<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic aaa authentication enable console issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-enable-console-issue/m-p/2078401#M188759</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Using TACACS+&lt;/P&gt;&lt;P&gt;No command authorization rules are being used&lt;/P&gt;&lt;P&gt;When I add the aaa authentication enable console xxxxxxxx LOCAL command,&lt;/P&gt;&lt;P&gt;and use login instead of enable, I get Login failed if I try to use my credentials.&lt;/P&gt;&lt;P&gt;However, if I use login with the locally configured username and password, it lets me in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the config (without the aaa authentication enable console command):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User Access Verification&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Username: xxx/xxxxxxxxxx&lt;/P&gt;&lt;P&gt;Password: ************&lt;/P&gt;&lt;P&gt;Type help or '?' for a list of available commands.&lt;/P&gt;&lt;P&gt;FW&amp;gt; en&lt;/P&gt;&lt;P&gt;Password: ********&lt;/P&gt;&lt;P&gt;FW# sh ru&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 8.2(5)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;terminal width 511&lt;/P&gt;&lt;P&gt;hostname xxxxxxxx&lt;/P&gt;&lt;P&gt;enable password *********** encrypted&lt;/P&gt;&lt;P&gt;passwd *********** encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan xxx&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; switchport access vlan xxx&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; switchport access vlan xxx&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlanxxx&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address x.x.x.x x.x.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlanxxx&lt;/P&gt;&lt;P&gt; nameif OUtside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address x.x.x.x x.x.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object-group protocol TCPUDP&lt;/P&gt;&lt;P&gt; protocol-object udp&lt;/P&gt;&lt;P&gt; protocol-object tcp&lt;/P&gt;&lt;P&gt;object-group protocol DM_INLINE_PROTOCOL_1&lt;/P&gt;&lt;P&gt; protocol-object udp&lt;/P&gt;&lt;P&gt; protocol-object tcp&lt;/P&gt;&lt;P&gt; group-object TCPUDP&lt;/P&gt;&lt;P&gt;object-group protocol DM_INLINE_PROTOCOL_2&lt;/P&gt;&lt;P&gt; protocol-object udp&lt;/P&gt;&lt;P&gt; protocol-object tcp&lt;/P&gt;&lt;P&gt; group-object TCPUDP&lt;/P&gt;&lt;P&gt;object-group protocol DM_INLINE_PROTOCOL_3&lt;/P&gt;&lt;P&gt; protocol-object ip&lt;/P&gt;&lt;P&gt; protocol-object udp&lt;/P&gt;&lt;P&gt; protocol-object tcp&lt;/P&gt;&lt;P&gt;object-group protocol DM_INLINE_PROTOCOL_4&lt;/P&gt;&lt;P&gt; protocol-object ip&lt;/P&gt;&lt;P&gt; protocol-object udp&lt;/P&gt;&lt;P&gt; protocol-object tcp&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit object-group DM_INLINE_PROTOCOL_1 a&lt;/P&gt;&lt;P&gt;ny any inactive&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit object-group DM_INLINE_PROTOCOL_4 a&lt;/P&gt;&lt;P&gt;ny any&lt;/P&gt;&lt;P&gt;access-list OUtside_access_in extended permit object-group DM_INLINE_PROTOCOL_1&lt;/P&gt;&lt;P&gt;any any inactive&lt;/P&gt;&lt;P&gt;access-list OUtside_access_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list OUtside_access_in extended permit object-group DM_INLINE_PROTOCOL_3&lt;/P&gt;&lt;P&gt;any any&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging host inside x.x.x.x&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu OUtside 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;access-group OUtside_access_in in interface OUtside&lt;/P&gt;&lt;P&gt;route inside 0.0.0.0 0.0.0.0 x.x.x.x 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;aaa-server xxxxxxxxx protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server xxxxxxxxx (inside) host x.x.x.x &lt;/P&gt;&lt;P&gt; key *****&lt;/P&gt;&lt;P&gt;aaa-server xxxxxxxxx (inside) host x.x.x.x&lt;/P&gt;&lt;P&gt; key *****&lt;/P&gt;&lt;P&gt;aaa-server xxxxxxxxx (inside) host x.x.x.x&lt;/P&gt;&lt;P&gt; key *****&lt;/P&gt;&lt;P&gt;aaa authentication http console ******* LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console ******* LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication telnet console ******* LOCAL&lt;/P&gt;&lt;P&gt;aaa local authentication attempts max-fail 5&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http x.x.x.x x.x.x.x inside&lt;/P&gt;&lt;P&gt;http x.x.x.x x.x.x.x inside&lt;/P&gt;&lt;P&gt;snmp-server host inside x.x.x.x community ***** version 2c&lt;/P&gt;&lt;P&gt;snmp-server host OUtside x.x.x.x community ***** version 2c&lt;/P&gt;&lt;P&gt;snmp-server host inside x.x.x.x community ***** version 2c&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community *****&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime seconds 28800&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;telnet x.x.x.x x.x.x.x inside&lt;/P&gt;&lt;P&gt;telnet x.x.x.x x.x.x.x inside&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd auto_config OUtside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;username ******* password ************** encrypted privilege 15&lt;/P&gt;&lt;P&gt;username ******* password ************** encrypted privilege 15&lt;/P&gt;&lt;P&gt;username ******* password ************** encrypted privilege 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;no call-home reporting anonymous&lt;/P&gt;&lt;P&gt;Cryptochecksum:&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;FW#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Nov 2012 06:49:50 GMT</pubDate>
