Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Firewall_Head
Explorer

Failed login alerts because of TACACS+ authentication failure

Hi Checkmates,

I have a firewall with TACACS+ enabled and it's working fine. 

I also have some local users configured for administration, but whenever I login using the local user ID, it creates a "failed authentication" log.

Why is my local user even getting authenticated with the TACACS+ server.

Can somebody help me on this ? This is creating a headache for the SOC team.

 

Thanks in advance !

========

WR,

FH

 

 

0 Kudos
4 Replies
the_rock
Legend
Legend

Hey bro,

Do you have a screenshot of it by any chance?

Andy

0 Kudos
Firewall_Head
Explorer

Hi @the_rock ,

Logs coming up, give me sometime.

====

WR,

FH

the_rock
Legend
Legend

If it does not help, we can do quick remote tomorrow.

Andy

0 Kudos
the_rock
Legend
Legend

Hey bro,

Just thought of something. IF you want to block local users from connecting, you can run blockSFAInternalUsers command from fw expert mode to see what it shows, just add -s flag and it would show you how to block it if you want.

Andy

[Expert@R82:0]# blockSFAInternalUsers

Internal User, Single Factor Auth. Blocking Utility

Usage: blockSFAInternalUsers [flags]

-s show current status
-a allow internal users with password single factor to authenticate
-b block internal users with password single factor from authenticating

[Expert@R82:0]# blockSFAInternalUsers -s

blockSFAInternalUsers: Allowed

[Expert@R82:0]#

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events