<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Key precedence when using aaa group server and radius-server host in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/key-precedence-when-using-aaa-group-server-and-radius-server/m-p/1767426#M439721</link>
    <description>&lt;P&gt;Looking at the following configuration on a Cisco Router:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;!&lt;BR /&gt;aaa group server radius 8021x&lt;BR /&gt;&amp;nbsp; &lt;SPAN style="color: #ff0000;"&gt;server-private 192.168.1.1&lt;/SPAN&gt; auth-port 1812 acct-port 1813 key &lt;SPAN style="color: #ff0000;"&gt;SECRET-A&lt;/SPAN&gt;&lt;BR /&gt;!&lt;BR /&gt;aaa group server radius radius-auth&lt;BR /&gt;&lt;SPAN style="color: #333333;"&gt; server-private 192.168.2.1&lt;/SPAN&gt; auth-port 1645 acct-port 1646 key SECRET-B&lt;BR /&gt;!&lt;BR /&gt;&lt;SPAN style="color: #0000ff;"&gt;radius-server host 192.168.1.1&lt;/SPAN&gt; auth-port 1812 acct-port 1813 key &lt;SPAN style="color: #0000ff;"&gt;SECRET-C&lt;/SPAN&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;The question is:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When considering the radius server 192.168.1.1 which password / key will take precedence: &lt;SPAN style="color: #ff0000;"&gt;SECRET-A&lt;/SPAN&gt; or&lt;SPAN style="color: #0000ff;"&gt; SECRET-B&lt;/SPAN&gt; ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Reading the documentation posted below the answer is:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;SECRET-A&lt;/SPAN&gt;, because:&lt;BR /&gt;In cases where both global commands and server commands are used, the server command will take precedence over the global command.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone know if this is correct ? Which key will take precedence ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See: &lt;A href="http://www.cisco.com/en/US/docs/ios/12_2/security/configuration/guide/scfrad.html#wp1001168" target="_blank"&gt;http://www.cisco.com/en/US/docs/ios/12_2/security/configuration/guide/scfrad.html#wp1001168&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See: &lt;A href="http://www.cisco.com/en/US/docs/ios/12_2/security/configuration/guide/scfrad.html#wp1001482" target="_blank"&gt;http://www.cisco.com/en/US/docs/ios/12_2/security/configuration/guide/scfrad.html#wp1001482&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Feb 2020 19:11:01 GMT</pubDate>
    <dc:creator>klaustecnico</dc:creator>
    <dc:date>2020-02-24T19:11:01Z</dc:date>
    <item>
      <title>Key precedence when using aaa group server and radius-server host</title>
      <link>https://community.cisco.com/t5/network-access-control/key-precedence-when-using-aaa-group-server-and-radius-server/m-p/1767426#M439721</link>
      <description>&lt;P&gt;Looking at the following configuration on a Cisco Router:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;!&lt;BR /&gt;aaa group server radius 8021x&lt;BR /&gt;&amp;nbsp; &lt;SPAN style="color: #ff0000;"&gt;server-private 192.168.1.1&lt;/SPAN&gt; auth-port 1812 acct-port 1813 key &lt;SPAN style="color: #ff0000;"&gt;SECRET-A&lt;/SPAN&gt;&lt;BR /&gt;!&lt;BR /&gt;aaa group server radius radius-auth&lt;BR /&gt;&lt;SPAN style="color: #333333;"&gt; server-private 192.168.2.1&lt;/SPAN&gt; auth-port 1645 acct-port 1646 key SECRET-B&lt;BR /&gt;!&lt;BR /&gt;&lt;SPAN style="color: #0000ff;"&gt;radius-server host 192.168.1.1&lt;/SPAN&gt; auth-port 1812 acct-port 1813 key &lt;SPAN style="color: #0000ff;"&gt;SECRET-C&lt;/SPAN&gt;&lt;BR /&gt;!&lt;BR /&gt;&lt;BR /&gt;The question is:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When considering the radius server 192.168.1.1 which password / key will take precedence: &lt;SPAN style="color: #ff0000;"&gt;SECRET-A&lt;/SPAN&gt; or&lt;SPAN style="color: #0000ff;"&gt; SECRET-B&lt;/SPAN&gt; ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Reading the documentation posted below the answer is:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;SECRET-A&lt;/SPAN&gt;, because:&lt;BR /&gt;In cases where both global commands and server commands are used, the server command will take precedence over the global command.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone know if this is correct ? Which key will take precedence ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See: &lt;A href="http://www.cisco.com/en/US/docs/ios/12_2/security/configuration/guide/scfrad.html#wp1001168" target="_blank"&gt;http://www.cisco.com/en/US/docs/ios/12_2/security/configuration/guide/scfrad.html#wp1001168&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See: &lt;A href="http://www.cisco.com/en/US/docs/ios/12_2/security/configuration/guide/scfrad.html#wp1001482" target="_blank"&gt;http://www.cisco.com/en/US/docs/ios/12_2/security/configuration/guide/scfrad.html#wp1001482&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2020 19:11:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/key-precedence-when-using-aaa-group-server-and-radius-server/m-p/1767426#M439721</guid>
      <dc:creator>klaustecnico</dc:creator>
      <dc:date>2020-02-24T19:11:01Z</dc:date>
    </item>
  </channel>
</rss>

