<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA System Context AAA authentication enable in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/asa-system-context-aaa-authentication-enable/m-p/1848492#M193794</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that you are hitting the following known issue:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsw18455"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsw18455&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="5" cellspacing="2" style="width: 100%;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD colspan="2" style="font-size: 88%; padding: 8px;"&gt;&lt;STRONG&gt;admin context enable mode credentials compared to system context DB &lt;/STRONG&gt; &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="font-size: 88%; padding: 0px 8px 8px;" valign="top"&gt;&lt;BR /&gt; &lt;BR /&gt; &lt;STRONG&gt;Symptom:&lt;/STRONG&gt;&lt;BR /&gt; &lt;BR /&gt; In multi-mode configuration, user credentials for entering privileged mode &lt;BR /&gt;(enable mode) via serial console are not sent to external server for &lt;BR /&gt;authentication purpose.&lt;BR /&gt; &lt;BR /&gt; &lt;STRONG&gt;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;:&lt;/STRONG&gt;&lt;BR /&gt; &lt;BR /&gt; ASA/PIX is in multi-mode. serial console and enable console authentication &lt;BR /&gt;are configured to use external aaa server in admin context.&lt;BR /&gt; &lt;BR /&gt; &lt;STRONG&gt;Workaround:&lt;/STRONG&gt;&lt;BR /&gt; &lt;BR /&gt; Option 1: Configure enable password in system context.&lt;P&gt;&lt;/P&gt;Option 2: Avoid the use of the serial console interface and rely on telnet &lt;BR /&gt;or ssh console access.&amp;nbsp; From ssh or telnet consoles, attempts to enter &lt;BR /&gt;enabled mode will be authenticated as specified by the aaa configuration in &lt;BR /&gt;the "admin" context.&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BR /&gt; &lt;STRONG&gt;Further Problem Description:&lt;/STRONG&gt;&lt;BR /&gt; &lt;BR /&gt; When authentication is enabled for serial console and for enable console in &lt;BR /&gt;admin context via an external aaa server(eg: tacacs+ or radius), serial &lt;BR /&gt;console authentcation is done against external aaa server, but enable mode &lt;BR /&gt;credentials are compared against enable db in system context.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this clarifies it. Unfortunately there is no fix yet for this behavior.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Jan 2012 22:51:23 GMT</pubDate>
    <dc:creator>camejia</dc:creator>
    <dc:date>2012-01-16T22:51:23Z</dc:date>
    <item>
      <title>ASA System Context AAA authentication enable</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-system-context-aaa-authentication-enable/m-p/1848491#M193762</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have ASA configured in multi context mode, with software 8.4(2) configured for AAA&lt;/P&gt;&lt;P&gt;Configuration is admin context as follows:&lt;/P&gt;&lt;P&gt; aaa-server TAC protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TAC (management) host 10.162.2.201&lt;/P&gt;&lt;P&gt; key *****&lt;/P&gt;&lt;P&gt;aaa authentication enable console TAC LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication http console TAC LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication serial console TAC LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication ssh console TAC LOCAL &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Because of multiple context, after logging in we enter System context. Console port authentication is working fine except access to privileged mode while connecting over console port. &lt;/P&gt;&lt;P&gt;After issuing "enable" command ASA accepts only configured enable secret in system context and changes user ID to enable_15, so we are unable to do user-level command authorization and accounting.&lt;/P&gt;&lt;P&gt;It seems that ASA in system context is not aware of any AAA configuration, and there isn't any command to configure AAA in system context.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way to configure enable authentication over AAA in system context?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:43:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-system-context-aaa-authentication-enable/m-p/1848491#M193762</guid>
      <dc:creator>g-oliveira</dc:creator>
      <dc:date>2019-03-11T01:43:11Z</dc:date>
    </item>
    <item>
