Skip to main content
PacketMentor logo
Open menu
← All lab tasks
Security Fundamentals Fix · Medium ~15 min · 3 devices · 5 tasks · CCNA v1.1 and v2.0

TACACS+ VTY login: fix AAA and the local fallback

R1 is a branch router. Admins must log in over SSH with their TACACS+ accounts, checked by the server TACSRV (10.0.99.10) that sits behind R2. If TACSRV stops answering, a local account on R1 must still let an admin in. The AAA setup is half done: the login list exists but no line uses it, the server entry points at the wrong address, R1 has no route to the server LAN and there is no local account to fall back to. The shared key TacKey99 is already correct. Logins here are simulated: the engine checks routing, the server address, the key and the method list, then answers the way IOS would.

R1 Gi0/0 10.0.12.1/30 to R2 Gi0/0 10.0.12.2/30
R2 Gi0/1 10.0.99.1/24 to TACSRV 10.0.99.10/24 (TACACS+ server, key TacKey99)
TACACS+ test account on TACSRV: netops, password Ops2026
Topology
R1R2TACSRV

Stuck on a lab, or not sure what to practice next?

Talk it through with a mentor on a free 20-minute call. We look at your lab, your exam date and your weak spots, and you leave with a plan.

Book a free session