<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA and CNA? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-and-cna/m-p/1795344#M219304</link>
    <description>&lt;P&gt;I am trying to configure a 3750 switch for AAA?&amp;nbsp; Telnet and SSH work fine but CNA and HTTP is not working.&amp;nbsp; Both SSH and Telnet need to authenticate using RADIUS but CNA/HTTP needs to authenticate using a local account because the local administrator only uses the CNA for management and the admins in TACACS use CLI.&amp;nbsp; Here is what I have so far.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default local group tacacs+&lt;/P&gt;&lt;P&gt;aaa authentication login con line&lt;/P&gt;&lt;P&gt;aaa authentication login http_auth local enable&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;P&gt;aaa authorization exec default local group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization exec http_auth local&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default local group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 http_auth local&lt;/P&gt;&lt;P&gt;aaa authorization network default local group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting network default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;ip http authentication aaa login-authentication http_auth&lt;/P&gt;&lt;P&gt;ip http authentication aaa exec-authorization http_auth&lt;/P&gt;&lt;P&gt;ip http authentication aaa command-authorization 15 http_auth&lt;/P&gt;&lt;P&gt;tacacs-server host X.X.X.X&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;tacacs-server key 7 XXXXX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The debugs show the connection authenticating correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;170536: 48w1d: HTTP AAA Login-Authentication List name: http_auth&lt;/P&gt;&lt;P&gt;170537: 48w1d: HTTP AAA Exec-Authorization List name: http_auth&lt;/P&gt;&lt;P&gt;170538: 48w1d: AAA/BIND(000003FA): Bind i/f&lt;/P&gt;&lt;P&gt;170539: 48w1d: AAA/AUTHEN/LOGIN (000003FA): Pick method list 'http_auth'&lt;/P&gt;&lt;P&gt;170540: 48w1d: AAA/AUTHOR (0x3FA): Pick method list 'http_auth'&lt;/P&gt;&lt;P&gt;170541: 48w1d: HTTP: Priv level authorization success priv_level: 15&lt;/P&gt;&lt;P&gt;170542: 48w1d: HTTP: Priv level granted 15&lt;/P&gt;&lt;P&gt;170543: 48w1d: AAA/BIND(000003FB): Bind i/f&lt;/P&gt;&lt;P&gt;170544: 48w1d: HTTP AAA Login-Authentication List name: http_auth&lt;/P&gt;&lt;P&gt;170545: 48w1d: HTTP AAA Exec-Authorization List name: http_auth&lt;/P&gt;&lt;P&gt;170546: 48w1d: AAA/BIND(000003FC): Bind i/f&lt;/P&gt;&lt;P&gt;170547: 48w1d: AAA/AUTHEN/LOGIN (000003FC): Pick method list 'http_auth'&lt;/P&gt;&lt;P&gt;170548: 48w1d: AAA/AUTHOR (0x3FC): Pick method list 'http_auth'&lt;/P&gt;&lt;P&gt;170549: 48w1d: HTTP: Priv level authorization success priv_level: 15&lt;/P&gt;&lt;P&gt;170550: 48w1d: HTTP: Priv level granted 15&lt;/P&gt;&lt;P&gt;170551: 48w1d: AAA/BIND(000003FD): Bind i/f&lt;/P&gt;&lt;P&gt;170552: 48w1d: AAA: parse name=tty0 idb type=-1 tty=-1&lt;/P&gt;&lt;P&gt;170553: 48w1d: AAA: name=tty0 flags=0x11 type=4 shelf=0 slot=0 adapter=0 port=0 channel=0&lt;/P&gt;&lt;P&gt;170554: 48w1d: AAA/MEMORY: create_user (0x632D26C) user='granto-mark' ruser='Switch' ds0=0 port='tty0' rem_addr='async' authen_type=ASCII service=NONE priv=1 