User database and radius authentication at the same time

Greetings!

First time poster on this forum so be gentle :slight_smile:

Until now I’ve always found existing threads to andwer my questions, but this time I’ve failed…

Have a couple of CCR1016’s at different sites, and looking to set up client-site L2TP VPN for remote workers and support.
I want to allow the Windows support guys to manage VPN users through AD/Radius so planning to configure radius authentication, but concerned that if the radius server isn’t available for some reason that we won’t be able to connect to the VPN to resolve the issue.
Hoping that we can have a couple of local users as a fallback. Is it possible to use both radius and local user database at the same time?
If so, what is the authentication order - local then radius?