RE: Radius Authentication

From: Tim (ccie2be@nyc.rr.com)
Date: Mon Dec 19 2005 - 14:27:35 GMT-3


Henk,

The command you're using doesn't look correct but if it is maybe you're
missing other commands such as aaa new-model, aaa host x.x.x.x, etc.

One thing you might try is using debug aaa to see what traffic is being sent
and received from your radius server.

HTH, Tim

-----Original Message-----
From: nobody@groupstudy.com [mailto:nobody@groupstudy.com] On Behalf Of Henk
Botha
Sent: Monday, December 19, 2005 11:14 AM
To: ccielab@groupstudy.com
Subject: Radius Authentication

Hi

I am a bit confused about the process of Authentication.

I have a router setup to use Radius first and then local
"aaa authentication login use-radius radius local"

It all works fine. But the bit that confuses me is when I use the local
username to login it allows me to log in, as far as I understand this should

only happen if the Radius server is unavailable. With my scenario the Radius

server is always available.

For a test I add a username on the Radius that is exactly the same as the
local with a different password. But using the local still allows me to
login.

Is this the way it should work?

Regards

Henk



This archive was generated by hypermail 2.1.4 : Mon Jan 09 2006 - 07:07:51 GMT-3