<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tacacs and local users AAA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112543#M177808</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. i have change the TACACS group to TACACS-SRV and it works fine but still not in exec mode (enable mode)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. i try to configure "login local" under "line con 0" but it shows:&lt;/P&gt;&lt;P&gt;AAA: Warning authentication list "local" is not defined for LOGIN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i wanted him to use the "Cisco" user under login local but it didnt help..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what does it means?&lt;/P&gt;&lt;P&gt;3. in the config command: &lt;STRONG style="border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;ip tacacs source-interface Vlan2.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what does it means?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 16 Dec 2012 14:57:48 GMT</pubDate>
    <dc:creator>bendali10</dc:creator>
    <dc:date>2012-12-16T14:57:48Z</dc:date>
    <item>
      <title>Tacacs and local users AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112541#M177806</link>
      <description>&lt;P&gt;hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have many types of cisco devices such as:&lt;/P&gt;&lt;P&gt;* catalyst's switches (2960, 3560, 2950,4500 chassis, etc... )&lt;/P&gt;&lt;P&gt;* Nexus 5548.&lt;/P&gt;&lt;P&gt;* Nexus 7000.&lt;/P&gt;&lt;P&gt;* Nexus 4K.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have configure a tacas server and it works fine.&lt;/P&gt;&lt;P&gt;but i have many problems:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. when i login with a tacacs user it logs me in without exec mode (enable mode).&lt;/P&gt;&lt;P&gt;2. i want to be able to login via console with a local username and password (even when the tacacs server is alive).&lt;/P&gt;&lt;P&gt;3. for now i have configured only the Catalyst's Switches. but i dont know the proper commands to the Nexus OS's (5k, 7k, i understand that the configuration between the nexus models is different..)...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am testing all the environment with a "test switch" (Catalyst 2960) my current configuration is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;aaa new-model&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;aaa authentication login default group tacacs+ local&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;aaa authentication enable default group tacacs+ enable&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;aaa authorization console&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;aaa authorization exec default group tacacs+ local &lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;aaa authorization commands 15 default group tacacs+ local &lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;aaa accounting exec default start-stop group tacacs+&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;aaa accounting connection default start-stop group tacacs+&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;aaa session-id common&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;ip default-gateway 1.1.1.1&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;ip http server&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;ip http secure-server&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;tacacs-server host 1.1.1.2&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;tacacs-server key 7 1427171F09161A2E2A08&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;tacacs server TACACS-SRV&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;line con 0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;line vty 0 4&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt; transport input ssh&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;line vty 5 15&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: helvetica;"&gt;&lt;EM&gt;end&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:53:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112541#M177806</guid>
      <dc:creator>bendali10</dc:creator>
      <dc:date>2019-03-11T02:53:52Z</dc:date>
    </item>
    <item>
      <title>Tacacs and local users AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112542#M177807</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bendali,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try below modifcations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. when i login with a tacacs user it logs me in without exec mode (enable mode).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought your existing configuration would have taken you to enable mode. Since it is not try reconfiguring the aaa as below to go tor enable mode&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: helvetica;"&gt;no &lt;EM style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: helvetica;"&gt;aaa authentication login default group tacacs+ local&lt;/EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: helvetica;"&gt;&lt;EM style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: helvetica;"&gt;&lt;EM style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: helvetica;"&gt;aaa authentication login TACACS group tacacs+ local&lt;/EM&gt;&lt;BR /&gt;&lt;/EM&gt;line vty 0 4&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;login authentication TACACS&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: helvetica;"&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;2. I want to be able to login via console with a local username and password (even when the tacacs server is alive)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To use local console login modify configuration as below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;username Cisco priv 15 password Cisco&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;line console 0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;login local&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. for now i have configured only the Catalyst's Switches. but i dont know the proper commands to the Nexus OS's &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A typical confogiration for Nexus 7k looks as below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;STRONG&gt;aaa group server tacacs+ AAA-Server&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;aaa authentication login default group AAA-Server&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;STRONG&gt;feature tacacs+&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;ip tacacs source-interface Vlan2&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;tacacs-server host [ip address] key 7 "TEST"&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;aaa group server tacacs+ TacServer&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; server [ip address]&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; use-vrf &lt;VRF&gt;&lt;/VRF&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;aaa authentication login default group TacServer&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;tacacs-server directed-request&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Najaf&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Please rate when applicable or helpful !!!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Dec 2012 14:28:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112542#M177807</guid>
      <dc:creator>kcnajaf</dc:creator>