      <title>ASA System Context AAA authentication enable</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-system-context-aaa-authentication-enable/m-p/1848492#M193794</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that you are hitting the following known issue:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsw18455"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsw18455&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="5" cellspacing="2" style="width: 100%;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD colspan="2" style="font-size: 88%; padding: 8px;"&gt;&lt;STRONG&gt;admin context enable mode credentials compared to system context DB &lt;/STRONG&gt; &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="font-size: 88%; padding: 0px 8px 8px;" valign="top"&gt;&lt;BR /&gt; &lt;BR /&gt; &lt;STRONG&gt;Symptom:&lt;/STRONG&gt;&lt;BR /&gt; &lt;BR /&gt; In multi-mode configuration, user credentials for entering privileged mode &lt;BR /&gt;(enable mode) via serial console are not sent to external server for &lt;BR /&gt;authentication purpose.&lt;BR /&gt; &lt;BR /&gt; &lt;STRONG&gt;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;:&lt;/STRONG&gt;&lt;BR /&gt; &lt;BR /&gt; ASA/PIX is in multi-mode. serial console and enable console authentication &lt;BR /&gt;are configured to use external aaa server in admin context.&lt;BR /&gt; &lt;BR /&gt; &lt;STRONG&gt;Workaround:&lt;/STRONG&gt;&lt;BR /&gt; &lt;BR /&gt; Option 1: Configure enable password in system context.&lt;P&gt;&lt;/P&gt;Option 2: Avoid the use of the serial console interface and rely on telnet &lt;BR /&gt;or ssh console access.&amp;nbsp; From ssh or telnet consoles, attempts to enter &lt;BR /&gt;enabled mode will be authenticated as specified by the aaa configuration in &lt;BR /&gt;the "admin" context.&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BR /&gt; &lt;STRONG&gt;Further Problem Description:&lt;/STRONG&gt;&lt;BR /&gt; &lt;BR /&gt; When authentication is enabled for serial console and for enable console in &lt;BR /&gt;admin context via an external aaa server(eg: tacacs+ or radius), serial &lt;BR /&gt;console authentcation is done against external aaa server, but enable mode &lt;BR /&gt;credentials are compared against enable db in system context.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this clarifies it. Unfortunately there is no fix yet for this behavior.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jan 2012 22:51:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-system-context-aaa-authentication-enable/m-p/1848492#M193794</guid>
      <dc:creator>camejia</dc:creator>
      <dc:date>2012-01-16T22:51:23Z</dc:date>
    </item>
    <item>
      <title>ASA System Context AAA authentication enable</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-system-context-aaa-authentication-enable/m-p/1848493#M193853</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the info.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have used the refred workarround &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the info &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jan 2012 10:14:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-system-context-aaa-authentication-enable/m-p/1848493#M193853</guid>
      <dc:creator>g-oliveira</dc:creator>
      <dc:date>2012-01-17T10:14:40Z</dc:date>
    </item>
    <item>
      <title>ASA System Context AAA authentication enable</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-system-context-aaa-authentication-enable/m-p/1848494#M193879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am glad that the workaround worked for you. If you feel that the accurate answer was provided please mark the thread as answered for future reference for our Community members.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jan 2012 15:02:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-system-context-aaa-authentication-enable/m-p/1848494#M193879</guid>
      <dc:creator>camejia</dc:creator>
      <dc:date>2012-01-17T15:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA System Context AAA authentication enable</title>
      <link>https://community.cisco.com/t5/network-access-control/asa-system-context-aaa-authentication-enable/m-p/4296872#M565679</link>
      <description>&lt;P&gt;That link above is currently returning:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H1&gt;503 Service Unavailable&lt;/H1&gt;&lt;P&gt;&lt;SPAN&gt;No server is available to handle this request.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Updated URL: &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCsw18455" target="_blank" rel="noopener"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCsw18455&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wow it has been almost 10 years, and this hasn't been addressed and:&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;&amp;nbsp; &amp;nbsp;"No release planned to fix this bug"&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 12:43:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/asa-system-context-aaa-authentication-enable/m-p/4296872#M565679</guid>
      <dc:creator>BrianSekleckiGE</dc:creator>
      <dc:date>2021-02-24T12:43:34Z</dc:date>
    </item>
  </channel>
</rss>