    <dc:creator>josrankin</dc:creator>
    <dc:date>2012-11-08T06:49:50Z</dc:date>
    <item>
      <title>aaa authentication enable console issue</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-enable-console-issue/m-p/2078399#M188627</link>
      <description>&lt;P&gt;I have an ASA5505 running 8.2(5). It is configured with &lt;/P&gt;&lt;P&gt;aaa authentication telnet console xxxxxx LOCAL&lt;/P&gt;&lt;P&gt;and I am able to use my username and password to telnet in, but I then have to use the local enable password to get to privilege exec mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried configuring aaa authentication enable console xxxxxx LOCAL so that when I try to access privilege exec mode,I would be prompted for my password instead of the enable password, but it doesn't work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also tried removing the aaa authentication telnet console xxxxxx LOCAL and telenetted in with the local passwd.&lt;/P&gt;&lt;P&gt;I was prompted for a username and password when trying to get to priv exec mode, but again, the credentials did not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could there be something that needs to be changed on the ACS server to make this work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:45:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-enable-console-issue/m-p/2078399#M188627</guid>
      <dc:creator>josrankin</dc:creator>
      <dc:date>2019-03-11T02:45:16Z</dc:date>
    </item>
    <item>
      <title>aaa authentication enable console issue</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-enable-console-issue/m-p/2078400#M188717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What protocol are you using: Radius or TACACS+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you pusing any command authorization rules&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post a snip-it of your config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once you authenticate, have you tried to use "login" vs "enable"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating!&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2012 05:49:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-enable-console-issue/m-p/2078400#M188717</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2012-11-08T05:49:47Z</dc:date>
    </item>
    <item>
      <title>aaa authentication enable console issue</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-enable-console-issue/m-p/2078401#M188759</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Using TACACS+&lt;/P&gt;&lt;P&gt;No command authorization rules are being used&lt;/P&gt;&lt;P&gt;When I add the aaa authentication enable console xxxxxxxx LOCAL command,&lt;/P&gt;&lt;P&gt;and use login instead of enable, I get Login failed if I try to use my credentials.&lt;/P&gt;&lt;P&gt;However, if I use login with the locally configured username and password, it lets me in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the config (without the aaa authentication enable console command):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User Access Verification&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Username: xxx/xxxxxxxxxx&lt;/P&gt;&lt;P&gt;Password: ************&lt;/P&gt;&lt;P&gt;Type help or '?' for a list of available commands.&lt;/P&gt;&lt;P&gt;FW&amp;gt; en&lt;/P&gt;&lt;P&gt;Password: ********&lt;/P&gt;&lt;P&gt;FW# sh ru&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;ASA Version 8.2(5)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;terminal width 511&lt;/P&gt;&lt;P&gt;hostname xxxxxxxx&lt;/P&gt;&lt;P&gt;enable password *********** encrypted&lt;/P&gt;&lt;P&gt;passwd *********** encrypted&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt; switchport access vlan xxx&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; switchport access vlan xxx&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt; switchport access vlan xxx&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlanxxx&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address x.x.x.x x.x.