<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic aaa commands in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-commands/m-p/1608269#M257496</link>
    <description>&lt;P&gt;Hi group ,&lt;/P&gt;&lt;P&gt;help me with the following aaa commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)aaa authentication login default group tacacs+ none&lt;/P&gt;&lt;P&gt;does it means if my tacacs server fails , the user will be authorized immediately (no authorization done ) as the next method list is "none"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;does this means if tacacs server is unavailable or fails to respond locally stored enable password will be used&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) if i issue this command " username admin&amp;nbsp; password cisco " what will be the privilege assigned to it .(by default)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) aaa authorization exec default group tacacs+ if-authenticated&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; a) plz explain what this do in general&lt;BR /&gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; b) what happens if authentication is successful with tacacs server and i have implemented command authorization to authorize all commands entered . now imagine server goes down. will authorization be allowed or user will be locked ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i hope i m clear in asking&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 00:49:24 GMT</pubDate>
    <dc:creator>mirehteshamali</dc:creator>
    <dc:date>2019-03-11T00:49:24Z</dc:date>
    <item>
      <title>aaa commands</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-commands/m-p/1608269#M257496</link>
      <description>&lt;P&gt;Hi group ,&lt;/P&gt;&lt;P&gt;help me with the following aaa commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1)aaa authentication login default group tacacs+ none&lt;/P&gt;&lt;P&gt;does it means if my tacacs server fails , the user will be authorized immediately (no authorization done ) as the next method list is "none"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;does this means if tacacs server is unavailable or fails to respond locally stored enable password will be used&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) if i issue this command " username admin&amp;nbsp; password cisco " what will be the privilege assigned to it .(by default)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) aaa authorization exec default group tacacs+ if-authenticated&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; a) plz explain what this do in general&lt;BR /&gt; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; b) what happens if authentication is successful with tacacs server and i have implemented command authorization to authorize all commands entered . now imagine server goes down. will authorization be allowed or user will be locked ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i hope i m clear in asking&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 00:49:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-commands/m-p/1608269#M257496</guid>
      <dc:creator>mirehteshamali</dc:creator>
      <dc:date>2019-03-11T00:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: aaa commands</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-commands/m-p/1608270#M257515</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1) If the TACACS+ server is unavailable authentication will succeed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) The enable password stored in the router will be used if the TACACS+ server is not available&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) The user will be given privilege level 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) It will do exec authorization using TACACS+ and if the authentication server is not available then the authorization will succeed if the user has successfully authenticated. This does not involve command authorization, only exec.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Exec authorization means the user will be granted the privilege level handed by either the TACACS+ server or the local username/password database.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Feb 2011 21:16:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-commands/m-p/1608270#M257515</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2011-02-13T21:16:08Z</dc:date>
    </item>
  </channel>
</rss>

