cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2810
Views
0
Helpful
1
Replies

% Backup authentication

lemmocisco
Level 1
Level 1

Hi,

I have configured accaunting with Tacacs on a 3560 as:

- aaa authentication login default group tacacs+ local none

everything works fine but when I let the tacacs go off-line (ip route to null0) I can still telnet in the 3560 using username and passwords defined on the tacacs server, an it promps me "% Backup authentication", is it correct? I would expect not to be possible to use the same credentials but it should allow the local user database

thanks

1 Accepted Solution

Accepted Solutions

Premdeep Banga
Level 7
Level 7

Try removing "none", command should look like,

aaa authentication login default group tacacs+ local

- At this moment, I think this is happening,

-- Tacacs+ services not available, go for next method,

-- Local account (the username/password combination that you used does not exist on the local database), go for next method,

-- none (you are in)

Regards,

Prem

Please rate if it helps!

View solution in original post

1 Reply 1

Premdeep Banga
Level 7
Level 7

Try removing "none", command should look like,

aaa authentication login default group tacacs+ local

- At this moment, I think this is happening,

-- Tacacs+ services not available, go for next method,

-- Local account (the username/password combination that you used does not exist on the local database), go for next method,

-- none (you are in)

Regards,

Prem

Please rate if it helps!