![](/images/new-backgrounds/1121221/121221237x1.webp)
Figure 5-3. RADIUS Servers in a Network
When a user attempts to log in, the switch prompts for a username and password. The switch then attempts to communicate with the primary RADIUS server at 10.10.10.10. Upon successful connection with the server, the login credentials are exchanged over an encrypted channel. The server grants or denies access, which the switch honors, and either allows or does not allow the user to access the switch. If neither of the two servers can be contacted, the switch searches its local user database for the user.
console(config)#aaa authentication login radiusList radius local console(config)#aaa authentication dot1x default radius
Device Security