENCODE(000002B3): dropping service type, "radius-server attribute 6 on-for-login-auth" is off&lt;/P&gt;&lt;P&gt;9w0d: RADIUS(000002B3): Config NAS IP: 0.0.0.0&lt;/P&gt;&lt;P&gt;9w0d: RADIUS(000002B3): Config NAS IPv6: ::&lt;/P&gt;&lt;P&gt;9w0d: RADIUS/ENCODE(000002B3): acct_session_id: 681&lt;/P&gt;&lt;P&gt;9w0d: RADIUS(000002B3): sending&lt;/P&gt;&lt;P&gt;9w0d: RADIUS/ENCODE: Best Local IP-Address 192.168.172.249 for Radius-Server 192.168.150.22&lt;/P&gt;&lt;P&gt;9w0d: RADIUS(000002B3): Sending a IPv4 Radius Packet&lt;/P&gt;&lt;P&gt;9w0d: RADIUS(000002B3): Send Access-Request to 192.168.150.22:1645 id 1645/79,len 82&lt;/P&gt;&lt;P&gt;9w0d: RADIUS:&amp;nbsp; authenticator 12 78 F8 39 D5 B0 12 F4 - 18 7E 38 AC 59 3B CD F4&lt;/P&gt;&lt;P&gt;9w0d: RADIUS:&amp;nbsp; User-Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [1]&amp;nbsp;&amp;nbsp; 8&amp;nbsp;&amp;nbsp; "tatari"&lt;/P&gt;&lt;P&gt;9w0d: RADIUS:&amp;nbsp; Reply-Message&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [18]&amp;nbsp; 12&amp;nbsp; &lt;/P&gt;&lt;P&gt;9w0d: RADIUS:&amp;nbsp;&amp;nbsp; 50 61 73 73 77 6F 72 64 3A 20&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ Password: ]&lt;/P&gt;&lt;P&gt;9w0d: RADIUS:&amp;nbsp; User-Password&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [2]&amp;nbsp;&amp;nbsp; 18&amp;nbsp; *&lt;/P&gt;&lt;P&gt;9w0d: RADIUS:&amp;nbsp; NAS-Port&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [5]&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp; 2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;9w0d: RADIUS:&amp;nbsp; NAS-Port-Id&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [87]&amp;nbsp; 6&amp;nbsp;&amp;nbsp; "tty2"&lt;/P&gt;&lt;P&gt;9w0d: RADIUS:&amp;nbsp; NAS-Port-Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [61]&amp;nbsp; 6&amp;nbsp;&amp;nbsp; Virtual&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [5]&lt;/P&gt;&lt;P&gt;9w0d: RADIUS:&amp;nbsp; NAS-IP-Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [4]&amp;nbsp;&amp;nbsp; 6&amp;nbsp;&amp;nbsp; 192.168.172.249&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;9w0d: RADIUS(000002B3): Started 5 sec timeout&lt;/P&gt;&lt;P&gt;9w0d: RADIUS(000002B3): Request timed out! &lt;/P&gt;&lt;P&gt;9w0d: RADIUS: Retransmit to (192.168.150.22:1645,1646) for id 1645/79&lt;/P&gt;&lt;P&gt;9w0d: RADIUS(000002B3): Started 5 sec timeout&lt;/P&gt;&lt;P&gt;9w0d: RADIUS(000002B3): Request timed out! &lt;/P&gt;&lt;P&gt;9w0d: RADIUS: Retransmit to (192.168.150.22:1645,1646) for id 1645/79&lt;/P&gt;&lt;P&gt;9w0d: RADIUS(000002B3): Started 5 sec timeout&lt;/P&gt;&lt;P&gt;9w0d: RADIUS(000002B3): Request timed out! &lt;/P&gt;&lt;P&gt;9w0d: RADIUS: Retransmit to (192.168.150.22:1645,1646) for id 1645/79&lt;/P&gt;&lt;P&gt;9w0d: RADIUS(000002B3): Started 5 sec timeout&lt;/P&gt;&lt;P&gt;9w0d: RADIUS(000002B3): Request timed out! &lt;/P&gt;&lt;P&gt;9w0d: RADIUS: No response from (192.168.150.22:1645,1646) for id 1645/79&lt;/P&gt;&lt;P&gt;9w0d: RADIUS/DECODE: No response from radius-server; parse response; FAIL&lt;/P&gt;&lt;P&gt;9w0d: RADIUS/DECODE: Case error(no response/ bad packet/ op decode);parse response; FAIL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why aaa don´t try to local authentication?.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:35:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-login-local-after-radius-server-down/m-p/2248937#M126183</guid>
      <dc:creator>Grupo Internet</dc:creator>
      <dc:date>2019-03-11T03:35:48Z</dc:date>
    </item>
    <item>
      <title>Unable to login local after radius server down</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-login-local-after-radius-server-down/m-p/2248938#M126184</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The authentication request is not even trying local auth method?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried alone with local authentication only? Does that work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please provide &lt;STRONG&gt;show version&lt;/STRONG&gt; from the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;/P&gt;&lt;P&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jun 2013 13:35:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-login-local-after-radius-server-down/m-p/2248938#M126184</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-06-28T13:35:23Z</dc:date>
    </item>
    <item>
      <title>Unable to login local after radius server down</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-login-local-after-radius-server-down/m-p/2248939#M126185</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; aaa authentication login only_local local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; access-class 101 in&lt;/P&gt;&lt;P&gt; exec-timeout 5 0&lt;/P&gt;&lt;P&gt; login authentication only_local&lt;/P&gt;&lt;P&gt; transport input ssh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With this configuration work fine with local user but I need radius also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the show version output :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco IOS Software, C3560 Software (C3560-IPBASEK9-M), Version 15.0(2)SE2, RELEASE SOFTWARE (fc1)&lt;BR /&gt;Technical Support: &lt;A href="http://www.cisco.com/techsupport"&gt;http://www.cisco.com/techsupport&lt;/A&gt;&lt;BR /&gt;Copyright (c) 1986-2013 by Cisco Systems, Inc.&lt;BR /&gt;Compiled Tue 05-Feb-13 12:21 by prod_rel_team&lt;/P&gt;&lt;P&gt;ROM: Bootstrap program is C3560 boot loader&lt;BR /&gt;BOOTLDR: C3560 Boot Loader (C3560-HBOOT-M) Version 12.2(35r)SE2, RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt;INSWTRIV02 uptime is 9 weeks, 23 hours, 27 minutes&lt;BR /&gt;System returned to ROM by power-on&lt;BR /&gt;System restarted at 16:21:52 GMT+2 Thu Apr 25 2013&lt;BR /&gt;System image file is "flash:/c3560-ipbasek9-mz.150-2.se2.bin"&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This product contains cryptographic features and is subject to United&lt;BR /&gt;States and local country laws governing import, export, transfer and&lt;BR /&gt;use. Delivery of Cisco cryptographic products does not imply&lt;BR /&gt;third-party authority to import, export, distribute or use encryption.