<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA - Local authentication problem in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-local-authentication-problem/m-p/2029778#M158484</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can try setting up an ACL on the svi that belongs to the radius server and just deny it from ths host. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Sep 2012 17:38:50 GMT</pubDate>
    <dc:creator>Tarik Admani</dc:creator>
    <dc:date>2012-09-20T17:38:50Z</dc:date>
    <item>
      <title>AAA - Local authentication problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-local-authentication-problem/m-p/2029777#M158483</link>
      <description>&lt;P&gt;We have following configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default local group radius&lt;/P&gt;&lt;P&gt;aaa authentication enable default enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group radius local&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;authentication preference is local and then it's radius.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently Radius is reachable&amp;nbsp; but we need to test the local username and passsowrds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when local username and passwords are given switch still contacts RADIUS and then access is denied.&lt;/P&gt;&lt;P&gt;Looking for way to test the local username and passwords.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please share the experience.&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;P&gt;- Subodh &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:34:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-local-authentication-problem/m-p/2029777#M158483</guid>
      <dc:creator>bapatsubodh</dc:creator>
      <dc:date>2019-03-11T02:34:17Z</dc:date>
    </item>
    <item>
      <title>AAA - Local authentication problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-local-authentication-problem/m-p/2029778#M158484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can try setting up an ACL on the svi that belongs to the radius server and just deny it from ths host. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Sep 2012 17:38:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-local-authentication-problem/m-p/2029778#M158484</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-09-20T17:38:50Z</dc:date>
    </item>
    <item>
      <title>Re:AAA - Local authentication problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-local-authentication-problem/m-p/2029779#M158485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;You defined local meyhod as the 1'st method in auth.   However in autho u defined the AAA server.&lt;/P&gt;&lt;P&gt;In my prespective this is a logical error because when the autho request recieved ,the server will say u didn't authenticated to begin with since auth. Was local.&lt;/P&gt;&lt;P&gt;To achieve ur goal&lt;/P&gt;&lt;P&gt;==================&lt;/P&gt;&lt;P&gt;-make the first authentication method is AAA server&lt;/P&gt;&lt;P&gt;-break the connectivity to that server or change the IP address that defined on the router/switch to something else.so the router\switch will assume the server is down. Then test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Sep 2012 21:13:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-local-authentication-problem/m-p/2029779#M158485</guid>
      <dc:creator>hkhrais</dc:creator>
      <dc:date>2012-09-20T21:13:01Z</dc:date>
    </item>
    <item>
      <title>Re:AAA - Local authentication problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-local-authentication-problem/m-p/2029780#M158486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess u need to make the authorization also set to local and then radius to check it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 22 Sep 2012 20:44:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-local-authentication-problem/m-p/2029780#M158486</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2012-09-22T20:44:46Z</dc:date>
    </item>
    <item>
      <title>Re:AAA - Local authentication problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-local-authentication-problem/m-p/2029781#M158487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks guys!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Same configuration is working on another switch with different IOS veriosn. So I guess it's related to this IOS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco IOS Software, C3560 Software (C3560-IPSERVICESK9-M), Version 12.2(55)SE3, RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BOOTLDR: C3560 Boot Loader (C3560-HBOOT-M) Version 12.2(44)SE5, RELEASE SOFTWARE (fc1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it a known bug/cavet in this version?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please share the experience.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers..&lt;/P&gt;&lt;P&gt;Subodh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 13:19:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-local-authentication-problem/m-p/2029781#M158487</guid>
      <dc:creator>bapatsubodh</dc:creator>
      <dc:date>2012-09-24T13:19:34Z</dc:date>
    </item>
    <item>
      <title>Re:AAA - Local authentication problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-local-authentication-problem/m-p/2029782#M158488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;In the switch that is working fine , would u pls double check the method order for authenticatin and authorization&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 20:43:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-local-authentication-problem/m-p/2029782#M158488</guid>
      <dc:creator>hkhrais</dc:creator>
      <dc:date>2012-09-24T20:43:23Z</dc:date>
    </item>
    <item>
      <title>Re:AAA - Local authentication problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-local-authentication-problem/m-p/2029783#M158489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the output for which the local user works &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch1#sh running-config | inc aaa&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default local group radius&lt;/P&gt;&lt;P&gt;aaa authentication enable default enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group radius if-authenticated&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the switch where it's not working, it's the same, only difference in these switches is&amp;nbsp; IOS veriosn. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default local group radius&lt;/P&gt;&lt;P&gt;aaa authentication enable default enable&lt;/P&gt;&lt;P&gt;aaa authorization exec default group radius if-authenticated &lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Sep 2012 14:58:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-local-authentication-problem/m-p/2029783#M158489</guid>
      <dc:creator>bapatsubodh</dc:creator>
      <dc:date>2012-09-26T14:58:45Z</dc:date>
    </item>
    <item>
      <title>Re:AAA - Local authentication problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-local-authentication-problem/m-p/2029784#M158490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;Can u make your IOS image as the working one then test again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note&lt;/P&gt;&lt;P&gt;In auhtentication . U stated the local as the first method and RADIUS as the second one. Pls note the switch will NOT failover to radius. Because if the local database is down this mean your switch is totally down.&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Sep 2012 17:49:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-local-authentication-problem/m-p/2029784#M158490</guid>
      <dc:creator>hkhrais</dc:creator>
      <dc:date>2012-09-26T17:49:52Z</dc:date>
    </item>
  </channel>
</rss>

