<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: aaa authentication failed in console mode in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-failed-in-console-mode/m-p/3747435#M25072</link>
    <description>&lt;P&gt;It works, many thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alex&lt;/P&gt;</description>
    <pubDate>Thu, 15 Nov 2018 15:03:49 GMT</pubDate>
    <dc:creator>Labin08</dc:creator>
    <dc:date>2018-11-15T15:03:49Z</dc:date>
    <item>
      <title>aaa authentication failed in console mode</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-failed-in-console-mode/m-p/3747246#M25070</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I authenticate my switches over an ISE acting as radius server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I connect with ssh, everything works well. My radius server return priv15 and I am logged directly in privilege 15.&lt;/P&gt;
&lt;P&gt;But the weird thing when I try to connect through the console cable, I get authenticate, the radius server return me the priv15 but the switch ask me to put the "enable" command. When I issue this command, I get rejected because the radius server is not able to find the object "$enab15$" that sounds logical.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So do you have any idea why I can't log with the console cable directly in privilege 15 ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can find below my configuration:&lt;/P&gt;
&lt;PRE&gt;aaa new-model
aaa group server radius RADIUS-SERVERS
aaa authentication login default group RADIUS-SERVERS local
aaa authentication enable default group RADIUS-SERVERS enable
aaa authentication dot1x default group RADIUS-SERVERS
aaa authorization exec default group RADIUS-SERVERS if-authenticated
aaa authorization network default group RADIUS-SERVERS if-authenticated
aaa accounting send stop-record authentication failure
aaa accounting update newinfo periodic 55
aaa accounting exec default start-stop group RADIUS-SERVERS
aaa accounting connection default start-stop group RADIUS-SERVERS
aaa accounting system default start-stop group RADIUS-SERVERS
no aaa accounting system guarantee-first
aaa session-id common
!
line con 0
 logging synchronous
 escape-character 3
 stopbits 1
line vty 0 4
 logging synchronous
 transport input ssh
 escape-character 3
line vty 5 15
 logging synchronous
 transport input ssh
 escape-character 3
!&lt;/PRE&gt;
&lt;P&gt;Have a nice day,&lt;/P&gt;
&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 08:52:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-failed-in-console-mode/m-p/3747246#M25070</guid>
      <dc:creator>Labin08</dc:creator>
      <dc:date>2019-03-11T08:52:04Z</dc:date>
    </item>
    <item>
      <title>Re: aaa authentication failed in console mode</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-failed-in-console-mode/m-p/3747336#M25071</link>
      <description>&lt;P&gt;Hi Alex.&lt;BR /&gt;I think you need this command "aaa authorization console" and "authorization exec" in line console&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Nov 2018 12:46:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-failed-in-console-mode/m-p/3747336#M25071</guid>
      <dc:creator>fbabashahi</dc:creator>
      <dc:date>2018-11-15T12:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: aaa authentication failed in console mode</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-failed-in-console-mode/m-p/3747435#M25072</link>
      <description>&lt;P&gt;It works, many thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Thu, 15 Nov 2018 15:03:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-failed-in-console-mode/m-p/3747435#M25072</guid>
      <dc:creator>Labin08</dc:creator>
      <dc:date>2018-11-15T15:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: aaa authentication failed in console mode</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-failed-in-console-mode/m-p/3747589#M25073</link>
      <description>your welcome&lt;BR /&gt;&lt;BR /&gt;Good Luck</description>
      <pubDate>Thu, 15 Nov 2018 18:31:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-failed-in-console-mode/m-p/3747589#M25073</guid>
      <dc:creator>fbabashahi</dc:creator>
      <dc:date>2018-11-15T18:31:25Z</dc:date>
    </item>
  </channel>
</rss>

