> Source: [sk185125](https://support.checkpoint.com/results/sk/sk185125)

# sk185125 - TACACS+ users cannot access Gaia administrative commands when TACACS+ and RADIUS are configured on the same system

| Property | Value |
|----------|-------|
| Solution ID | sk185125 |
| Date Created | 2026-07-16 |
| Last Modified | 2026-07-22 |
| Technical Level | Advanced |
| Products | Security Gateway, Scalable Platforms |
| Versions | R82.10, R82, R82.10, R82 |
| OS | Gaia |

## Symptoms

- * TACACS+ and RADIUS authentication servers are configured on the same Gaia system.

* SSH login using a TACACS+ user account fails, or the authenticated user cannot run Gaia or Check Point administrative commands.

* Authentication and command execution using a RADIUS-authenticated account succeed.

## Cause

When TACACS+ and RADIUS are configured simultaneously, Gaia resolves user authentication through RADIUS before TACACS+..  
In this scenario, TACACS+ user mapping to `UID 0` is not applied. The authenticated session is assigned `UID 96` (`_nonlocl`) instead.  
As a result, the user does not receive the required Gaia and Check Point administrative command paths and cannot perform administrative operations.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