initial_task_id='0', vrf= (id=0)&lt;/P&gt;&lt;P&gt;170555: 48w1d: tty0 AAA/AUTHOR/CMD (1941738464): Port='tty0' list='' service=CMD&lt;/P&gt;&lt;P&gt;170556: 48w1d: AAA/AUTHOR/CMD: tty0 (1941738464) user='granto-mark'&lt;/P&gt;&lt;P&gt;170557: 48w1d: tty0 AAA/AUTHOR/CMD (1941738464): send AV service=shell&lt;/P&gt;&lt;P&gt;170558: 48w1d: tty0 AAA/AUTHOR/CMD (1941738464): send AV cmd=show&lt;/P&gt;&lt;P&gt;170559: 48w1d: tty0 AAA/AUTHOR/CMD (1941738464): send AV cmd-arg=version&lt;/P&gt;&lt;P&gt;170560: 48w1d: tty0 AAA/AUTHOR/CMD (1941738464): send AV cmd-arg=&amp;lt;cr&amp;gt;&lt;/P&gt;&lt;P&gt;170561: 48w1d: tty0 AAA/AUTHOR/CMD (1941738464): found list "default"&lt;/P&gt;&lt;P&gt;170562: 48w1d: tty0 AAA/AUTHOR/CMD (1941738464): Method=LOCAL&lt;/P&gt;&lt;P&gt;170563: 48w1d: AAA/AUTHOR (1941738464): Post authorization status = PASS_ADD&lt;/P&gt;&lt;P&gt;170564: 48w1d: AAA/MEMORY: free_user (0x632D26C) user='granto-mark' ruser='Switch' port='tty0' rem_addr='async' authen_type=ASCII service=NONE priv=1&lt;/P&gt;&lt;P&gt;170565: 48w1d: HTTP AAA Login-Authentication List name: http_auth&lt;/P&gt;&lt;P&gt;170566: 48w1d: HTTP AAA Exec-Authorization List name: http_auth&lt;/P&gt;&lt;P&gt;170567: 48w1d: AAA/BIND(000003FE): Bind i/f&lt;/P&gt;&lt;P&gt;170568: 48w1d: AAA/AUTHEN/LOGIN (000003FE): Pick method list 'http_auth'&lt;/P&gt;&lt;P&gt;170569: 48w1d: AAA/AUTHOR (0x3FE): Pick method list 'http_auth'&lt;/P&gt;&lt;P&gt;170570: 48w1d: HTTP: Priv level authorization success priv_level: 15&lt;/P&gt;&lt;P&gt;170571: 48w1d: HTTP: Priv level granted 15&lt;/P&gt;&lt;P&gt;170572: 48w1d: AAA/BIND(000003FF): Bind i/f&lt;/P&gt;&lt;P&gt;170573: 48w1d: HTTP AAA Login-Authentication List name: http_auth&lt;/P&gt;&lt;P&gt;170574: 48w1d: HTTP AAA Exec-Authorization List name: http_auth&lt;/P&gt;&lt;P&gt;170575: 48w1d: AAA/BIND(00000400): Bind i/f&lt;/P&gt;&lt;P&gt;170576: 48w1d: AAA/AUTHEN/LOGIN (00000400): Pick method list 'http_auth'&lt;/P&gt;&lt;P&gt;170577: 48w1d: AAA/AUTHOR (0x400): Pick method list 'http_auth'&lt;/P&gt;&lt;P&gt;170578: 48w1d: HTTP: Priv level authorization success priv_level: 15&lt;/P&gt;&lt;P&gt;170579: 48w1d: HTTP: Priv level granted 15&lt;/P&gt;&lt;P&gt;170580: 48w1d: AAA/BIND(00000401): Bind i/f&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appriciated.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Robert&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 01:21:38 GMT</pubDate>
    <dc:creator>robert_rhoads</dc:creator>
    <dc:date>2019-03-11T01:21:38Z</dc:date>
    <item>
      <title>AAA and CNA?</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-cna/m-p/1795344#M219304</link>
      <description>&lt;P&gt;I am trying to configure a 3750 switch for AAA?&amp;nbsp; Telnet and SSH work fine but CNA and HTTP is not working.&amp;nbsp; Both SSH and Telnet need to authenticate using RADIUS but CNA/HTTP needs to authenticate using a local account because the local administrator only uses the CNA for management and the admins in TACACS use CLI.&amp;nbsp; Here is what I have so far.