Refer to the Authentication tab to define how user credential validation is conducted on behalf of a Management Access policy. Setting up an authentication scheme by policy allows for policy member credential validation collectively, as opposed to authenticating users individually.
To configure an external authentication resource:
Local |
Select whether the authentication server resource is centralized (local), or whether an external authentication resource is used for validating user access requests. |
RADIUS |
If local authentication is disable, define whether the RADIUS server is External or Fallback. Select fallback to revert to local RADIUS resources should a dedicated external server be unreachable. |
Authentication | Select to enable TACACS authentication on login. This option is not available when the Local field is set to enabled. Also, this option cannot be selected when Fallback is selected. |
Fallback | Select to enable fallback to use local authentication if TACACS authentication fails. This option is not available when the Local field is set to enabled. Also, this option cannot be selected when Authentication is selected. |
Accounting | Select to enable TACACS accounting on login. This option is not available when the Local field is set to enabled. When selected, the AAA TACACS Policy field is enabled. |
Authorization | Select to enable TACACS authorization on login. |
Authorization Fallback | Select to enable fallback on TACACS authorization failure. This option is only available when Authorization is selected. |