<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ip http server (with no authentication) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ip-http-server-with-no-authentication/m-p/1825190#M227528</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Kevin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that you are referring to the following bug:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsb59717"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsb59717&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;"Symptom:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may get into the switch via http without a username or password&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Start out with a blank config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Put an ip address on a vlan so that you can ping the 3750.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then enter the following commands and nothing else&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default local&lt;/P&gt;&lt;P&gt;aaa authorization exec default local&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At&amp;nbsp; this point you will be able to access the switch via http and modify&amp;nbsp; the config.&amp;nbsp; But, you will not be able to access it via telnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;STRONG&gt; Workaround:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure that you have a enable password on the box and /or the correct ip http auth command."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, we cannot trigger the above behavior anymore on newer IOS releases. A username/password or atleast "enable" password is needed on newer IOS versions in order to access the Switch GUI (HTTP) interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tested this on my lab with multiple variations on the configuration commands always getting a username/password prompt and not letting me in if leaving blank fields on the prompt.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 30 Dec 2011 20:00:58 GMT</pubDate>
    <dc:creator>camejia</dc:creator>
    <dc:date>2011-12-30T20:00:58Z</dc:date>
    <item>
      <title>ip http server (with no authentication)</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-http-server-with-no-authentication/m-p/1825189#M227510</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an interesting dilemma. I have a customer who used to own a 3750 with a older version of IOS. The switch he had used a three year old version of IOS which allowed him to browse to the switch IP and manage it via HTTP without entering a password at all. Now that he has a replacement switch with a new ver of IOS (since the previous switch died). We slapped the config on from the old switch but no matter what we do (understanding that new http aaa authentication commands were added) we cant get this thing to let him in without prompting him for a password. I understand this was an insecure config to begin with so I shouldn't be advocating using it in the first place, but this is what the customer wants.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically what I'm trying to figure out is are we banging our heads into the wall for nothing as the "ip http server" will not allow an authentication method of "none" anyway? None of the offical documentation I have read for the http aaa authentication cmds shows this as an example nor have I found any blog posts on how to do it ether. So is it even possible? Perhaps Cisco removed this by design.. does anyone know?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new model &lt;/P&gt;&lt;P&gt;aaa authentication login default local&lt;/P&gt;&lt;P&gt;aaa authentication enable default none&lt;/P&gt;&lt;P&gt;aaa authentication login none none&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;ip http authentication aaa login-authentication none&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IOS ver: c3750-ipbase-mz.122-50.SE5.bin&lt;/P&gt;&lt;P&gt;-----------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;I've also tried changing the config around (to no avail) to be:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default none&lt;/P&gt;&lt;P&gt;ip http authentication aaa login-authentication default&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks everyone.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:40:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-http-server-with-no-authentication/m-p/1825189#M227510</guid>
      <dc:creator>KEVIN DELANEY</dc:creator>
      <dc:date>2019-03-11T01:40:23Z</dc:date>
    </item>
    <item>
      <title>ip http server (with no authentication)</title>
      <link>https://community.cisco.com/t5/network-access-control/ip-http-server-with-no-authentication/m-p/1825190#M227528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Kevin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that you are referring to the following bug:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsb59717"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsb59717&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;"Symptom:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may get into the switch via http without a username or password&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Start out with a blank config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Put an ip address on a vlan so that you can ping the 3750.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then enter the following commands and nothing else&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default local&lt;/P&gt;&lt;P&gt;aaa authorization exec default local&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At&amp;nbsp; this point you will be able to access the switch via http and modify&amp;nbsp; the config.&amp;nbsp; But, you will not be able to access it via telnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;STRONG&gt; Workaround:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure that you have a enable password on the box and /or the correct ip http auth command."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, we cannot trigger the above behavior anymore on newer IOS releases. A username/password or atleast "enable" password is needed on newer IOS versions in order to access the Switch GUI (HTTP) interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tested this on my lab with multiple variations on the configuration commands always getting a username/password prompt and not letting me in if leaving blank fields on the prompt.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Dec 2011 20:00:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ip-http-server-with-no-authentication/m-p/1825190#M227528</guid>
      <dc:creator>camejia</dc:creator>
      <dc:date>2011-12-30T20:00:58Z</dc:date>
    </item>
  </channel>
</rss>