      <dc:date>2012-12-16T14:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs and local users AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112543#M177808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1. i have change the TACACS group to TACACS-SRV and it works fine but still not in exec mode (enable mode)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. i try to configure "login local" under "line con 0" but it shows:&lt;/P&gt;&lt;P&gt;AAA: Warning authentication list "local" is not defined for LOGIN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i wanted him to use the "Cisco" user under login local but it didnt help..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what does it means?&lt;/P&gt;&lt;P&gt;3. in the config command: &lt;STRONG style="border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;ip tacacs source-interface Vlan2.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what does it means?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Dec 2012 14:57:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112543#M177808</guid>
      <dc:creator>bendali10</dc:creator>
      <dc:date>2012-12-16T14:57:48Z</dc:date>
    </item>
    <item>
      <title>Tacacs and local users AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112544#M177809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which version of IOS you are running. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Try adding another line as below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: helvetica;"&gt;aaa authentication login TACACS group tacacs+ local&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;&lt;EM style="background-color: #ffffff; border-collapse: collapse; list-style: none; font-family: helvetica;"&gt;no &lt;EM style="border-collapse: collapse; list-style: none;"&gt;aaa authentication login default group tacacs+ local&lt;/EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;&lt;EM style="background-color: #ffffff; border-collapse: collapse; list-style: none; font-family: helvetica;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;aaa authentication login TACACS group tacacs+ local&lt;/EM&gt;&lt;BR /&gt;&lt;/EM&gt;line vty 0 4&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;login authentication TACACS&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope you are configuring this in the same line order.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Try modifying config as below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: helvetica;"&gt;aaa authentication login&lt;/EM&gt; no_tacacs local&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;line con 0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;login authentication no_tacacs&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) This command ensures the tacacs request is orginated from vlan 2 in this case. For your configuration you will have find the right interface and put in there instead of vlan 2. Please be aware that what ever interface ip address which you are using here should be added as aaa client on the ACS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Najaf &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Dec 2012 15:51:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112544#M177809</guid>
      <dc:creator>kcnajaf</dc:creator>
      <dc:date>2012-12-16T15:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs and local users AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112545#M177810</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i am running IOS 15.0(2)SE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. yes i am posting that in the same order.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; when i try to add "no aaa authentication login default group tacacs+ local" it shows me:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Authentication method list update failed!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. when i try " &lt;STRONG style="background-color: #f7fafb; border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;login authentication no_tacacs&lt;/STRONG&gt;" &lt;/P&gt;&lt;P&gt;it shows me: &lt;/P&gt;&lt;P&gt;AAA: Warning authentication list "no_tacas" is not defined for LOGIN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. thanks for the verification.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ben&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Dec 2012 15:59:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112545#M177810</guid>
      <dc:creator>bendali10</dc:creator>
      <dc:date>2012-12-16T15:59:15Z</dc:date>
    </item>
    <item>
      <title>Tacacs and local users AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112546#M177812</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ben,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would request to wipe all aaa configuration (use&lt;STRONG&gt; no aaa new-model&lt;/STRONG&gt;) and apply one by one in below order.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;username Cisco priv 15 password Cisco&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa new-model&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;STRONG style="font-family: Arial, verdana, sans-serif; font-size: 12px; border-collapse: collapse; list-style: none;"&gt;&lt;EM style="background-color: #ffffff; border-collapse: collapse; list-style: none; font-family: helvetica;"&gt;&lt;STRONG style="background-color: #f7fafb; border-collapse: collapse; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;EM style="background-color: #ffffff; border-collapse: collapse; list-style: none; font-family: helvetica;"&gt;aaa authentication login&lt;/EM&gt; no_tacacs local&lt;/STRONG&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;&lt;EM style="background-color: #ffffff; border-collapse: collapse; list-style: none; font-family: helvetica;"&gt;aaa authentication login TACACS group tacacs+ local&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;&lt;EM style="background-color: #ffffff; border-collapse: collapse; list-style: none; font-family: helvetica;"&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;line con 0&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;login authentication no_tacacs&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;&lt;EM style="background-color: #ffffff; border-collapse: collapse; list-style: none; font-family: helvetica;"&gt;&lt;EM style="border-collapse: collapse; list-style: none;"&gt;&lt;BR /&gt;&lt;/EM&gt;line vty 0 4&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 11.818181991577148px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;STRONG style="border-collapse: collapse; list-style: none;"&gt;login authentication TACACS&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how is goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Najaf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 16 Dec 2012 16:37:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112546#M177812</guid>
      <dc:creator>kcnajaf</dc:creator>
      <dc:date>2012-12-16T16:37:42Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs and local users AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112547#M177814</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Najaf.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sorry for the Deelay.i was OOO (out of office).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ok so i did what you posted and it works. i am able to login with local user thru CONSOLE and i am able to login thru SSH with a tacacs user..but i have some questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. when i loggen in ith a local or a tacas user i'm still not in exec mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. before i configure those commands when i login with a tacacs user the "enable" password was the tacacs user password. and right now the enable password is the "local enable secret".why?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. i created in the tacacs server two user groups with a different permissions and when i am logged in with one of the both group users they have the same permissions (before this config i tested it and there was a difference between the users that are member of two different groups in the tacacs server...).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4. what happends to the accounting on the tacacs server? because in this config i dont have any configuration about "aaa accounting"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ben&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Dec 2012 13:27:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112547#M177814</guid>
