Configure AAA on both switches using RADIUS. See Example 4-35.
Configure EXEC authorization using RADIUS.
Configure Network entries on ACS for Switch1 IP 172.16.3.10 and Switch2 IP 172.16.4.20 with key cisco. This is because Switch1 has a VLAN3 interface and all AAA requests will be sourced using the VLAN3 interface IP address. This is not the case in Switch2, since it has only one VLAN interface—the Management VLAN4 with IP address 172.16.4.20 See Figure 4-7 for ACS configuration.
Configure the AAA fallback method to local and configure a local username on both switches.