<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Looks like NX-OS will not in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/failover-to-local-login-when-tacacs-is-reachable-but-not/m-p/1622277#M345930</link>
    <description>&lt;P&gt;Looks like NX-OS will not allow me to do this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nexus001(config)# aaa authentication login default local group&amp;nbsp;TACACS&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;BR /&gt;% Invalid command at '^' marker.&lt;BR /&gt;Nexus001(config)# aaa authentication login default local ?&lt;BR /&gt;&amp;nbsp; &amp;lt;CR&amp;gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nexus001(config)# aaa authentication login ?&lt;BR /&gt;&amp;nbsp; ascii-authentication&amp;nbsp; Enable ascii authentication&lt;BR /&gt;&amp;nbsp; chap&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CHAP authentication for login&lt;BR /&gt;&amp;nbsp; console&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Configure console methods&lt;BR /&gt;&amp;nbsp; default&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Configure default methods&lt;BR /&gt;&amp;nbsp; error-enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enable display of error message on login failures&lt;BR /&gt;&amp;nbsp; mschap&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MSCHAP authentication for login&lt;BR /&gt;&amp;nbsp; mschapv2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MSCHAP V2 authentication for login&lt;/P&gt;&lt;P&gt;Nexus001(config)# aaa authentication login default ?&lt;BR /&gt;&amp;nbsp; fallback&amp;nbsp; Configure fallback behavior&lt;BR /&gt;&amp;nbsp; group&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Specify server groups&lt;BR /&gt;&amp;nbsp; local&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Use local username authentication&lt;BR /&gt;&amp;nbsp; none&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; No authentication&lt;/P&gt;&lt;P&gt;Nexus001(config)# aaa authentication login default local ?&lt;BR /&gt;&amp;nbsp; &amp;lt;CR&amp;gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Aug 2014 13:50:21 GMT</pubDate>
    <dc:creator>Steven Williams</dc:creator>
    <dc:date>2014-08-05T13:50:21Z</dc:date>
    <item>
      <title>Failover to local login when TACACS is reachable but not authenticating</title>
      <link>https://community.cisco.com/t5/network-access-control/failover-to-local-login-when-tacacs-is-reachable-but-not/m-p/1622271#M345924</link>
      <description>&lt;P&gt;Hello, I'm confident I already know the answer to this question but I want to be sure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am moving a large number of Cisco devices to a new TACACS server, is there anything that can be done to allow local login if the new TACACS server is reachable but not authenticating for some reason? For example if the Cisco source IP is not built correctly into the server or the key is not configured properly on the device; in these situations the server is reachable but will not provide authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already have AAA authentication set similar to the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Router1(config)#&lt;STRONG&gt;aaa authentication login default group tacacs+ line&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will allow me to use line authentication if the tacacs server is not reachable but not if the server is reachable and not authenticating properly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas on how/if I can failover to local login for the example situation I provided above?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:49:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/failover-to-local-login-when-tacacs-is-reachable-but-not/m-p/1622271#M345924</guid>
      <dc:creator>101100101</dc:creator>
      <dc:date>2019-03-11T00:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: Failover to local login when TACACS is reachable but not aut</title>
      <link>https://community.cisco.com/t5/network-access-control/failover-to-local-login-when-tacacs-is-reachable-but-not/m-p/1622272#M345925</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if the tacacs server is reachable and not authentication for some reason, then no fallback will be kicked even if the configuration is&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa authentication login default group tacacs+ line.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i don't think there is anyway to force a fallback of authentication server when the primary aaa server is reachable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anisha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S.: please mark this thread as answered if you feel your query is resolved.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Feb 2011 15:55:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/failover-to-local-login-when-tacacs-is-reachable-but-not/m-p/1622272#M345925</guid>
      <dc:creator>andamani</dc:creator>
      <dc:date>2011-02-15T15:55:08Z</dc:date>
    </item>
    <item>
      <title>Failover to local login when TACACS is reachable but not authent</title>
      <link>https://community.cisco.com/t5/network-access-control/failover-to-local-login-when-tacacs-is-reachable-but-not/m-p/1622273#M345926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know this topic is old, but your workaround would be to make the TACACS server unreachable to that device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could do this through policy routing.&amp;nbsp; Route the TACACS servers host address to Null0 based on a source IP of the tacacs source-interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jan 2012 17:46:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/failover-to-local-login-when-tacacs-is-reachable-but-not/m-p/1622273#M345926</guid>
      <dc:creator>adsyparker</dc:creator>
      <dc:date>2012-01-05T17:46:22Z</dc:date>
    </item>
    <item>
      <title>Failover to local login when TACACS is reachable but not authent</title>