      <dc:creator>bendali10</dc:creator>
      <dc:date>2012-12-18T13:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs and local users AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112548#M177816</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Ben,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didnt notice your reply. Sorry for that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For point 1 could you please provide full aaa configuration currently you are using.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For point 2 you could additional command which will enable you to use your tacacs password from ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;﻿aaa authentication enable default tacacs+ enable&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;For point 3 im not sure why this is happening? What access permission you have restricted between users of both groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For point 4 you need to enable "aaa accouting"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Najaf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Dec 2012 09:48:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112548#M177816</guid>
      <dc:creator>kcnajaf</dc:creator>
      <dc:date>2012-12-24T09:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs and local users AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112549#M177817</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Najaf.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. I configured all what you recommended. But I will insert all my current configuration in the bottom of this post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. I configured the “&lt;STRONG&gt;&lt;EM&gt;aaa authentication enable default tacacs+ enable” &lt;/EM&gt;&lt;/STRONG&gt;and it works fine and use the user password to switch to “enable mode”. But when I login with the Cisco user via CONSOLE it doesn’t let me to use the local enable secret.it shows me “User does not belong to specified group”.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. I have created 2 groups in the tacacs server:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;UL&gt;&lt;LI&gt;Cisco admin group&lt;/LI&gt;&lt;LI&gt;Cisco RO group (RO=read only)&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 36.0pt;"&gt;The “cisco admin group”&amp;nbsp; - have the highest level permissions and can execute every command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 36.0pt;"&gt;The cisco RO group – can switch to “enable mode” and from “enable mode” to disable mode”. He also can run all the “show” commands but cant execute any other command such as “reload”,&amp;nbsp; “dir”, “wr” etc…&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 36.0pt;"&gt;I have tested it and it was working before I configure the last commande you recommended.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4. Thanks. I will configure the accounting according to the authentication methods.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;STRONG style="text-decoration: underline;"&gt;My current config is:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;Current configuration : 1989 bytes&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;version 15.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;no service pad&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;service timestamps debug datetime msec&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;service timestamps log datetime msec&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;service password-encryption&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;hostname tacacs_Switch&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;boot-start-marker&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;boot-end-marker&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;enable secret 4 lkdsjfklfjsdlkfjs4823748!@#$@#498fhsflkjfs&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;username admin privilege 15 password 7 XXXXXXXXXXXXXXXXX&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;username Cisco privilege 15 password 7 XXXXXXXXXXXXX&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;aaa new-model&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;aaa authentication login no_dce-mgmt00 local&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;aaa authentication login dce-mgmt00 group tacacs+ local&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;aaa session-id common&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;system mtu routing 1500&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;no ip domain-lookup&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;ip domain-name test.local&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;spanning-tree mode pvst&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;spanning-tree extend system-id&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;vlan internal allocation policy ascending&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;ip ssh rsa keypair-name sshkeys&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/1&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/2&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/3&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/4&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/5&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/6&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/7&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/8&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/9&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/10&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/11&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/12&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/13&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/14&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/15&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/16&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/17&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/18&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/19&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/20&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/21&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/22&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/23&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface FastEthernet0/24&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface GigabitEthernet0/1&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt; description upplink to HP switch&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface GigabitEthernet0/2&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;interface Vlan1&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt; description tacacs ip switch ip&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt; ip address 1.1.1.10 255.255.255.0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;ip default-gateway 1.1.1.1&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;ip http server&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;ip http secure-server&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;tacacs server dce-mgmt00&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt; address ipv4 1.1.1.2&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt; key 7 0034161201493B030101&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;line con 0&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt; login authentication no_dce-mgmt00&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;line vty 0 4&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt; login authentication dce-mgmt00&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt; transport input ssh&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;line vty 5 15&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;!&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;&lt;EM&gt;end&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-left: 18.0pt;"&gt;" &lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Dec 2012 12:54:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112549#M177817</guid>
