Forum Discussion
TACACS vs local users (admin and root)
Running 11.4.1
We implemented TACACS for administrative users and that part works fine, but when the TACACS servers are unreachable we are unable to login with local root or admin (console, ssh or web). These users work fine while TACACS is online.
Why can I not use the local users when TACACS is unavailable?
4 Replies
- Pedro_HaoaRet. Employee
Hi,
By default, the BIG-IP system uses its own user directory for user authentication. If you configure a remote authentication method, such as LDAP, RADIUS, or TACACS, the system does not allow you to use local authentication as a backup method if remote authentication fails.
Please add more TACACS servers to avoid this or use local database instead.
More info here: https://support.f5.com/kb/en-us/solutions/public/13000/400/sol13456.html?sr=26331845
- Pedro_HaoaRet. Employee
Thanks Nathan for the update.
So this is another issue.
DarrellE, please try to contact F5 technical support and open a new case.
- nathe
Cirrocumulus
Are u sure it's not logging in as a remote root or admin user when tacacs is up, and not the local one?? - DarrellE_142273
Nimbostratus
Yeah, very sure. I administer the TACACS system and checked the logs while the issue was going on.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com