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlanxxx&lt;/P&gt;&lt;P&gt; nameif OUtside&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address x.x.x.x x.x.x.x&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;object-group protocol TCPUDP&lt;/P&gt;&lt;P&gt; protocol-object udp&lt;/P&gt;&lt;P&gt; protocol-object tcp&lt;/P&gt;&lt;P&gt;object-group protocol DM_INLINE_PROTOCOL_1&lt;/P&gt;&lt;P&gt; protocol-object udp&lt;/P&gt;&lt;P&gt; protocol-object tcp&lt;/P&gt;&lt;P&gt; group-object TCPUDP&lt;/P&gt;&lt;P&gt;object-group protocol DM_INLINE_PROTOCOL_2&lt;/P&gt;&lt;P&gt; protocol-object udp&lt;/P&gt;&lt;P&gt; protocol-object tcp&lt;/P&gt;&lt;P&gt; group-object TCPUDP&lt;/P&gt;&lt;P&gt;object-group protocol DM_INLINE_PROTOCOL_3&lt;/P&gt;&lt;P&gt; protocol-object ip&lt;/P&gt;&lt;P&gt; protocol-object udp&lt;/P&gt;&lt;P&gt; protocol-object tcp&lt;/P&gt;&lt;P&gt;object-group protocol DM_INLINE_PROTOCOL_4&lt;/P&gt;&lt;P&gt; protocol-object ip&lt;/P&gt;&lt;P&gt; protocol-object udp&lt;/P&gt;&lt;P&gt; protocol-object tcp&lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit object-group DM_INLINE_PROTOCOL_1 a&lt;/P&gt;&lt;P&gt;ny any inactive&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit object-group DM_INLINE_PROTOCOL_4 a&lt;/P&gt;&lt;P&gt;ny any&lt;/P&gt;&lt;P&gt;access-list OUtside_access_in extended permit object-group DM_INLINE_PROTOCOL_1&lt;/P&gt;&lt;P&gt;any any inactive&lt;/P&gt;&lt;P&gt;access-list OUtside_access_in extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list OUtside_access_in extended permit object-group DM_INLINE_PROTOCOL_3&lt;/P&gt;&lt;P&gt;any any&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;logging host inside x.x.x.x&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu OUtside 1500&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;access-group OUtside_access_in in interface OUtside&lt;/P&gt;&lt;P&gt;route inside 0.0.0.0 0.0.0.0 x.x.x.x 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;&lt;P&gt;aaa-server xxxxxxxxx protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server xxxxxxxxx (inside) host x.x.x.x &lt;/P&gt;&lt;P&gt; key *****&lt;/P&gt;&lt;P&gt;aaa-server xxxxxxxxx (inside) host x.x.x.x&lt;/P&gt;&lt;P&gt; key *****&lt;/P&gt;&lt;P&gt;aaa-server xxxxxxxxx (inside) host x.x.x.x&lt;/P&gt;&lt;P&gt; key *****&lt;/P&gt;&lt;P&gt;aaa authentication http console ******* LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console ******* LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication telnet console ******* LOCAL&lt;/P&gt;&lt;P&gt;aaa local authentication attempts max-fail 5&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http x.x.x.x x.x.x.x inside&lt;/P&gt;&lt;P&gt;http x.x.x.x x.x.x.x inside&lt;/P&gt;&lt;P&gt;snmp-server host inside x.x.x.x community ***** version 2c&lt;/P&gt;&lt;P&gt;snmp-server host OUtside x.x.x.x community ***** version 2c&lt;/P&gt;&lt;P&gt;snmp-server host inside x.x.x.x community ***** version 2c&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community *****&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime seconds 28800&lt;/P&gt;&lt;P&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;/P&gt;&lt;P&gt;telnet x.x.x.x x.x.x.x inside&lt;/P&gt;&lt;P&gt;telnet x.x.x.x x.x.x.x inside&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcpd auto_config OUtside&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;no threat-detection statistics tcp-intercept&lt;/P&gt;&lt;P&gt;webvpn&lt;/P&gt;&lt;P&gt;username ******* password ************** encrypted privilege 15&lt;/P&gt;&lt;P&gt;username ******* password ************** encrypted privilege 15&lt;/P&gt;&lt;P&gt;username ******* password ************** encrypted privilege 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;prompt hostname context&lt;/P&gt;&lt;P&gt;no call-home reporting anonymous&lt;/P&gt;&lt;P&gt;Cryptochecksum:&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;FW#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2012 06:49:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-enable-console-issue/m-p/2078401#M188759</guid>
      <dc:creator>josrankin</dc:creator>
      <dc:date>2012-11-08T06:49:50Z</dc:date>
    </item>
    <item>
      <title>aaa authentication enable console issue</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-enable-console-issue/m-p/2078402#M188854</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK so since you are able to login with the TACACS credentials that means that you got the authentication peace done properly. Now since you are not able to get to the exec level then that means that the authorization part is not configured properly on either your ASA and/or ACS. A couple more questions:&lt;/P&gt;&lt;P&gt;1. What version of ACS are you using&lt;/P&gt;&lt;P&gt;2. Are you passing privilege level 15 profile from ACS&lt;/P&gt;&lt;P&gt;3. I am not that good with ASAs but I think you need to add some authorization commands to your ASA as well. Try:&lt;/P&gt;&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;aaa authorization command &lt;EM&gt;your_server_name/IP&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Calibri; font-size: 11pt;"&gt;aaa authorization exec authentication-server&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 10 Nov 2012 03:35:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-enable-console-issue/m-p/2078402#M188854</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2012-11-10T03:35:08Z</dc:date>
    </item>
  </channel>
</rss>

