<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA and vty authentication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-and-vty-authentication/m-p/735877#M421049</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This password is known as the line password as it is configured on the line interface.   In your configuration it is not used at all and can probably be removed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This password is used as the login password when you are not using "aaa new-model". This password is probably left over from the days before you used AAA for authentication on the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you wanted to you could add the line password to your aaa authentication line:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login LETMEIN local line&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;... in which case, telnet access would use local usernames and passwords but if these were unavailable for some reason (perhaps because you forgot to create them or accidentally deleted them) the device could fall back to using the line password for authentication. This is not really that useful as one mostly uses local as a backup for a network-based authentication source such as tacacs+ in case the tacacs+ server is unreachable via the network which is far more likely than a problem occurring with your local user accounts. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 14 Apr 2007 16:04:38 GMT</pubDate>
    <dc:creator>Craig Balfour</dc:creator>
    <dc:date>2007-04-14T16:04:38Z</dc:date>
    <item>
      <title>AAA and vty authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-vty-authentication/m-p/735876#M421048</link>
      <description>&lt;P&gt;If i have got this configuration :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RouterA#show config&lt;/P&gt;&lt;P&gt;username forum password 0 A34@#&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login LETMEIN local&lt;/P&gt;&lt;P&gt;aaa authentication TO_CONSOLE group tacacs+ local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; line con 0&lt;/P&gt;&lt;P&gt;  login authentication TO_CONSOLE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; line vtu 0 3&lt;/P&gt;&lt;P&gt;  password class&lt;/P&gt;&lt;P&gt;  login authentication LETMEIN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the configuration shown above, users that telnet into the router are to be authenticated via the AAA line labeled "LETMEIN". This line says that the local user database should be used, so users that enter "forum" as the username, and "A34@#" as the password will be granted access to the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What will be the use of the password : " class" , Do we need it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:05:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-vty-authentication/m-p/735876#M421048</guid>
      <dc:creator>zillah2004</dc:creator>
      <dc:date>2019-03-10T22:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: AAA and vty authentication</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-and-vty-authentication/m-p/735877#M421049</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This password is known as the line password as it is configured on the line interface.   In your configuration it is not used at all and can probably be removed. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This password is used as the login password when you are not using "aaa new-model". This password is probably left over from the days before you used AAA for authentication on the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you wanted to you could add the line password to your aaa authentication line:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login LETMEIN local line&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;... in which case, telnet access would use local usernames and passwords but if these were unavailable for some reason (perhaps because you forgot to create them or accidentally deleted them) the device could fall back to using the line password for authentication. This is not really that useful as one mostly uses local as a backup for a network-based authentication source such as tacacs+ in case the tacacs+ server is unreachable via the network which is far more likely than a problem occurring with your local user accounts. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Apr 2007 16:04:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-and-vty-authentication/m-p/735877#M421049</guid>
      <dc:creator>Craig Balfour</dc:creator>
      <dc:date>2007-04-14T16:04:38Z</dc:date>
    </item>
  </channel>
</rss>