      <link>https://community.cisco.com/t5/network-access-control/failover-to-local-login-when-tacacs-is-reachable-but-not/m-p/1622274#M345927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you configure the following command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default local group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you input "local" argument on the command before the "group tacacs+" you should be able to access the IOS device with both Local Username/Password and TACACS+ Username/Password even when the TACACS+ server is up and running.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above behavior can only be triggered when using LOCAL IOS database and then TACACS+. If you input "line" before "group tacacs+" the IOS will only ask for the LINE password when authenticating. It will only ask for TACACS+ credentials if the "line vty 0 15" has no password configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jan 2012 18:38:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/failover-to-local-login-when-tacacs-is-reachable-but-not/m-p/1622274#M345927</guid>
      <dc:creator>camejia</dc:creator>
      <dc:date>2012-01-05T18:38:28Z</dc:date>
    </item>
    <item>
      <title>Is this a true solution to</title>
      <link>https://community.cisco.com/t5/network-access-control/failover-to-local-login-when-tacacs-is-reachable-but-not/m-p/1622275#M345928</link>
      <description>&lt;P&gt;Is this a true solution to allow local authentication when ACS is reachable? We have a need for local authentication so that an application can login using local username and password and change the password for the local username for security compliance.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Aug 2014 14:31:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/failover-to-local-login-when-tacacs-is-reachable-but-not/m-p/1622275#M345928</guid>
      <dc:creator>Steven Williams</dc:creator>
      <dc:date>2014-08-02T14:31:26Z</dc:date>
    </item>
    <item>
      <title>Hi Steve,   You can try the</title>
      <link>https://community.cisco.com/t5/network-access-control/failover-to-local-login-when-tacacs-is-reachable-but-not/m-p/1622276#M345929</link>
      <description>&lt;P&gt;Hi Steve,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; You can try the following command:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 18px;"&gt;aaa authentication login default local group tacacs+&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 18px;"&gt;This means it will try to authenticate using local credentials first then Tacacs. so you will be able to access IOS regardless of Tacacs server being reachble or not.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(119, 119, 119); font-size: 18px;"&gt;However, The above behavior can only be triggered when using LOCAL IOS database and then TACACS+. If you input "line" before "group tacacs+" the IOS will only ask for the LINE password when authenticating. It will only ask for TACACS+ credentials if the "line vty 0 15" has no password configured&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Aug 2014 05:51:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/failover-to-local-login-when-tacacs-is-reachable-but-not/m-p/1622276#M345929</guid>
      <dc:creator>minkumar</dc:creator>
      <dc:date>2014-08-04T05:51:56Z</dc:date>
    </item>
    <item>
      <title>Looks like NX-OS will not</title>
      <link>https://community.cisco.com/t5/network-access-control/failover-to-local-login-when-tacacs-is-reachable-but-not/m-p/1622277#M345930</link>
      <description>&lt;P&gt;Looks like NX-OS will not allow me to do this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nexus001(config)# aaa authentication login default local group&amp;nbsp;TACACS&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;BR /&gt;% Invalid command at '^' marker.&lt;BR /&gt;Nexus001(config)# aaa authentication login default local ?&lt;BR /&gt;&amp;nbsp; &amp;lt;CR&amp;gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nexus001(config)# aaa authentication login ?&lt;BR /&gt;&amp;nbsp; ascii-authentication&amp;nbsp; Enable ascii authentication&lt;BR /&gt;&amp;nbsp; chap&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CHAP authentication for login&lt;BR /&gt;&amp;nbsp; console&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Configure console methods&lt;BR /&gt;&amp;nbsp; default&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Configure default methods&lt;BR /&gt;&amp;nbsp; error-enable&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Enable display of error message on login failures&lt;BR /&gt;&amp;nbsp; mschap&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MSCHAP authentication for login&lt;BR /&gt;&amp;nbsp; mschapv2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MSCHAP V2 authentication for login&lt;/P&gt;&lt;P&gt;Nexus001(config)# aaa authentication login default ?&lt;BR /&gt;&amp;nbsp; fallback&amp;nbsp; Configure fallback behavior&lt;BR /&gt;&amp;nbsp; group&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Specify server groups&lt;BR /&gt;&amp;nbsp; local&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Use local username authentication&lt;BR /&gt;&amp;nbsp; none&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; No authentication&lt;/P&gt;&lt;P&gt;Nexus001(config)# aaa authentication login default local ?&lt;BR /&gt;&amp;nbsp; &amp;lt;CR&amp;gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Aug 2014 13:50:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/failover-to-local-login-when-tacacs-is-reachable-but-not/m-p/1622277#M345930</guid>
      <dc:creator>Steven Williams</dc:creator>
      <dc:date>2014-08-05T13:50:21Z</dc:date>
    </item>
    <item>
      <title>Hi Steve,   Thats seems to be</title>
      <link>https://community.cisco.com/t5/network-access-control/failover-to-local-login-when-tacacs-is-reachable-but-not/m-p/1622278#M345931</link>
      <description>&lt;P&gt;Hi Steve,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; Thats seems to be not possible with Nexus,I thought you were using IOS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can follow the below document and see if that helps:&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/switches/datacenter/sw/4_1/nx-os/security/configuration/guide/sec_nx-os-cfg/sec_aaa.html#wp1259788&lt;/P&gt;&lt;P&gt;Cheers!!&lt;/P&gt;&lt;P&gt;Minakshi(Rate the helpful posts)&lt;/P&gt;</description>
      <pubDate>Wed, 06 Aug 2014 03:46:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/failover-to-local-login-when-tacacs-is-reachable-but-not/m-p/1622278#M345931</guid>
      <dc:creator>minkumar</dc:creator>
      <dc:date>2014-08-06T03:46:42Z</dc:date>
    </item>
  </channel>
</rss>