      <dc:creator>bendali10</dc:creator>
      <dc:date>2012-12-24T12:54:55Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs and local users AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112550#M177818</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ben,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the console access you have to use the username and password associated with the username Cisco if you are trying to autheticate using that credentials. If you try to use the enable secret it will not work. You have configured the Cisco username as privellage level 15 and hence this will not ask you enable password when you try to login to console since this username already have level 15 privellage.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For point 3 could be brief which command are you refering here? "I have tested it and it was working before I configure the last commande you recommended"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please try after removing this command and see if that works as expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Najaf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Dec 2012 14:24:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112550#M177818</guid>
      <dc:creator>kcnajaf</dc:creator>
      <dc:date>2012-12-24T14:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs and local users AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112551#M177819</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;Unfortunately when i login thru CONSOLE with the user "Cisco" it still logs mm in "disabled mode" and to switch to exec mode i must use the "enable password" even that i configured the Cisco user to privilege 15.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;for point 3. i tested two users on the switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;each user is a member of a different group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;user A1 is member of "cisco admin group" and user B2 is member of "cisco RO group".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt;"&gt;before i configured the following commands you recommended I was not able to run the “reload” command with the user B2 (and that’s was good because these are one of the restrictions of the group).but after I configured these commands he can run the “reload” or any command that should be restricted to this users because he is a member of “cisco RO group” (in the tacacs server).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt; background: #F7FAFB;"&gt;&lt;STRONG&gt;username Cisco priv 15 password Cisco&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt; background-color: #f7fafb;"&gt;&lt;STRONG&gt;aaa new-model&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt; background-color: #f7fafb;"&gt;&lt;EM&gt;&lt;STRONG&gt;aaa authentication login&lt;/STRONG&gt;&lt;/EM&gt;&lt;STRONG&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&lt;EM&gt;no_tacacs local&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt; background-color: #f7fafb;"&gt;&lt;EM&gt;&lt;STRONG&gt;aaa authentication login TACACS group tacacs+ local&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt; background-color: #f7fafb;"&gt;&lt;STRONG&gt;line con 0&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt; background-color: #f7fafb;"&gt;&lt;STRONG&gt;login authentication no_tacacs&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt; background-color: #f7fafb;"&gt;&lt;STRONG&gt;&lt;EM&gt; &lt;EM&gt;line vty 0 4&lt;/EM&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin: 0cm 0cm 0.0001pt; background-color: #f7fafb;"&gt;&lt;STRONG&gt;login authentication TACACS&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;only user that is a member of “cisco admin groups” should have the permissions to run any commands and not users from “cisco RO groups”.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Dec 2012 14:43:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112551#M177819</guid>
      <dc:creator>bendali10</dc:creator>
      <dc:date>2012-12-24T14:43:39Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs and local users AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112552#M177820</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ben,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For point 1 which version of IOS you are running? This should work as expectedand not sure why this is not working for you. Also i'm not sure what you meant here by "it still logs mm in "disabled mode"".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For point 3 you could try setting authetrization with below commands.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa authorization exec default group tacacs+ local&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;aaa authorization commands 15 default group tacacs+ local&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Najaf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Dec 2012 02:56:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112552#M177820</guid>
      <dc:creator>kcnajaf</dc:creator>
      <dc:date>2012-12-25T02:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: Tacacs and local users AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112553#M177821</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;my switch version:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Switch Ports Model&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SW Version&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SW Image&lt;/P&gt;&lt;P&gt;------ ----- -----&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ----------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ----------&lt;/P&gt;&lt;P&gt;*&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 26&amp;nbsp;&amp;nbsp;&amp;nbsp; WS-C2960-24TT-L&amp;nbsp;&amp;nbsp;&amp;nbsp; 15.0(2)SE&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; C2960-LANBASEK9-M&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for point 3 i tried to run the last commands but it didnt reach our goal..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ben&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Dec 2012 14:06:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112553#M177821</guid>
      <dc:creator>bendali10</dc:creator>
      <dc:date>2012-12-26T14:06:18Z</dc:date>
    </item>
    <item>
      <title>Tacacs and local users AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112554#M177822</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On the tacacs server (if youre running in linux anyway) you need to set privilege 15 for the admin group or user you have configured. Here is a snippet of my configuration for example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; group = lv15 {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; default service = permit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; service = shell {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; default command = permit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; default attribute = permit&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; set priv-lvl = 15&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here you can see that it specifically sets ANY USER WHO MATCHES THIS GROUP to privilege level 15. This ties into an LDAP backend where users are added to the group that they need to be in.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Mar 2013 19:11:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/tacacs-and-local-users-aaa/m-p/2112554#M177822</guid>
      <dc:creator>Andre Toms</dc:creator>
      <dc:date>2013-03-20T19:11:32Z</dc:date>
    </item>
  </channel>
</rss>

