<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA login authentication methods in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-login-authentication-methods/m-p/1998055#M245705</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the config you have under the line you are logging from (console, vty ... Etc.)?&lt;/P&gt;&lt;P&gt;What happens when you remove the "none" keyword from the config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Jul 2012 14:25:45 GMT</pubDate>
    <dc:creator>Amjad Abdullah</dc:creator>
    <dc:date>2012-07-05T14:25:45Z</dc:date>
    <item>
      <title>AAA login authentication methods</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-login-authentication-methods/m-p/1998054#M245702</link>
      <description>&lt;P&gt;﻿Hello guys, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've noticed a strange behaviour with AAA authentication login. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My AAA configuration for login authentication is: &lt;STRONG&gt;aaa authentication login default group tacacs+ local&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No tacacs server exists, but username and password in local database does. Indeed everything works fine when I log in: &lt;STRONG&gt;aaa authentication login default group tacacs+ local line none&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem comes up when I add to the method list line and none authentication methods. &lt;/P&gt;&lt;P&gt;﻿&lt;/P&gt;&lt;P&gt;In this case, when I log into the switch (via console for example), and I'm asked for username, there is no validation of the username, I mean to say, I can put whatever username and been granted access. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Conclusion: According to my aaa authentication list, method line or none should not be used unless tacacs and local are not available. In this case, local method is available and should fail so login should be rejected, but it jumps to the next method, finally giving access. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this a bug in AAA? or am I misunderstanding something.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot. &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:16:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-login-authentication-methods/m-p/1998054#M245702</guid>
      <dc:creator>Oscar Falcon Ortiz</dc:creator>
      <dc:date>2019-03-11T02:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: AAA login authentication methods</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-login-authentication-methods/m-p/1998055#M245705</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the config you have under the line you are logging from (console, vty ... Etc.)?&lt;/P&gt;&lt;P&gt;What happens when you remove the "none" keyword from the config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 14:25:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-login-authentication-methods/m-p/1998055#M245705</guid>
      <dc:creator>Amjad Abdullah</dc:creator>
      <dc:date>2012-07-05T14:25:45Z</dc:date>
    </item>
    <item>
      <title>AAA login authentication methods</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-login-authentication-methods/m-p/1998056#M245717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Only exec-timeout command, so it applies the default list defined by aaa.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I remove the none, authentication fails. I've debugged AAA authentication and shows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User Access Verification&lt;/P&gt;&lt;P&gt;Username: &lt;BR /&gt;Jul&amp;nbsp; 5 18:16:48.329 METDST: AAA/BIND(00000035): Bind i/f&amp;nbsp; &lt;BR /&gt;Jul&amp;nbsp; 5 18:16:49.493 METDST: AAA/AUTHEN/LOGIN (00000035): Pick method list 'default' adsf&lt;/P&gt;&lt;P&gt;Jul&amp;nbsp; 5 18:16:56.382 METDST: AAA/AUTHEN/LINE(00000035): FAIL - &lt;STRONG&gt;Line password &lt;/STRONG&gt;not found&lt;BR /&gt;% Authentication failed&lt;/P&gt;&lt;P&gt;Username:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Local authentication method is being bypassed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I configure a password under line con 0, I've access regardless of the username, so no local authentication is being enforced as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 16:21:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-login-authentication-methods/m-p/1998056#M245717</guid>
      <dc:creator>Oscar Falcon Ortiz</dc:creator>
      <dc:date>2012-07-05T16:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: AAA login authentication methods</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-login-authentication-methods/m-p/1998057#M245725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's not a bug, it works as designed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your confusion is caused by the way the method "local" works. "local" does not give an error if the username doesn't exist as a typical RADIUS- or TACACS-server would do. Instead the next available method is picked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What happens in your case:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- You log in with "anyname"&lt;/P&gt;&lt;P&gt;- TACACS-server is not available, so fall back to next method (local)&lt;/P&gt;&lt;P&gt;- "anyname" is not in the local userdatabase, so fall back to the next method (line)&lt;/P&gt;&lt;P&gt;- a line password is not configured, so fall back to the next method (none)&lt;/P&gt;&lt;P&gt;- you're in!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Jul 2012 18:25:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-login-authentication-methods/m-p/1998057#M245725</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2012-07-05T18:25:33Z</dc:date>
    </item>
  </channel>
</rss>

