08-11-2025 09:27 AM
Hi Cisco Community,
I’m configuring local authentication in Cisco ACI but need help understanding the exact purpose of each option available in the settings (e.g., "Local", "TACACS+", "RADIUS", "LDAP", etc.). I’ve searched online but couldn’t find official documentation that clearly explains:
What each authentication method specifically controls in ACI.
Best practices for when to use one over another.
Any dependencies or prerequisites for these options.
Thanks in advance! I’ll summarize the answers for others once resolved.
#ACI #Authentication #LocalAuth #HelpNeeded
08-12-2025 01:20 AM
Hello @willytech007 ,
Local authentication in ACI is where the user accounts are stored on the APIC database.
The other options you mentioned, LDAP, RADIUS, etc. are not local authentication options.
There are no dependencies between them. You can configure any one of them or all of them.
I haven't encountered a best practice of which to choose over which so far. Some combine local authentication with LDAP. Some might combine local authentication with Cisco ISE as a RADIUS server. But a healthy practice is not to disable local authentication at all. Remember that at APIC initial installation, you configure a local account called 'admin' which you use to login to APIC.
09-15-2025 07:51 PM
Hello sir
Right, I read best practie is never disable fallback authentication.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide