<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CATOS AAA Config in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/catos-aaa-config/m-p/765284#M420241</link>
    <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the below working config for TACACS+ authentication and accounting for IOS based devices. Would anybody be able to give me a CATOS version for the config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 0 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;enable password cisco&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;username Manager password 0 cisco&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host 10.1.1.1&lt;/P&gt;&lt;P&gt;tacacs-server key cisco&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 22:14:12 GMT</pubDate>
    <dc:creator>daniel.bowen</dc:creator>
    <dc:date>2019-03-10T22:14:12Z</dc:date>
    <item>
      <title>CATOS AAA Config</title>
      <link>https://community.cisco.com/t5/network-access-control/catos-aaa-config/m-p/765284#M420241</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the below working config for TACACS+ authentication and accounting for IOS based devices. Would anybody be able to give me a CATOS version for the config?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable&lt;/P&gt;&lt;P&gt;aaa accounting exec default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 0 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 1 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;aaa accounting commands 15 default start-stop group tacacs+&lt;/P&gt;&lt;P&gt;enable password cisco&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;username Manager password 0 cisco&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host 10.1.1.1&lt;/P&gt;&lt;P&gt;tacacs-server key cisco&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:14:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/catos-aaa-config/m-p/765284#M420241</guid>
      <dc:creator>daniel.bowen</dc:creator>
      <dc:date>2019-03-10T22:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: CATOS AAA Config</title>
      <link>https://community.cisco.com/t5/network-access-control/catos-aaa-config/m-p/765285#M420242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First make sure that your CatOS version supports fallback, because few earlier versions were not able to do so,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyhow, here you go,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/----------------------------------/&lt;/P&gt;&lt;P&gt;!--- Define localuser to prevent ourself from being lockedout&lt;/P&gt;&lt;P&gt;!--- For backdoor purpose&lt;/P&gt;&lt;P&gt;set localuser user &lt;USERNAME&gt; password &lt;PASSWORD&gt; privilege 15&lt;/PASSWORD&gt;&lt;/USERNAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!--- Specify the TACACS server ip address,i.e., ACS ip address&lt;/P&gt;&lt;P&gt;set tacacs server &lt;IP-ADDR-ACS&gt;&lt;/IP-ADDR-ACS&gt;&lt;/P&gt;&lt;P&gt;set tacacs key &lt;SECRET-TACACS-KEY&gt;&lt;/SECRET-TACACS-KEY&gt;&lt;/P&gt;&lt;P&gt;set tacacs timeout 30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!--- For backdoor purspose, specify authentication for &lt;/P&gt;&lt;P&gt;!--- login and enable via local database.&lt;/P&gt;&lt;P&gt;set authentication login local enable all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!--- Specifying authentication for login &amp;amp; enable via TACACS&lt;/P&gt;&lt;P&gt;set authentication login tacacs enable telnet primary&lt;/P&gt;&lt;P&gt;set authorization exec enable tacacs+ none telnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!--- Specifying accouting for exec level&lt;/P&gt;&lt;P&gt;set accounting exec enable start-stop tacacs+&lt;/P&gt;&lt;P&gt;!--- Specifying accounting for users telnetting out of the switch&lt;/P&gt;&lt;P&gt;set accounting connect enable start-stop tacacs+&lt;/P&gt;&lt;P&gt;!--- Accounts for system level changes over switch&lt;/P&gt;&lt;P&gt;set accounting system enable start-stop tacacs+&lt;/P&gt;&lt;P&gt;!--- For accounting events performed by users,i.e.,commands being issued&lt;/P&gt;&lt;P&gt;set accounting commands enable all start-stop tacacs+&lt;/P&gt;&lt;P&gt;/----------------------------------/&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For 8.6:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuring the Switch Access Using AAA:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/sw_8_6/confg_gd/authent.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/sw_8_6/confg_gd/authent.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jun 2007 14:53:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/catos-aaa-config/m-p/765285#M420242</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2007-06-22T14:53:17Z</dc:date>
    </item>
    <item>
      <title>Re: CATOS AAA Config</title>
      <link>https://community.cisco.com/t5/network-access-control/catos-aaa-config/m-p/765286#M420243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do not put exec authorization, you do not have that in IOS config,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!--- Specifying authentication for login &amp;amp; enable via TACACS&lt;/P&gt;&lt;P&gt;set authentication login tacacs enable telnet primary&lt;/P&gt;&lt;P&gt;set authorization exec enable tacacs+ none telnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Instead, use this,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!--- Specifying authentication for enable&lt;/P&gt;&lt;P&gt;set authentication enable tacacs enable telnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you have "aaa authentication enable default group tacacs+ enable"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Jun 2007 14:59:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/catos-aaa-config/m-p/765286#M420243</guid>
      <dc:creator>Premdeep Banga</dc:creator>
      <dc:date>2007-06-22T14:59:53Z</dc:date>
    </item>
  </channel>
</rss>

