cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
311
Views
0
Helpful
1
Replies

Local authentication with TACACS

Ehsan M.
Level 1
Level 1

Hello experts,

I know this might be an easy one for some...

Is there a way to have your network device (Switch or Router) to try to first authenticate locally (if the username was found on the local database of the device) and then if not found, device reach for TACACS authentication? We're rolling out TACACS authentication but don't want to disrupt existing 'local' authentication on our devices.

Thanks! Any help is highly apreciated!

Cheers,

Ehsan

1 Reply 1

Rolf Fischer
Level 9
Level 9

Ehsan,

you can define a list of authentication methods; the methods will be tried in the order in which they are configured:

aaa authentication login {default|<name>} method1 [method2] ...

I haven't tested it but this should work as desired:

aaa authentication login default local group tacacs+

HTH

Rolf