cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1990
Views
0
Helpful
3
Replies

TACACS + Radius authentication

williamehmke1
Level 1
Level 1

I was wondering if anyone has successfully configured both TACACS and Radius on Cisco devices for aaa. We are looking to move to TACACS and have it reside on our ISE PSN's but I want to still keep radius as a backup as it will continue to reside on VM's outside of the ISE PSN's. 

 

Any input is greatly appreciated

1 Accepted Solution

Accepted Solutions

You can have up to 3 different methods for login for example:

aaa authentication login default group tacacs(first method) group radius (fallback) local (2nd fallback)

 

Fallback to next method will occur only if there is no communication with previous method.

View solution in original post

3 Replies 3

Marvin Rhoads
Hall of Fame
Hall of Fame

I haven't had the occassion to do it but you should be able to put method lists for both in sequence for your aaa authentication commands. The device will always try the servers first in the list and only use the second method if all servers time out from the first method.

ok Thank you. I will try find some examples to reference and then give it a try

You can have up to 3 different methods for login for example:

aaa authentication login default group tacacs(first method) group radius (fallback) local (2nd fallback)

 

Fallback to next method will occur only if there is no communication with previous method.