cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
264
Views
0
Helpful
1
Replies

FWSM not accessible with local accounts if AAA is configured

pweichmann
Level 1
Level 1

I do have an issue that I am not able to log in with telnet to our FWSM with a local account created in the system context.

Let's say I have an account usera with password 12345 and I do have AAA configured with LOCAL added as well.

When I try to log in I see the login on the ACS as failed which is correct but then it should check the local database and see that this user exists and should let me in.

Does anybody have an idea what could be the problem?

1 Accepted Solution

Accepted Solutions

Fernando_Meza
Level 7
Level 7

Hi ..

It sounds like you have configured AAA using two methods of authentication (RADIUS or TACACS and LOCAL). If that is correct, then be aware that LOCAL authentication will be checked only if the server(s) referred by the first method of authentication (the ACS in your case) is unavailable. The second authentication method (LOCAL in your case) will not be checked if the FWSM can contact the ACS server.

I hope it helps .. please rate it if it does !!!

View solution in original post

1 Reply 1

Fernando_Meza
Level 7
Level 7

Hi ..

It sounds like you have configured AAA using two methods of authentication (RADIUS or TACACS and LOCAL). If that is correct, then be aware that LOCAL authentication will be checked only if the server(s) referred by the first method of authentication (the ACS in your case) is unavailable. The second authentication method (LOCAL in your case) will not be checked if the FWSM can contact the ACS server.

I hope it helps .. please rate it if it does !!!

Review Cisco Networking products for a $25 gift card