<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic There is default support for  in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/configuring-aaa-fallback-to-local-on-nexus-9k/m-p/2873912#M36831</link>
    <description>&lt;P&gt;There is default support for "local". &amp;nbsp;You do not have to specifically identify it. &amp;nbsp;This provided I agree with you to have the "admin" name defined in TACACS. &amp;nbsp;Unfortunately, I do not have access to that server.&lt;/P&gt;</description>
    <pubDate>Thu, 28 Apr 2016 18:19:49 GMT</pubDate>
    <dc:creator>rpatnaik_slf</dc:creator>
    <dc:date>2016-04-28T18:19:49Z</dc:date>
    <item>
      <title>Configuring AAA fallback to local on Nexus 9k</title>
      <link>https://community.cisco.com/t5/network-access-control/configuring-aaa-fallback-to-local-on-nexus-9k/m-p/2873910#M36827</link>
      <description>&lt;P&gt;To Whom it May Concern,&lt;BR /&gt;&lt;BR /&gt;I've configured the following:&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;tacacs-server key abcdefg&lt;BR /&gt;tacacs-server host x.x.x.x timeout 5 &lt;BR /&gt;tacacs-server host y.y.y.y timeout 5 &lt;BR /&gt;aaa group server tacacs+ tacacs &lt;BR /&gt; server x.x.x.x&amp;nbsp;&lt;BR /&gt; server y.y.y.y&lt;BR /&gt; use-vrf management&lt;/P&gt;
&lt;P&gt;source-interface mgmt0&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;aaa authentication login default group tacacs&amp;nbsp;&lt;BR /&gt;aaa authorization commands default group tacacs local &lt;BR /&gt;aaa accounting default group tacacs &lt;BR /&gt;&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;username admin password 5 $5$FGFIEN$6.3JWzAkkhZvxNrbd6pB6P6UqFULglpyhgJgwq9WQbA role network-admin&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;What I'm looking at is to ensure that fallback works when TACACS+ is enabled. However, I shouldn't be able to use the "admin" account even when tacacs is working. &amp;nbsp;What am I doing wrong? &amp;nbsp;It seems that "admin" is allowed still with TACACS working.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Rash&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:38:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configuring-aaa-fallback-to-local-on-nexus-9k/m-p/2873910#M36827</guid>
      <dc:creator>rpatnaik_slf</dc:creator>
      <dc:date>2019-03-11T06:38:40Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/configuring-aaa-fallback-to-local-on-nexus-9k/m-p/2873911#M36828</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;aaa works order of method types.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if no response at one method pass to another method and vice versa.&lt;/P&gt;
&lt;P&gt;if fail at one method dont pass another method and reject.&lt;/P&gt;
&lt;P&gt;you defined for authentication &amp;nbsp;one method as group tacacs. and if tacacs authentication is failed you take a message authentication fail.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should add to configuration&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;aaa authentication login default group tacacs local&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;or you should define an user in tacacs user that name is &lt;SPAN style="text-decoration: underline;"&gt;&lt;EM&gt;admin&lt;/EM&gt;&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;Best regards.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2016 13:52:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configuring-aaa-fallback-to-local-on-nexus-9k/m-p/2873911#M36828</guid>
      <dc:creator>aydinnmu1</dc:creator>
      <dc:date>2016-04-05T13:52:48Z</dc:date>
    </item>
    <item>
      <title>There is default support for</title>
      <link>https://community.cisco.com/t5/network-access-control/configuring-aaa-fallback-to-local-on-nexus-9k/m-p/2873912#M36831</link>
      <description>&lt;P&gt;There is default support for "local". &amp;nbsp;You do not have to specifically identify it. &amp;nbsp;This provided I agree with you to have the "admin" name defined in TACACS. &amp;nbsp;Unfortunately, I do not have access to that server.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2016 18:19:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/configuring-aaa-fallback-to-local-on-nexus-9k/m-p/2873912#M36831</guid>
      <dc:creator>rpatnaik_slf</dc:creator>
      <dc:date>2016-04-28T18:19:49Z</dc:date>
    </item>
  </channel>
</rss>

