- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hi Team,
We have configured TACACS authentication for Firewall.
User are able to authenticate from TACACS server.
But local user authentication shouldn't work when TACACS is working.
Local authentication should work only when TACACS server is not working.
Is there any priority to set TACACS as high priority ?
First priority always is Local Authentication, see sk111572.
Hi Team,
Is there any solution for this ?
Afaik local user auth always is enabled as a fallback. See sk111572 Authentication on Gaia OS from console with local user fails (times out) while two RADIUS servers are configured:
Code was improved: Local authentication will have priority over RADIUS authentication.
Hi Albrecht,
Thank you for the information.
Here local authentication shouldn't work when TACACS authentication is active.Local authentication should work only if the TACACS auth fails.
Is there any priority setting ?
First Priority --- > TACACS Aunthentication.
Second Priority ---> Local Authentication.
First priority always is Local Authentication, see sk111572.
sk105320 - How to disable local authentication when RADIUS authentication is available
This is for radius but might be very close for tacacs. Would need to play around with it to see. Its all PAM under the hood so my guess is it should work.
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY