<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 8.0 and Microsoft ISA (local user backup) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/asa-8-0-and-microsoft-isa-local-user-backup/m-p/950543#M391233</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On a router, "aaa authentication login default local group tacacs+ " will ALWAYS use the local user DB, never tacacs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"aaa authentication login default group tacacs+ local" will first try tacacs and only if the tacacs server is not responding, use the local DB. Note that if the tacacs DOES respond but rejects the authentication attempt (user does not exist or wrong password), that the router will NOT use the local DB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That said, on pix/asa you can do the same, e.g.:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server TPLUS protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TPLUS (management) host 10.0.0.1&lt;/P&gt;&lt;P&gt;aaa authentication telnet console TPLUS LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;H&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 14 Mar 2008 11:35:39 GMT</pubDate>
    <dc:creator>Herbert Baerten</dc:creator>
    <dc:date>2008-03-14T11:35:39Z</dc:date>
    <item>
      <title>ASA 8.0 and Microsoft ISA (local user backup)</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-8-0-and-microsoft-isa-local-user-backup/m-p/950542#M391232</link>
      <description>&lt;P&gt;What is the command so that when the username + password cannot be found in the microsoft isa server, the pix will look at the local database?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This command works in the router, but I cannot seem to find the equivlant for the pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default local group tacacs+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically does the pix asa 8.0 support Multiple authorization commands?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for your help.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:43:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-8-0-and-microsoft-isa-local-user-backup/m-p/950542#M391232</guid>
      <dc:creator>vtra</dc:creator>
      <dc:date>2019-03-10T22:43:12Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.0 and Microsoft ISA (local user backup)</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-8-0-and-microsoft-isa-local-user-backup/m-p/950543#M391233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On a router, "aaa authentication login default local group tacacs+ " will ALWAYS use the local user DB, never tacacs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"aaa authentication login default group tacacs+ local" will first try tacacs and only if the tacacs server is not responding, use the local DB. Note that if the tacacs DOES respond but rejects the authentication attempt (user does not exist or wrong password), that the router will NOT use the local DB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That said, on pix/asa you can do the same, e.g.:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server TPLUS protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TPLUS (management) host 10.0.0.1&lt;/P&gt;&lt;P&gt;aaa authentication telnet console TPLUS LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;H&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Mar 2008 11:35:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-8-0-and-microsoft-isa-local-user-backup/m-p/950543#M391233</guid>
      <dc:creator>Herbert Baerten</dc:creator>
      <dc:date>2008-03-14T11:35:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 8.0 and Microsoft ISA (local user backup)</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-8-0-and-microsoft-isa-local-user-backup/m-p/950544#M391234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much, that helped a lot!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Mar 2008 19:06:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-8-0-and-microsoft-isa-local-user-backup/m-p/950544#M391234</guid>
      <dc:creator>vtra</dc:creator>
      <dc:date>2008-03-27T19:06:26Z</dc:date>
    </item>
  </channel>
</rss>

