Telnet and SSH Prompts when the TACACS+ Server Is Unavailable

When TACACS+ is the first method in the authentication-method list, the device displays the login prompt received from the TACACS+ server. If a user attempts to login through Telnet or SSH, but none of the configured TACACS+ servers are available, the following rules apply:

  • If the next method in the authentication-method list is enable, the login prompt is skipped, and the user is prompted for the Enable password (that is, the password configured with the enable super-user-password command).
  • If the next method in the authentication-method list is line, the login prompt is skipped, and the user is prompted for the Line password (that is, the password configured with the enable telnet password command).