<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Please share the line Con 0 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-commands/m-p/2957635#M37450</link>
    <description>&lt;P&gt;Please share the line Con 0 configuration from IOS switch.&lt;/P&gt;
&lt;P&gt;Do you have local enable password set ?&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;</description>
    <pubDate>Fri, 25 Nov 2016 15:19:17 GMT</pubDate>
    <dc:creator>Gagandeep Singh</dc:creator>
    <dc:date>2016-11-25T15:19:17Z</dc:date>
    <item>
      <title>AAA commands</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-commands/m-p/2957634#M37449</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;i want to enable aaa on the ios switch on ssh and telnet and not on console access. i am putting the below commands&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;phase 1:-&lt;/P&gt;
&lt;P&gt;aaa authentication login default group TACACS_SERVERS local&lt;BR /&gt;aaa authentication login CONSOLE local&lt;BR /&gt;aaa authentication enable default group TACACS_SERVERS enable&lt;BR /&gt;aaa session-id common&lt;BR /&gt;!&lt;BR /&gt;aaa authorization config-commands&lt;BR /&gt;aaa authorization exec CONSOLE none&lt;/P&gt;
&lt;P&gt;aaa authorization exec default group TACACS_SERVERS local&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;this way i am able to login to console using local username and password but the enable password is not working.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;does it require the below commands as well to make it work. as i dont want console users to be authenticated through AAA.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;aaa authorization commands 0 default group TACACS_SERVERS if-authenticated &lt;BR /&gt;aaa authorization commands 1 default group TACACS_SERVERS if-authenticated &lt;BR /&gt;aaa authorization commands 15 default group TACACS_SERVERS if-authenticated &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:15:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-commands/m-p/2957634#M37449</guid>
      <dc:creator>saxenanitesh8522</dc:creator>
      <dc:date>2019-03-11T07:15:25Z</dc:date>
    </item>
    <item>
      <title>Please share the line Con 0</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-commands/m-p/2957635#M37450</link>
      <description>&lt;P&gt;Please share the line Con 0 configuration from IOS switch.&lt;/P&gt;
&lt;P&gt;Do you have local enable password set ?&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;</description>
      <pubDate>Fri, 25 Nov 2016 15:19:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-commands/m-p/2957635#M37450</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2016-11-25T15:19:17Z</dc:date>
    </item>
    <item>
      <title>this command aaa</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-commands/m-p/2957636#M37451</link>
      <description>&lt;P&gt;this command&amp;nbsp;&lt;SPAN&gt;aaa authorization exec CONSOLE none&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;will put you directly in privilege&amp;nbsp;mode the enable will not be prompted. when you access from console&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;but of course you need to use the local user name and password for authentication &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;those:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;aaa authorization commands 1 default group TACACS_SERVERS if-authenticated &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;aaa authorization commands 15 default group TACACS_SERVERS if-authenticated&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;required only if you want to authorize the commands !, so make sure to configure the ACS or any authentication server&amp;nbsp;properly&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;because&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;each command you type will be forwarded to ACS for authorization permission.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Yazan &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 26 Nov 2016 13:53:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-commands/m-p/2957636#M37451</guid>
      <dc:creator>yalbikaw</dc:creator>
      <dc:date>2016-11-26T13:53:51Z</dc:date>
    </item>
  </channel>
</rss>

