Refer to the Authentication tab to define how user credential validation is conducted on behalf of a Management Access policy. Setting up an authentication scheme by policy allows for policy member credential validation collectively, as opposed to authenticating users individually.
To configure an external authentication resource:
Local |
Select whether the authentication server resource is centralized (local), or whether an external authentication resource is used for validating user access requests. |
RADIUS |
If local authentication is disable, define whether the RADIUS server is External or Fallback. Select fallback to revert to local RADIUS resources should a dedicated external server be unreachable. |
AAA Policy |
Define the AAA policy used to authenticate user validation requests to the controller or service platform managed network. Select the Create icon as needed to define a new AAA policy or select the Edit icon to modify the configuration of an existing policy. |
TACACS |
If local authentication is disabled, optionally select Authentication or Fallback (only one authentication or fallback option can be selected) or Accounting and Authorization. TACACS policies control user access to devices and network resources while providing separate accounting, authentication, and authorization services. |
AAA TACACS Policy |
Select an existing AAA TACACS policy (if available), or select Create to define a new policy or Edit to modify an existing one. |
Authentication | Select to enable TACACS authentication on login. This option is not available when the Local field is set to enabled. Also, this option cannot be selected when Fallback is selected. |
Fallback | Select to enable fallback to use local authentication if TACACS authentication fails. This option is not available when the Local field is set to enabled. Also, this option cannot be selected when Authentication is selected. |
Accounting | Select to enable TACACS accounting on login. This option is not available when the Local field is set to enabled. When selected, the AAA TACACS Policy field is enabled. |
Authorization | Select to enable TACACS authorization on login. |
Authorization Fallback | Select to enable fallback on TACACS authorization failure. This option is only available when Authorization is selected. |