cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4543
Views
0
Helpful
1
Replies

% Error in authentication

Hoyt Page
Level 1
Level 1

I have been receiving an error when switches that I have are not online. I use a local account to login and when I try to get into enable mode, I get % error in the authentication. 

 

aaa authentication attempts login 5
aaa authentication login default group tacacs+ local
aaa authentication enable default group tacacs+
aaa authentication dot1x default group radius group TEST
aaa authorization console
aaa authorization config-commands
aaa authorization exec default group tacacs+ if-authenticated
aaa authorization commands 0 default group tacacs+ none
aaa authorization commands 1 default group tacacs+ if-authenticated
aaa authorization commands 15 default group tacacs+ if-authenticated
aaa authorization network default group radius
aaa accounting dot1x default start-stop group radius
aaa accounting commands 15 default start-stop group tacacs+
aaa accounting connection default start-stop group tacacs+
!

 

How can I have tacacs authentication enabled and when I lose connectivity, be able to failover to the local account?

 

Thank you for your time!

1 Reply 1

Cristian Matei
VIP Alumni
VIP Alumni

Hi,

 

 See the attached config, test again:

 

 aaa authentication enable default group tacacs+ enable

aaa authorization exec default group tacacs+ local

aaa authorization commands 0 default group tacacs+ none

aaa authorization commands 1 default group tacacs+ local 

aaa authorization commands 15 default group tacacs+ local 

!

enable secret xxxxx

username xxxx privilege x secret xxxx

 

Regards,

Cristian Matei.

Review Cisco Networking for a $25 gift card