&lt;BR /&gt;Importers, exporters, distributors and users are responsible for&lt;BR /&gt;compliance with U.S. and local country laws. By using this product you&lt;BR /&gt;agree to comply with applicable laws and regulations. If you are unable&lt;BR /&gt;to comply with U.S. and local laws, return this product immediately.&lt;/P&gt;&lt;P&gt;A summary of U.S. laws governing Cisco cryptographic products may be found at:&lt;BR /&gt;&lt;A href="http://www.cisco.com/wwl/export/crypto/tool/stqrg.html"&gt;http://www.cisco.com/wwl/export/crypto/tool/stqrg.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you require further assistance please contact us by sending email to&lt;BR /&gt;&lt;A href="mailto:export@cisco.com"&gt;export@cisco.com&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;cisco WS-C3560-8PC (PowerPC405) processor (revision C0) with 131072K bytes of memory.&lt;BR /&gt;Processor board ID FOC1327W73D&lt;BR /&gt;Last reset from power-on&lt;BR /&gt;2 Virtual Ethernet interfaces&lt;BR /&gt;8 FastEthernet interfaces&lt;BR /&gt;1 Gigabit Ethernet interface&lt;BR /&gt;The password-recovery mechanism is enabled.&lt;/P&gt;&lt;P&gt;512K bytes of flash-simulated non-volatile configuration memory.&lt;BR /&gt;Base ethernet MAC Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 00:26:52:A4:96:80&lt;BR /&gt;Motherboard assembly number&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 73-10612-07&lt;BR /&gt;Power supply part number&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 341-0207-01&lt;BR /&gt;Motherboard serial number&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : FOC13281794&lt;BR /&gt;Power supply serial number&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : LIT13120986&lt;BR /&gt;Model revision number&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : C0&lt;BR /&gt;Motherboard revision number&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : C0&lt;BR /&gt;Model number&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : WS-C3560-8PC-S&lt;BR /&gt;System serial number&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : FOC1327W73D&lt;BR /&gt;Top Assembly Part Number&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 800-28131-02&lt;BR /&gt;Top Assembly Revision Number&amp;nbsp;&amp;nbsp;&amp;nbsp; : A0&lt;BR /&gt;Version ID&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : V02&lt;BR /&gt;CLEI Code Number&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : COMN400CRA&lt;BR /&gt;Hardware Board Revision Number&amp;nbsp; : 0x01&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Switch Ports Model&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SW Version&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SW Image&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;------ ----- -----&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ----------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ----------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;*&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 9&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; WS-C3560-8PC&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 15.0(2)SE2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; C3560-IPBASEK9-M&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Configuration register is 0xF&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Jun 2013 13:52:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-login-local-after-radius-server-down/m-p/2248939#M126185</guid>
      <dc:creator>Grupo Internet</dc:creator>
      <dc:date>2013-06-28T13:52:07Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to login local after radius server down</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-login-local-after-radius-server-down/m-p/2248940#M126186</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;maybe you need to wait until 5 minutes because of "radius-server deadtime 5", default is 0...&lt;/P&gt;&lt;P&gt;you set it to "5", so the switch will waiting for 5 minutes if RADIUS unreachable...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see below :&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/switches/lan/catalyst3550/software/release/12.1_13_ea1/configuration/guide/swauthen.html#wp1091663"&gt;http://www.cisco.com/en/US/docs/switches/lan/catalyst3550/software/release/12.1_13_ea1/configuration/guide/swauthen.html#wp1091663&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jul 2013 01:43:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-login-local-after-radius-server-down/m-p/2248940#M126186</guid>
      <dc:creator>myanznki</dc:creator>
      <dc:date>2013-07-03T01:43:40Z</dc:date>
    </item>
    <item>
      <title>Please usedebug aaa</title>
      <link>https://community.cisco.com/t5/network-access-control/unable-to-login-local-after-radius-server-down/m-p/2248941#M126187</link>
      <description>&lt;P&gt;Please use&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;debug aaa subsys&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;debug aaa authentication&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;to make sure the switch really does not attempt local authentication. Do you have local users defined?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is strongly recommended to add&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa authorization exec default group radius local&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;too.&lt;/P&gt;</description>
      <pubDate>Sun, 31 Aug 2014 12:49:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/unable-to-login-local-after-radius-server-down/m-p/2248941#M126187</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2014-08-31T12:49:28Z</dc:date>
    </item>
  </channel>
</rss>

