A
UTHENTICATION
C
OMMANDS
4-97
Authentication Sequence
authentication login
This command defines the login authentication method and precedence.
Use the no form to restore the default.
Syntax
authentication login {[local] [radius] [tacacs]}
no authentication login
- local - Use local password.
- radius - Use RADIUS server password.
- tacacs - Use TACACS server password.
Default Setting
Local
Command Mode
Global Configuration
Command Usage
• RADIUS uses UDP while TACACS+ uses TCP. UDP only offers best
effort delivery, while TCP offers a connection-oriented transport.
Also, note that RADIUS encrypts only the password in the
access-request packet from the client to the server, while TACACS+
encrypts the entire body of the packet.
• RADIUS and TACACS+ logon authentication assigns a specific
privilege level for each user name and password pair. The user name,
password, and privilege level must be configured on the authentication
server.
Authentication Sequence
Command Function Mod
e
Pag
e
authentication login Defines logon authentication method and
precedence
GC 4-97
authentication enable Defines the authentication method and
precedence for command mode change
GC 4-98