<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic aaa authorization console in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-console/m-p/2206692#M127028</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have the following config :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login NO_LOGIN none&lt;/P&gt;&lt;P&gt;aaa authentication login ADMINS group radius local&lt;/P&gt;&lt;P&gt;aaa authentication login CONSOLE group radius local&lt;/P&gt;&lt;P&gt;aaa authorization exec NO_AUTHOR none&lt;/P&gt;&lt;P&gt;aaa authorization exec ADMINS group radius local&lt;/P&gt;&lt;P&gt;aaa authorization exec CONSOLE group radius local&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;enable secret cisco&lt;/P&gt;&lt;P&gt;username cisco privilage 15 secret cisco&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt; password 7 05080F1C2243&lt;/P&gt;&lt;P&gt; authorization exec CONSOLE&lt;/P&gt;&lt;P&gt; login authentication CONSOLE&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; password 7 045802150C2E0C&lt;/P&gt;&lt;P&gt; authorization exec ADMINS&lt;/P&gt;&lt;P&gt; logging synchronous&lt;/P&gt;&lt;P&gt; login authentication ADMINS&lt;/P&gt;&lt;P&gt;line vty 5 15&lt;/P&gt;&lt;P&gt; password 7 060506324F41&lt;/P&gt;&lt;P&gt; authorization exec ADMINS&lt;/P&gt;&lt;P&gt; logging synchronous&lt;/P&gt;&lt;P&gt; login authentication ADMINS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i am tryin gto login to the switch from vty line i come directly to privillage mode, but when loging to console port i come to the exec mode (privilage 1) and i cant go further to the user privillage mode . each time i have to type a password (i type the enable one) and my access is denied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when issuing the command # &lt;SPAN style="font-size: 10pt;"&gt;aaa authorization console&amp;nbsp;&amp;nbsp; (using telnet from other switch)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;the problem is solved.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Can someone please explain why is this happening? i think after logging in with local account (with privillage 15) from console port i should get directly to privilage mode, or am i wrong ?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 03:27:03 GMT</pubDate>
    <dc:creator>mhawas</dc:creator>
    <dc:date>2019-03-11T03:27:03Z</dc:date>
    <item>
      <title>aaa authorization console</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-console/m-p/2206692#M127028</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have the following config :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login NO_LOGIN none&lt;/P&gt;&lt;P&gt;aaa authentication login ADMINS group radius local&lt;/P&gt;&lt;P&gt;aaa authentication login CONSOLE group radius local&lt;/P&gt;&lt;P&gt;aaa authorization exec NO_AUTHOR none&lt;/P&gt;&lt;P&gt;aaa authorization exec ADMINS group radius local&lt;/P&gt;&lt;P&gt;aaa authorization exec CONSOLE group radius local&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;enable secret cisco&lt;/P&gt;&lt;P&gt;username cisco privilage 15 secret cisco&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt; password 7 05080F1C2243&lt;/P&gt;&lt;P&gt; authorization exec CONSOLE&lt;/P&gt;&lt;P&gt; login authentication CONSOLE&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; password 7 045802150C2E0C&lt;/P&gt;&lt;P&gt; authorization exec ADMINS&lt;/P&gt;&lt;P&gt; logging synchronous&lt;/P&gt;&lt;P&gt; login authentication ADMINS&lt;/P&gt;&lt;P&gt;line vty 5 15&lt;/P&gt;&lt;P&gt; password 7 060506324F41&lt;/P&gt;&lt;P&gt; authorization exec ADMINS&lt;/P&gt;&lt;P&gt; logging synchronous&lt;/P&gt;&lt;P&gt; login authentication ADMINS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i am tryin gto login to the switch from vty line i come directly to privillage mode, but when loging to console port i come to the exec mode (privilage 1) and i cant go further to the user privillage mode . each time i have to type a password (i type the enable one) and my access is denied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when issuing the command # &lt;SPAN style="font-size: 10pt;"&gt;aaa authorization console&amp;nbsp;&amp;nbsp; (using telnet from other switch)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;the problem is solved.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Can someone please explain why is this happening? i think after logging in with local account (with privillage 15) from console port i should get directly to privilage mode, or am i wrong ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:27:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization-console/m-p/2206692#M127028</guid>
      <dc:creator>mhawas</dc:creator>
      <dc:date>2019-03-11T03:27:03Z</dc:date>
    </item>
    <item>
      <title>aaa authorization console</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-console/m-p/2206693#M127032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are a couple of parts to this explanation.&lt;/P&gt;&lt;P&gt;First thing is to understand that going directly into privilege mode is dependent on authorization granting that.&lt;/P&gt;&lt;P&gt;Second thing to understand is that by default Cisco does not perform authorization for sessions on the console. The reason for that is to provide some protection against the situation where authorization is mis-configured and you could get locked out from executing commands on the IOS device. If you want authorization to be performed on console sessions then you must manually configure aaa authorization console.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jun 2013 01:07:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization-console/m-p/2206693#M127032</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2013-06-07T01:07:49Z</dc:date>
    </item>
    <item>
      <title>aaa authorization console</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authorization-console/m-p/2206694#M127036</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;aaa authorization console is a hidden command. We have to execute this command to enable authorization for console line. If you create a method list &lt;STRONG&gt;"aaa authorization exec CONSOLE group radius local"&lt;/STRONG&gt; for console and try to apply it on line console 0, it will throw an error that without &lt;STRONG&gt;"aaa authorization console"&lt;/STRONG&gt; all authorization commands for console is useless. You have to first enable authorization for console with the help of aaa authorization console.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;command refrence&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/ios/12_2/security/command/reference/srfauth.html#wp1024046"&gt;http://www.cisco.com/en/US/docs/ios/12_2/security/command/reference/srfauth.html#wp1024046&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; - Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Jun 2013 06:41:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authorization-console/m-p/2206694#M127036</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-06-07T06:41:21Z</dc:date>
    </item>
  </channel>
</rss>