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default local group tacacs+&lt;/P&gt;&lt;P&gt;aaa authentication login con line&lt;/P&gt;&lt;P&gt;aaa authentication login http_auth local enable&lt;/P&gt;&lt;P&gt;aaa authorization config-commands&lt;/P&gt;&lt;P&gt;aaa authorization exec default local group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization exec http_auth local&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default local group tacacs+&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 http_auth local&lt;/P&gt;&lt;P&gt;aaa authorization network default local group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting network default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;ip http authentication aaa login-authentication http_auth&lt;/P&gt;&lt;P&gt;ip http authentication aaa exec-authorization http_auth&lt;/P&gt;&lt;P&gt;ip http authentication aaa command-authorization 15 http_auth&lt;/P&gt;&lt;P&gt;tacacs-server host X.X.X.X&lt;/P&gt;&lt;P&gt;tacacs-server directed-request&lt;/P&gt;&lt;P&gt;tacacs-server key 7 XXXXX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The debugs show the connection authenticating correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;170536: 48w1d: HTTP AAA Login-Authentication List name: http_auth&lt;/P&gt;&lt;P&gt;170537: 48w1d: HTTP AAA Exec-Authorization List name: http_auth&lt;/P&gt;&lt;P&gt;170538: 48w1d: AAA/BIND(000003FA): Bind i/f&lt;/P&gt;&lt;P&gt;170539: 48w1d: AAA/AUTHEN/LOGIN (000003FA): Pick method list 'http_auth'&lt;/P&gt;&lt;P&gt;170540: 48w1d: AAA/AUTHOR (0x3FA): Pick method list 'http_auth'&lt;/P&gt;&lt;P&gt;170541: 48w1d: HTTP: Priv level authorization success priv_level: 15&lt;/P&gt;&lt;P&gt;170542: 48w1d: HTTP: Priv level granted 15&lt;/P&gt;&lt;P&gt;170543: 48w1d: AAA/BIND(000003FB): Bind i/f&lt;/P&gt;&lt;P&gt;170544: 48w1d: HTTP AAA Login-Authentication List name: http_auth&lt;/P&gt;&lt;P&gt;170545: 48w1d: HTTP AAA Exec-Authorization List name: http_auth&lt;/P&gt;&lt;P&gt;170546: 48w1d: AAA/BIND(000003FC): Bind i/f&lt;/P&gt;&lt;P&gt;170547: 48w1d: AAA/AUTHEN/LOGIN (000003FC): Pick method list 'http_auth'&lt;/P&gt;&lt;P&gt;170548: 48w1d: AAA/AUTHOR (0x3FC): Pick method list 'http_auth'&lt;/P&gt;&lt;P&gt;170549: 48w1d: HTTP: Priv level authorization success priv_level: 15&lt;/P&gt;&lt;P&gt;170550: 48w1d: HTTP: Priv level granted 15&lt;/P&gt;&lt;P&gt;170551: 48w1d: AAA/BIND(000003FD): Bind i/f&lt;/P&gt;&lt;P&gt;170552: 48w1d: AAA: parse name=tty0 idb type=-1 tty=-1&lt;/P&gt;&lt;P&gt;170553: 48w1d: AAA: name=tty0 flags=0x11 type=4 shelf=0 slot=0 adapter=0 port=0 channel=0&lt;/P&gt;&lt;P&gt;170554: 48w1d: AAA/MEMORY: create_user (0x632D26C) user='granto-mark' ruser='Switch' ds0=0 port='tty0' rem_addr='async' authen_type=ASCII service=NONE priv=1 initial_task_id='0', vrf= (id=0)&lt;/P&gt;&lt;P&gt;170555: 48w1d: tty0 AAA/AUTHOR/CMD (1941738464): Port='tty0' list='' service=CMD&lt;/P&gt;&lt;P&gt;170556: 48w1d: AAA/AUTHOR/CMD: tty0 (1941738464) user='granto-mark'&lt;/P&gt;&lt;P&gt;170557: 48w1d: tty0 AAA/AUTHOR/CMD (1941738464): send AV service=shell&lt;/P&gt;&lt;P&gt;170558: 48w1d: tty0 AAA/AUTHOR/CMD (1941738464): send AV cmd=show&lt;/P&gt;&lt;P&gt;170559: 48w1d: tty0 AAA/AUTHOR/CMD (1941738464): send AV cmd-arg=version&lt;/P&gt;&lt;P&gt;170560: 48w1d: tty0 AAA/AUTHOR/CMD (1941738464): send AV cmd-arg=&amp;lt;cr&amp;gt;&lt;/P&gt;&lt;P&gt;170561: 48w1d: tty0 AAA/AUTHOR/CMD (1941738464): found list "default"&lt;/P&gt;&lt;P&gt;170562: 48w1d: tty0 AAA/AUTHOR/CMD (1941738464): Method=LOCAL&lt;/P&gt;&lt;P&gt;170563: 48w1d: AAA/AUTHOR (1941738464): Post