Manage External Authentication
From 12.1 onwards, SVO supports RADIUS and TACACS modes of external authentication. Ensure that you enable and use either RADIUS or TACACS authentication method. You can add a maximum of up to ten servers for each of RADIUS or TACACS on SVO.
There should be at least one RADIUS or TACACS authentication server that is configured for authentication to be enabled. In order to delete the last RADIUS or TACACS server, you must disable the external authentication first, and then delete the RADIUS or TACACS server.
When your login to SVO with the external authentication enabled, SVO first tries with the configured list of servers. If external authentication servers are not reachable, then SVO uses local authentication provided the local authentication is enabled on SVO.
To manage SVO, the following users are created:
-
Local users (local authentication)—Specifies users who are created to manage SVO instances.
-
External users (external authentication)—Specifies users who are created on the external authentication servers.
For more information related to users, see External Authentication Users for SVO.
The following table lists some external authentication scenarios that describe some possible authentication errors, causes, and actions.
External and Local Authentication Combination |
Possible Authentication Scenario |
Possible Cause |
Action to be Taken |
---|---|---|---|
|
Server denies authentication |
External username or password is incorrect |
Enter the correct username and password to log in to the system |
Server not reachable |
IP address, shared secret or port number is not configured correctly although username or password could be correct |
You are locked out of the system. Ensure that you have configured correct IP address, shared secret, and port number |
|
|
Server denies authentication (although location authentication is enabled) |
External username or password is incorrect |
Enter the correct username and password to log in to the system Local authentication only works when the RADIUS or TACACS external servers are not reacheable |
Server not reachable (Local authentication is enabled) |
IP address, shared secret, port number is not configured correctly although username or password could be correct |
Use local authentication credentials to log in to SVO |