<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA authentication preference in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-preference/m-p/1964917#M186077</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With the command "aaa authentication login default local group radius" the local database is checked first and RADIUS is the fallback. But there is a "feature" that is sometimes not expected. If the user is not found in the local database the authentication is not rejected, but passed to the next method which is RADIUS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 10 Aug 2012 19:09:35 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2012-08-10T19:09:35Z</dc:date>
    <item>
      <title>AAA authentication preference</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-preference/m-p/1964916#M186065</link>
      <description>&lt;P&gt;We have AAA configured as follows&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default local group radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication enable default enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization exec default group radius if-authenticated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It was expected that switch will check the local username first and then Radius server. But it is not checking local username it's getting authenticated by RADUIS. even though default priority is for "local" and then "Radius group".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please share the experience.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;-Subodh&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:24:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-preference/m-p/1964916#M186065</guid>
      <dc:creator>bapatsubodh</dc:creator>
      <dc:date>2019-03-11T02:24:34Z</dc:date>
    </item>
    <item>
      <title>AAA authentication preference</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-preference/m-p/1964917#M186077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With the command "aaa authentication login default local group radius" the local database is checked first and RADIUS is the fallback. But there is a "feature" that is sometimes not expected. If the user is not found in the local database the authentication is not rejected, but passed to the next method which is RADIUS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Aug 2012 19:09:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-preference/m-p/1964917#M186077</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2012-08-10T19:09:35Z</dc:date>
    </item>
  </channel>
</rss>

