<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA authentication configuration  in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-configuration/m-p/1300533#M343604</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Subodh &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) since there is no authentication list specified on the vty ports then they will use the default authentication. With aaa new-model the default for vty is local authentication. So the router should prompt for ID and password - and if you give the ID and password as configured then you should successfully access the vty.&lt;/P&gt;&lt;P&gt;2) since there is an authentication list specified for the console then the router will use the methods in the list when you access the console port. If the TACACS server is available then the router will authenticate using the server. If the server is not available then the router will authenticate with the local user ID and password. The router will not authenticate using the console password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 27 Jul 2009 00:19:49 GMT</pubDate>
    <dc:creator>Richard Burts</dc:creator>
    <dc:date>2009-07-27T00:19:49Z</dc:date>
    <item>
      <title>AAA authentication configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-configuration/m-p/1300532#M343582</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;If following configuration is done what will be effect?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;username operation priv 7 password cisco&lt;/P&gt;&lt;P&gt;enable secret cisco@1234&lt;/P&gt;&lt;P&gt;aaa authentication login TEST group tacacs+ local.&lt;/P&gt;&lt;P&gt;( tacacs+ server is down so local user database will be used)&lt;/P&gt;&lt;P&gt;line console 0&lt;/P&gt;&lt;P&gt;password Admin@login&lt;/P&gt;&lt;P&gt;aaa authentication TEST&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt;password operatio@login.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;case:&lt;/P&gt;&lt;P&gt;1: vty access : as there is no list or default  configured telnet access will be denied. Or it will still ask aaa authentication username / password. Am I correct ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;case 2 : If connected to console port, first console password will be asked or directly username / password will be asked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please share the experience.&lt;/P&gt;&lt;P&gt;Thanks in advance. sorry cant try it on production devices. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Subodh &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:36:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-configuration/m-p/1300532#M343582</guid>
      <dc:creator>bapatsubodh</dc:creator>
      <dc:date>2019-03-10T23:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication configuration</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-configuration/m-p/1300533#M343604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Subodh &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) since there is no authentication list specified on the vty ports then they will use the default authentication. With aaa new-model the default for vty is local authentication. So the router should prompt for ID and password - and if you give the ID and password as configured then you should successfully access the vty.&lt;/P&gt;&lt;P&gt;2) since there is an authentication list specified for the console then the router will use the methods in the list when you access the console port. If the TACACS server is available then the router will authenticate using the server. If the server is not available then the router will authenticate with the local user ID and password. The router will not authenticate using the console password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Jul 2009 00:19:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-configuration/m-p/1300533#M343604</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2009-07-27T00:19:49Z</dc:date>
    </item>
  </channel>
</rss>

