07-08-2015 07:10 AM - edited 03-12-2019 05:46 PM
Hi,
I have a Radius server wich has to authenticate users in order to allow them a connection on routers. In this case, each router is a NAS(Network Access Server). A fallback method, has been defined in startup&running configuration.
I try to find a method to make Radius authentication for the most requests send and allow local authentication(means on the router, based on the local account defined on configuration file) for few IP addresses. So those few IP addresses don't have to request the Radius Server (bypass of the Radius Server for operate authentication made on local accounts)before to be authenticate.
Is there a method, that exists to do such a scheme?
Thank you for your help,
07-11-2015 08:00 PM
I think this might be possible by using the rotary mechanism where you can bind a different ssh/telnet based port to a specific VTY lines. Then you can apply a different policy on those VTY lines and assign them an access-list where they are only permitted from specific IPs. Here is a document that explains the rotary functionality:
Thank you for rating helpful posts!
09-16-2015 08:09 AM
Hi Neno,
Thank you for your information. I have worked on anonther prior project that why my answer arrive with late. I have looked the page indicated and the idea describe seems good.
Thanks a lot ;-)
--
Joël
09-16-2015 11:52 AM
You are welcome! Try it out and let us know how it goes.
Thank you for rating helpful posts!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide