Got it

Local user authentication stop working after configure Radius auth.

Created: Jan 21, 2020 13:07:12Latest reply: Jan 21, 2020 14:11:45 406 2 0 0 1
  Rewarded HiCoins: 1 (problem resolved)


Hi all,


Local user authentication stop working after configure radius authentication (without accounting).


I follow this guide: https://support.huawei.com/enterprise/en/doc/EDOC1100034077/142fad68/example-for-configuring-radius-authentication-and-accounting


#display run

radius-server template radius4devices
 radius-server shared-key cipher %Mw.3}7ST|CG&H}8$1UZQOF"NG-%^%#
 radius-server authentication x.x.x.x 1812 weight 80
 undo radius-server user-name domain-included
aaa
 authentication-scheme auth
  authentication-mode radius *** local ***
local
 domain huawei
  authentication-scheme auth
  radius-server radius4devices
 local-user admin password irreversible-cipher $1a$)&EEJ"y)A*[P>.w4_X){n7Q7A^;D+1<+t5-:!29$
 local-user admin privilege level 15
 local-user admin service-type terminal ssh http


In logbuffer:

Dec  7 2019 06:07:26+00:00 Huawei %SSH/4/SSH_FAIL(l)[5]:Failed to log in through SSH. (Ip=y.y.y.y, UserName=admin, Times=2).


I tried change admin password, and reboot, but don't work


Any ideas?

Thanks


Featured Answers

Best answer

Recommended answer

Popeye_Wang
Admin Created Jan 21, 2020 13:17:59

Hello monchito,

You have configured the authentication-mode radius local command. At this time, if a login account is created locally but not on the remote server, remote authentication fails and local authentication will not be performed.

For details, see https://support.huawei.com/hedex/hdx.do?docid=EDOC1100101074&id=EN-US_CLIREF_0176366633&lang=en

radius.

You can create the account on the server or change the command to authentication-mode local radius.

Any further questions, let us know!

View more
  • x
  • convention:

All Answers

Hello monchito,

You have configured the authentication-mode radius local command. At this time, if a login account is created locally but not on the remote server, remote authentication fails and local authentication will not be performed.

For details, see https://support.huawei.com/hedex/hdx.do?docid=EDOC1100101074&id=EN-US_CLIREF_0176366633&lang=en

radius.

You can create the account on the server or change the command to authentication-mode local radius.

Any further questions, let us know!

View more
  • x
  • convention:

Hi @Popeye_Wang, you're right, and thanks for the documentation reference

I'll use
*authentication-mode local radius*
instead of
*authentication-mode radius local*

I think *authentication-mode radius local* it used to force radius authentication unless the server is not working fine o the communication, that pretty cool, but *authentication-mode radius local* it adjust better to my scenario.

Thanks!
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.