can not use local user login ssh after configuring the Tacacs

2023-12-29 10:41:28 Published
  • 0 Followed
  • 0Collected ,2110Browsed

Network Topology

irrelevant


Problem Description

When setting up the switch for the first time, I create a local user with maximum Network-admin rights.

After entering the list of commands from the guide on page 23 (in attachment), I am no longer allowed to access the Switch under a local account via SSH and HTTPS.

Please help me find the reason. And how to avoid it, that ssh or web will be available by local account.


Process Analysis

because all the port is enable the tacacs authentication, so the local user also will sent to tacacs sever to do authentication,


Solution

Please create another domain for your local ssh authentication, like this, then use username@domain to login in the switch

 

#

domain local

authentication lan-access local

authorization lan-access none

accounting lan-access none

#

 

#

local-user admin class manage

password hash $h$6$wdQtT0xgikmuNNuj$L4yfSaE32k7nMuEYIPdmcqaz5qZKZWlgaKu7lmVJOtnFaoYKm2W6o5Smqx5ROgoKAO91RCm9yaqaJxwe+c27Pg==

service-type ftp

service-type ssh telnet http https

authorization-attribute user-role network-admin

#

 

So you can login with admin@local to ssh to switch


Please rate this case:   
0 Comments

No Comments

Add Comments: