The normal practice is to define an authentication (or more accurately aaa) method list that has LOCAL after the RSA method.
That way the router will always use RSA except when it is not reachable in which case it will fall back to local. Otherwise you would be locked out of the router when RSA is not working for whatever reason.