Conditions for conformance
Consider the following conditions for remote server authentication:
- If the first source is specified as
default, do not specify a second source. A second source signals a request to set the login authentication mode to its default value, which is
local. If the first source is
local, the second source cannot be set to any value, because the failover will never occur.
- The source of authentication (except
local) and the corresponding server type configuration are dependent on each other. Therefore, at least one server should be configured before that server type can be specified as a source.
- If the source is configured to be a server type, you cannot delete a server of that type if it is the only server in the list. For example, if there are no entries in the TACACS+ server list, the authentication mode cannot be set to
tacacs+ or
tacacs+ local. Similarly, when the authentication mode is
radius or
radius local, a RADIUS server cannot be deleted if it is the only one in the list.