<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Login fallback to local user even tacacs configured in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/login-fallback-to-local-user-even-tacacs-configured/m-p/95086#M21799</link>
    <description>&lt;P&gt;Hello!&lt;BR /&gt;&lt;BR /&gt;Generally this issue is due to the TACACS+ server not replying with a 'fail' or 'accept' message. It is probably sending something else in response leading the switch to think that the server is not working, therefore, it falls back to local authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These articles may be helpful:&lt;BR /&gt;&lt;A href="https://extremeportal.force.com/ExtrArticleDetail?an=000093509" target="_blank"&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000093509&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://extremeportal.force.com/ExtrArticleDetail?an=000082285" target="_blank"&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000082285&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;You may also need to collect a PCAP of the TACACS+ exchange, decode it via wireshark, and see what the TACACS server is replying with. If it is not a 'Fail' or 'Accept', that would be the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;</description>
    <pubDate>Fri, 10 Mar 2023 15:49:48 GMT</pubDate>
    <dc:creator>Gabriel_G</dc:creator>
    <dc:date>2023-03-10T15:49:48Z</dc:date>
    <item>
      <title>Login fallback to local user even tacacs configured</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/login-fallback-to-local-user-even-tacacs-configured/m-p/95078#M21798</link>
      <description>&lt;P&gt;We configured TACACS over Extreme Switch but you can also log in with a local account.&lt;/P&gt;&lt;P&gt;My Configuration is&amp;nbsp;&lt;/P&gt;&lt;P&gt;configure tacacs primary server 172.16.11.52 49 client-ip 172.16.0.10 vr VR-Default&lt;BR /&gt;configure tacacs primary shared-secret encrypted "#$H4H5oLIn4H+TRgtYrxiHVtFwGtljZw=="&lt;BR /&gt;configure tacacs-accounting primary server 172.16.11.52 49 client-ip 172.16.0.10 vr VR-Default&lt;BR /&gt;configure tacacs-accounting primary shared-secret encrypted "#$hp08PEW0oz0kZBjQaP0bHYqBdCcqSg=="&lt;BR /&gt;enable tacacs&lt;BR /&gt;configure tacacs timeout 60&lt;BR /&gt;enable tacacs-accounting&lt;BR /&gt;enable tacacs-authorization&lt;BR /&gt;configure tacacs fallback disallow&lt;BR /&gt;configure tacacs priv-lvl required&lt;BR /&gt;create account admin cisco encrypted "$5$sRVgQN$aL8UAzkEwMLmGPy82v1On6QLuvBeKdjVQGCRsUmcjq3"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2023 09:29:18 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/login-fallback-to-local-user-even-tacacs-configured/m-p/95078#M21798</guid>
      <dc:creator>pgimer</dc:creator>
      <dc:date>2023-03-10T09:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: Login fallback to local user even tacacs configured</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/login-fallback-to-local-user-even-tacacs-configured/m-p/95086#M21799</link>
      <description>&lt;P&gt;Hello!&lt;BR /&gt;&lt;BR /&gt;Generally this issue is due to the TACACS+ server not replying with a 'fail' or 'accept' message. It is probably sending something else in response leading the switch to think that the server is not working, therefore, it falls back to local authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These articles may be helpful:&lt;BR /&gt;&lt;A href="https://extremeportal.force.com/ExtrArticleDetail?an=000093509" target="_blank"&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000093509&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://extremeportal.force.com/ExtrArticleDetail?an=000082285" target="_blank"&gt;https://extremeportal.force.com/ExtrArticleDetail?an=000082285&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;You may also need to collect a PCAP of the TACACS+ exchange, decode it via wireshark, and see what the TACACS server is replying with. If it is not a 'Fail' or 'Accept', that would be the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps!&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2023 15:49:48 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/login-fallback-to-local-user-even-tacacs-configured/m-p/95086#M21799</guid>
      <dc:creator>Gabriel_G</dc:creator>
      <dc:date>2023-03-10T15:49:48Z</dc:date>
    </item>
  </channel>
</rss>

