<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Use aaa for enable prompt? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/use-aaa-for-enable-prompt/m-p/1801592#M228624</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I show my aaa configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default local&lt;/P&gt;&lt;P&gt;aaa authorization console&lt;/P&gt;&lt;P&gt;aaa authorization exec default local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After, i try to enter your command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;privilege exec level 15 enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it doesnt work! Indeed, after my connection, i enter this command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show privilege&lt;/P&gt;&lt;P&gt;Current privilege level is 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whereas in my configuraiton my user is level 15... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Sep 2011 07:53:56 GMT</pubDate>
    <dc:creator>DynDarako</dc:creator>
    <dc:date>2011-09-29T07:53:56Z</dc:date>
    <item>
      <title>Use aaa for enable prompt?</title>
      <link>https://community.cisco.com/t5/network-access-control/use-aaa-for-enable-prompt/m-p/1801589#M228616</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently, I dont know how to have many users with different password. My switches are 2960-S.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;user:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username scd privilege 15 secret 5 $1$&lt;/P&gt;&lt;P&gt;username opst privilege 15 secret 5 $1$&lt;/P&gt;&lt;P&gt;username read privilege 7 secret 5 $1$&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i try to connect to my switch, I enter my username and my password, but I am not in enable mode then I enter enable but the switch doesnt ask me a password. It's not a problem with a personal username, but it's the same thing with a common username like read...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I try to enter this command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Enable secret &amp;lt;&lt;EM&gt;mypassword&lt;/EM&gt;&amp;gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this case, all users must enter &lt;EM&gt;mypassword&lt;/EM&gt; ! How to be enable with user's password with local base?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best regards,&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 01:26:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/use-aaa-for-enable-prompt/m-p/1801589#M228616</guid>
      <dc:creator>DynDarako</dc:creator>
      <dc:date>2019-03-11T01:26:00Z</dc:date>
    </item>
    <item>
      <title>Use aaa for enable prompt?</title>
      <link>https://community.cisco.com/t5/network-access-control/use-aaa-for-enable-prompt/m-p/1801590#M228618</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe you can setup levels on the enable command.&amp;nbsp; Here's the link: &lt;A href="http://www.cisco.com/en/US/docs/ios/12_2/security/configuration/guide/scfpass.html#wp1001368"&gt;http://www.cisco.com/en/US/docs/ios/12_2/security/configuration/guide/scfpass.html#wp1001368&lt;/A&gt;.&amp;nbsp; Read the 3rd paragraph from the bottom of "Protecting Passwords with Enable Password and Enable Secret" topic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Sep 2011 00:03:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/use-aaa-for-enable-prompt/m-p/1801590#M228618</guid>
      <dc:creator>jliscano</dc:creator>
      <dc:date>2011-09-28T00:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: Use aaa for enable prompt?</title>
      <link>https://community.cisco.com/t5/network-access-control/use-aaa-for-enable-prompt/m-p/1801591#M228623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is another option:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are half way to make this work. You already have authentication happening locally; we should be able to attach the user authentication to the assigned privilege by using authorization.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;aaa authorization exec default local &amp;lt;&amp;lt;&amp;lt; Once you add this the Switch will place the new authenticated user into the correct Privilege level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;The users will not be prompt for the enable password, but will jump directly into the enable mode. You could confirm the privilege level assigned to the user with the show priv command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The original enable password/secret would still be there, if you allow users access to the enable command, then they can still jump into the Full Privilege Enable mode (15). This can be avoided by giving the users a lower privilege level, then moving the enable command up to a higher privilege level.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't have a switch with me at this moment to test the cli, but I think the command to change the privilege would be:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Switch(config)#privilege exec level X enable&lt;/P&gt;&lt;P&gt;where X is the new privilege evel. Of course the junior user should be in a lower level in order to not reach the command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you find this &lt;EM style="font-weight: bold; font-style: normal; color: #000000;"&gt;post helpful&lt;/EM&gt;?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Sep 2011 01:40:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/use-aaa-for-enable-prompt/m-p/1801591#M228623</guid>
      <dc:creator>andressalazard</dc:creator>
      <dc:date>2011-09-28T01:40:01Z</dc:date>
    </item>
    <item>
      <title>Use aaa for enable prompt?</title>
      <link>https://community.cisco.com/t5/network-access-control/use-aaa-for-enable-prompt/m-p/1801592#M228624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I show my aaa configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login default local&lt;/P&gt;&lt;P&gt;aaa authorization console&lt;/P&gt;&lt;P&gt;aaa authorization exec default local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After, i try to enter your command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;privilege exec level 15 enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it doesnt work! Indeed, after my connection, i enter this command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show privilege&lt;/P&gt;&lt;P&gt;Current privilege level is 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whereas in my configuraiton my user is level 15... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Sep 2011 07:53:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/use-aaa-for-enable-prompt/m-p/1801592#M228624</guid>
      <dc:creator>DynDarako</dc:creator>
      <dc:date>2011-09-29T07:53:56Z</dc:date>
    </item>
    <item>
      <title>Use aaa for enable prompt?</title>
      <link>https://community.cisco.com/t5/network-access-control/use-aaa-for-enable-prompt/m-p/1801593#M228626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;why don't you just do this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication enable default local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Alain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Sep 2011 15:24:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/use-aaa-for-enable-prompt/m-p/1801593#M228626</guid>
      <dc:creator>cadet alain</dc:creator>
      <dc:date>2011-09-29T15:24:37Z</dc:date>
    </item>
    <item>
      <title>Use aaa for enable prompt?</title>
      <link>https://community.cisco.com/t5/network-access-control/use-aaa-for-enable-prompt/m-p/1801594#M228627</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This command doesn't exist in my IOS... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication enable default local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ^&lt;/P&gt;&lt;P&gt;% Invalid input detected at '^' marker.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My choices are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; cache&amp;nbsp;&amp;nbsp; Use Cached-group&lt;/P&gt;&lt;P&gt;&amp;nbsp; enable&amp;nbsp; Use enable password for authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp; group&amp;nbsp;&amp;nbsp; Use Server-group&lt;/P&gt;&lt;P&gt;&amp;nbsp; line&amp;nbsp;&amp;nbsp;&amp;nbsp; Use line password for authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp; none&amp;nbsp;&amp;nbsp;&amp;nbsp; NO authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No option solves the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Sep 2011 10:25:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/use-aaa-for-enable-prompt/m-p/1801594#M228627</guid>
      <dc:creator>DynDarako</dc:creator>
      <dc:date>2011-09-30T10:25:13Z</dc:date>
    </item>
    <item>
      <title>Re: Use aaa for enable prompt?</title>
      <link>https://community.cisco.com/t5/network-access-control/use-aaa-for-enable-prompt/m-p/5155000#M591038</link>
      <description>&lt;P&gt;Same issue on 9300, invalid input, did this ever get solved? Cisco authentication is a mess.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2024 12:59:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/use-aaa-for-enable-prompt/m-p/5155000#M591038</guid>
      <dc:creator>Josh732532</dc:creator>
      <dc:date>2024-08-02T12:59:38Z</dc:date>
    </item>
  </channel>
</rss>

