Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

RADIUS question 1

Status
Not open for further replies.

penghon

MIS
Jul 22, 2003
41
SG
The default/basic configuration of RADIUS/aaa auth goes something like this:

aaa authentication login default group radius local
aaa authentication login localauth local

What does the 2nd line do?
 
Defines a method of authentication against local user database and names it localauth.
 
i see...so this would mean that this line is redundant given that the first line stated that should the RADIUS server be uncontactable, the cisco device will authenticate user with the local database.

Am i correct?
 
No it is not redundant. This way you would have two methods of authentication with different names.

If you don't specify the name or use default when defining authentication for something like ppp or line vty or ... it will use the first line, uses the radius server to autheticate and if it failes uses the local database. On the other hand if you specify localauth as the name of authentication method somewhere, it will only use the local database.
 
easier terms would be the 'localauth' is your authentication profile, and you have to apply that profile to the *ty sessions, if you don't apply one, default is used..


BuckWeet
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top