Forum Discussion

DarrellE_142273's avatar
DarrellE_142273
Icon for Nimbostratus rankNimbostratus
Mar 09, 2015

TACACS vs local users (admin and root)

Running 11.4.1

 

We implemented TACACS for administrative users and that part works fine, but when the TACACS servers are unreachable we are unable to login with local root or admin (console, ssh or web). These users work fine while TACACS is online.

 

Why can I not use the local users when TACACS is unavailable?

 

4 Replies

  • Hi,

     

    By default, the BIG-IP system uses its own user directory for user authentication. If you configure a remote authentication method, such as LDAP, RADIUS, or TACACS, the system does not allow you to use local authentication as a backup method if remote authentication fails.

     

    Please add more TACACS servers to avoid this or use local database instead.

     

    More info here: https://support.f5.com/kb/en-us/solutions/public/13000/400/sol13456.html?sr=26331845

     

  • Thanks Nathan for the update.

     

    So this is another issue.

     

    DarrellE, please try to contact F5 technical support and open a new case.

     

  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus
    Are u sure it's not logging in as a remote root or admin user when tacacs is up, and not the local one??
  • Yeah, very sure. I administer the TACACS system and checked the logs while the issue was going on.