<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic aaa new-modelaaa in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/local-username-does-not-work-when-management-interface-is-down/m-p/2899111#M36759</link>
    <description>&lt;P&gt;aaa new-model&lt;BR /&gt;aaa authentication login default group tacacs+ local&lt;BR /&gt;aaa authentication enable default group tacacs+ enable&lt;BR /&gt;aaa authorization exec default group tacacs+ if-authenticated&lt;BR /&gt;aaa accounting update newinfo&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;username XXX secret XXXXXX&lt;/P&gt;</description>
    <pubDate>Fri, 08 Apr 2016 17:33:23 GMT</pubDate>
    <dc:creator>dwsmithjr</dc:creator>
    <dc:date>2016-04-08T17:33:23Z</dc:date>
    <item>
      <title>local username does not work when management interface is down</title>
      <link>https://community.cisco.com/t5/network-access-control/local-username-does-not-work-when-management-interface-is-down/m-p/2899109#M36757</link>
      <description>&lt;P&gt;On switches when the management interface is down (vlan1), we cannot login from the console using the local username and password. if the management interface is up but TACACS is not available, it works fine for a vty interface. If you connect to console and TACACS is available, the TACACS login for course works and local does not.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We need to be able to use the command "username xxx secret" and be able to login when connected to the console port when TACACS is not available or the management interface is down, using the local username and password.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:39:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-username-does-not-work-when-management-interface-is-down/m-p/2899109#M36757</guid>
      <dc:creator>dwsmithjr</dc:creator>
      <dc:date>2019-03-11T06:39:32Z</dc:date>
    </item>
    <item>
      <title>Can you please post the AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/local-username-does-not-work-when-management-interface-is-down/m-p/2899110#M36758</link>
      <description>&lt;P&gt;Can you please post the AAA configuration on your switch?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Javier Henderson&lt;/P&gt;
&lt;P&gt;Cisco Systems&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 17:30:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-username-does-not-work-when-management-interface-is-down/m-p/2899110#M36758</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2016-04-08T17:30:49Z</dc:date>
    </item>
    <item>
      <title>aaa new-modelaaa</title>
      <link>https://community.cisco.com/t5/network-access-control/local-username-does-not-work-when-management-interface-is-down/m-p/2899111#M36759</link>
      <description>&lt;P&gt;aaa new-model&lt;BR /&gt;aaa authentication login default group tacacs+ local&lt;BR /&gt;aaa authentication enable default group tacacs+ enable&lt;BR /&gt;aaa authorization exec default group tacacs+ if-authenticated&lt;BR /&gt;aaa accounting update newinfo&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;username XXX secret XXXXXX&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 17:33:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-username-does-not-work-when-management-interface-is-down/m-p/2899111#M36759</guid>
      <dc:creator>dwsmithjr</dc:creator>
      <dc:date>2016-04-08T17:33:23Z</dc:date>
    </item>
    <item>
      <title>We will need more to go</title>
      <link>https://community.cisco.com/t5/network-access-control/local-username-does-not-work-when-management-interface-is-down/m-p/2899112#M36760</link>
      <description>&lt;P&gt;We will need more to go further, for example, do you have VLAN 1 as the source for TACACS+ packets?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When I said the AAA configuration, I meant everything related to it.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Javier Henderson&lt;/P&gt;
&lt;P&gt;Cisco Systems&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 17:40:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-username-does-not-work-when-management-interface-is-down/m-p/2899112#M36760</guid>
      <dc:creator>Javier Henderson</dc:creator>
      <dc:date>2016-04-08T17:40:08Z</dc:date>
    </item>
    <item>
      <title>Yes, Vlan1 is the TACACS</title>
      <link>https://community.cisco.com/t5/network-access-control/local-username-does-not-work-when-management-interface-is-down/m-p/2899113#M36761</link>