authorization status = PASS_ADD&lt;/P&gt;&lt;P&gt;170564: 48w1d: AAA/MEMORY: free_user (0x632D26C) user='granto-mark' ruser='Switch' port='tty0' rem_addr='async' authen_type=ASCII service=NONE priv=1&lt;/P&gt;&lt;P&gt;170565: 48w1d: HTTP AAA Login-Authentication List name: http_auth&lt;/P&gt;&lt;P&gt;170566: 48w1d: HTTP AAA Exec-Authorization List name: http_auth&lt;/P&gt;&lt;P&gt;170567: 48w1d: AAA/BIND(000003FE): Bind i/f&lt;/P&gt;&lt;P&gt;170568: 48w1d: AAA/AUTHEN/LOGIN (000003FE): Pick method list 'http_auth'&lt;/P&gt;&lt;P&gt;170569: 48w1d: AAA/AUTHOR (0x3FE): Pick method list 'http_auth'&lt;/P&gt;&lt;P&gt;170570: 48w1d: HTTP: Priv level authorization success priv_level: 15&lt;/P&gt;&lt;P&gt;170571: 48w1d: HTTP: Priv level granted 15&lt;/P&gt;&lt;P&gt;170572: 48w1d: AAA/BIND(000003FF): Bind i/f&lt;/P&gt;&lt;P&gt;170573: 48w1d: HTTP AAA Login-Authentication List name: http_auth&lt;/P&gt;&lt;P&gt;170574: 48w1d: HTTP AAA Exec-Authorization List name: http_auth&lt;/P&gt;&lt;P&gt;170575: 48w1d: AAA/BIND(00000400): Bind i/f&lt;/P&gt;&lt;P&gt;170576: 48w1d: AAA/AUTHEN/LOGIN (00000400): Pick method list 'http_auth'&lt;/P&gt;&lt;P&gt;170577: 48w1d: AAA/AUTHOR (0x400): Pick method list 'http_auth'&lt;/P&gt;&lt;P&gt;170578: 48w1d: HTTP: Priv level authorization success priv_level: 15&lt;/P&gt;&lt;P&gt;170579: 48w1d: HTTP: Priv level granted 15&lt;/P&gt;&lt;P&gt;170580: 48w1d: AAA/BIND(00000401): Bind i/f&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appriciated.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Robert&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:21:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-cna/m-p/1795344#M219304</guid>
      <dc:creator>robert_rhoads</dc:creator>
      <dc:date>2019-03-11T01:21:38Z</dc:date>
    </item>
    <item>
      <title>AAA and CNA?</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-cna/m-p/1795345#M219305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Upgrading the 3750's to c3750-ipservicesk9-mz.122-55.SE3 fixed the problem.&amp;nbsp; The configuration above is the one that is working.&amp;nbsp; Now my problem is that everythign was working but I upgraded my 2960's to c2960-lanbasek9-mz.122-58.SE2 to keep them at the same version as me 3750's and the authentication is broken.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Sep 2011 14:55:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-cna/m-p/1795345#M219305</guid>
      <dc:creator>robert_rhoads</dc:creator>
      <dc:date>2011-09-02T14:55:29Z</dc:date>
    </item>
    <item>
      <title>AAA and CNA?</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-cna/m-p/1795346#M219306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good day.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you made any progress? I currently have an issue similar to yours with the IOS upgrade. Please see the link below to my discussion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/message/3562335#3562335"&gt;https://supportforums.cisco.com/message/3562335#3562335&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Feb 2012 16:05:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-cna/m-p/1795346#M219306</guid>
      <dc:creator>ACOA-CISCO</dc:creator>
      <dc:date>2012-02-20T16:05:55Z</dc:date>
    </item>
  </channel>
</rss>

