Setting the Web Authentication Failover Sequence
You can specify a failover sequence for the RADIUS and local user database authentication methods. For example, you can configure Web Authentication to first use a local user database to authenticate users in a VLAN. If the local user database is not available, it will use a RADIUS server. Enter the following command.
device(config-vlan-10-webauth)# auth-mode username-password auth-methods local radius
You can specify radius local or local radius depending on the failover sequence desired.