      <description>&lt;P&gt;Yes, Vlan1 is the TACACS source interface. I'll gather the rest of the configuration information relating to TACACS. We are able to login with the local account when we connect remotely using a vty interface (SSH) and TACACS is not available. That works fine.&lt;/P&gt;
&lt;P&gt;We cannot login using the console interface when the router is disconnected from the network, say when it is being initially configured, has been rebooted and the tech is trying to reconnect through the console port. So, the management interface or vlan is down.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 18:35:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-username-does-not-work-when-management-interface-is-down/m-p/2899113#M36761</guid>
      <dc:creator>dwsmithjr</dc:creator>
      <dc:date>2016-04-08T18:35:18Z</dc:date>
    </item>
    <item>
      <title>Here is the scenario. A tech</title>
      <link>https://community.cisco.com/t5/network-access-control/local-username-does-not-work-when-management-interface-is-down/m-p/2899114#M36762</link>
      <description>&lt;P&gt;Here is the scenario. A tech is configuring a switch to be deployed to a location using the console port. They add the configuration which includes "username XXX secret XXXXXXX. They then save the configuration and reboot the switch. The switch is not connected to any network at this point.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When the switch comes up, they attempt to login again through the console port and cannot authenticate. The login is denied.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Vlan1 is the management interface and the TACACS source interface.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2016 18:38:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-username-does-not-work-when-management-interface-is-down/m-p/2899114#M36762</guid>
      <dc:creator>dwsmithjr</dc:creator>
      <dc:date>2016-04-08T18:38:08Z</dc:date>
    </item>
    <item>
      <title>Let me know if you need</title>
      <link>https://community.cisco.com/t5/network-access-control/local-username-does-not-work-when-management-interface-is-down/m-p/2899115#M36763</link>
      <description>&lt;P&gt;Let me know if you need anything else.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;aaa group server tacacs+ ACS53&lt;BR /&gt;&amp;nbsp;server name XXX&lt;BR /&gt;&amp;nbsp;server name XXX&lt;BR /&gt;&lt;BR /&gt;aaa authentication login default group tacacs+ local&lt;BR /&gt;aaa authentication enable default group tacacs+ enable&lt;BR /&gt;aaa authorization exec default group tacacs+ if-authenticated&lt;BR /&gt;aaa accounting update newinfo&lt;BR /&gt;&lt;BR /&gt;aaa session-id common&lt;BR /&gt;&lt;BR /&gt;interface Vlan1&lt;BR /&gt;&amp;nbsp;description &amp;lt;Serial number and Asset tag&amp;gt;&lt;BR /&gt;&amp;nbsp;ip address &amp;lt;INSERT SWITCH IP ADDRESS&amp;gt; xxx.xxx.xxx.0&lt;BR /&gt;&amp;nbsp;no ip redirects&lt;BR /&gt;&amp;nbsp;no ip unreachables&lt;BR /&gt;&amp;nbsp;no ip route-cache&lt;BR /&gt;&amp;nbsp;no shut&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;ip tacacs source-interface Vlan1&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;tacacs-server timeout 20&lt;BR /&gt;tacacs server XXX&lt;BR /&gt;&amp;nbsp;address ipv4 xx.xxx.xxx.xxx&lt;BR /&gt;&amp;nbsp;key 7 xxxxxxxxxxxxxxxx&lt;BR /&gt;tacacs server XXX&lt;BR /&gt;&amp;nbsp;address ipv4 xxx.xxx.xxx.xxx&lt;BR /&gt;&amp;nbsp;key 7 xxxxxxxxxxxxxxxx&lt;BR /&gt;tacacs-server directed-request&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 11:59:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-username-does-not-work-when-management-interface-is-down/m-p/2899115#M36763</guid>
      <dc:creator>dwsmithjr</dc:creator>
      <dc:date>2016-04-11T11:59:07Z</dc:date>
    </item>
    <item>
      <title>We've resolved the issue. It</title>
      <link>https://community.cisco.com/t5/network-access-control/local-username-does-not-work-when-management-interface-is-down/m-p/2899116#M36764</link>
      <description>&lt;P&gt;We've resolved the issue. It was a "user error" on the part of some of the people configuring the switches.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2016 18:15:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/local-username-does-not-work-when-management-interface-is-down/m-p/2899116#M36764</guid>
      <dc:creator>dwsmithjr</dc:creator>
      <dc:date>2016-04-11T18:15:02Z</dc:date>
    </item>
  </channel>
</rss>

