<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/best-practice-for-reenabling-aaa/m-p/2867431#M36868</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;How do you access the device ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is it via SSH/telnet/console ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 03 Apr 2016 09:03:21 GMT</pubDate>
    <dc:creator>Aditya Ganjoo</dc:creator>
    <dc:date>2016-04-03T09:03:21Z</dc:date>
    <item>
      <title>Best practice for reenabling AAA</title>
      <link>https://community.cisco.com/t5/network-access-control/best-practice-for-reenabling-aaa/m-p/2867426#M36857</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My question is about reenabling AAA on a device. I have a company A that had their devices and their AAA configuration. Now company A was bought by company B and the devices of company A are migrating to configuration standard of B. Network engineers of B receive access to A with line password and when they do aaa new-model they lock themselves as configuration of aaa was not removed but only turned of by "no aaa new-model".&lt;/P&gt;
&lt;P&gt;I assume that best practice would be to instruct guys from A to remove whole config of AAA but lets say that I cannot do it. What's the best method to migrate to new aaa configuration?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 06:38:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/best-practice-for-reenabling-aaa/m-p/2867426#M36857</guid>
      <dc:creator>raaffffii</dc:creator>
      <dc:date>2019-03-11T06:38:14Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/best-practice-for-reenabling-aaa/m-p/2867427#M36859</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Could you share the sh run | in aaa output of the device ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If not then you can go ahead and remove the aaa config for the A company and configure the new one for company B.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Since you have already used no aaa new-model that means you have turned off the AAA on the device.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Not sure why did you &lt;G class="gr_ gr_212 gr-alert gr_gramm gr_run_anim Grammar only-ins replaceWithoutSep" id="212" data-gr-id="212"&gt;get&lt;/G&gt; lock out on the device ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;Please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Apr 2016 07:59:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/best-practice-for-reenabling-aaa/m-p/2867427#M36859</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-04-03T07:59:36Z</dc:date>
    </item>
    <item>
      <title>Hi Aditya,</title>
      <link>https://community.cisco.com/t5/network-access-control/best-practice-for-reenabling-aaa/m-p/2867428#M36862</link>
      <description>&lt;P&gt;Hi Aditya,&lt;/P&gt;
&lt;P&gt;Thank you for the answer. Both companies have their own ACS servers engineer from B has account only on ACS B. So when he enables aaa new-model when being logged in locally with a password old configuration takes into place. Old with aaa authorization so he now is unauthorized to do anything.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Apr 2016 08:07:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/best-practice-for-reenabling-aaa/m-p/2867428#M36862</guid>
      <dc:creator>raaffffii</dc:creator>
      <dc:date>2016-04-03T08:07:20Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/best-practice-for-reenabling-aaa/m-p/2867429#M36866</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;G class="gr_ gr_15 gr-alert gr_gramm gr_run_anim Punctuation only-ins replaceWithoutSep" id="15" data-gr-id="15"&gt;Yes&lt;/G&gt; you are correct.&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;So you can go ahead with removing the aaa authorization command.&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;Regards,&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;Aditya&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Apr 2016 08:09:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/best-practice-for-reenabling-aaa/m-p/2867429#M36866</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-04-03T08:09:40Z</dc:date>
    </item>
    <item>
      <title>I don't know if you see this</title>
      <link>https://community.cisco.com/t5/network-access-control/best-practice-for-reenabling-aaa/m-p/2867430#M36867</link>
      <description>&lt;P&gt;I don't know if you see this but when you do "no aaa new-model" then all the commens that you configured aaa authentication, authorization are somehow hidden and not removed. When you reenable aaa by "aaa new-model" then they apear once again in config. So the engineer does not have a chance to remove them as he locks himself just after enabling aaa.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Apr 2016 08:19:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/best-practice-for-reenabling-aaa/m-p/2867430#M36867</guid>
      <dc:creator>raaffffii</dc:creator>
      <dc:date>2016-04-03T08:19:57Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/best-practice-for-reenabling-aaa/m-p/2867431#M36868</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;How do you access the device ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Is it via SSH/telnet/console ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Apr 2016 09:03:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/best-practice-for-reenabling-aaa/m-p/2867431#M36868</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-04-03T09:03:21Z</dc:date>
    </item>
    <item>
      <title>via telnet</title>
      <link>https://community.cisco.com/t5/network-access-control/best-practice-for-reenabling-aaa/m-p/2867432#M36870</link>
      <description>&lt;P&gt;via telnet&lt;/P&gt;</description>
      <pubDate>Sun, 03 Apr 2016 11:06:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/best-practice-for-reenabling-aaa/m-p/2867432#M36870</guid>
      <dc:creator>raaffffii</dc:creator>
      <dc:date>2016-04-03T11:06:53Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/best-practice-for-reenabling-aaa/m-p/2867433#M36874</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Could you&amp;nbsp;share the show run | in aaa and show run | sec vty config from the device ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;</description>
      <pubDate>Sun, 03 Apr 2016 11:28:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/best-practice-for-reenabling-aaa/m-p/2867433#M36874</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-04-03T11:28:26Z</dc:date>
    </item>
  </channel>
</rss>

