cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2402
Views
0
Helpful
7
Replies

can't login to switch using Tacacs and local user

1 Accepted Solution

Accepted Solutions

Yes, disconnecting the uplink/ trunk port to your core would have the same effect, although the ACL option could be done in production during office hours.

View solution in original post

7 Replies 7

Seb Rupik
VIP Alumni
VIP Alumni

Hi there,

Did you have a fallback identity store configured on the AAA method? If so, you could create an ACL on your management network SVI to block the switches in question from being able to contact the TACACS server. This should cause the switch to timeout and fallback to the second identity store, hopefully local.

 

Have you tried access via the console port?

 

cheers,

Seb.

Hi Seb,

using console port as below

not prompt at all for the username

 

 

Using the console port, does it prompt you for a password?

nope, only showed the banner...
that all, and it keep on looping on the same screen output.
at least if it prompt username/password or > , i can key in something

Have you tried the ACL to block TACACS traffic?

haven't try but it is the same as i disconnect the trunk port,correct?

I might do it during off office hours .

cut off the connection i hope it go to local

Yes, disconnecting the uplink/ trunk port to your core would have the same effect, although the ACL option could be done in production during office hours.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: