<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AAA authentication problem in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-problem/m-p/695852#M422285</link>
    <description>&lt;P&gt;I've setup my AAA config as follows "aaa authentication login default group tacacs+ enable". When I test config with SSH (ACS turned off)to the router I cannot login using the enable password. The same does not work when trying to connect with Con0.  How can I correct this problem. Forum help is much appreciated, thanks all.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 21:52:36 GMT</pubDate>
    <dc:creator>ms4561</dc:creator>
    <dc:date>2019-03-10T21:52:36Z</dc:date>
    <item>
      <title>AAA authentication problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-problem/m-p/695852#M422285</link>
      <description>&lt;P&gt;I've setup my AAA config as follows "aaa authentication login default group tacacs+ enable". When I test config with SSH (ACS turned off)to the router I cannot login using the enable password. The same does not work when trying to connect with Con0.  How can I correct this problem. Forum help is much appreciated, thanks all.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:52:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-problem/m-p/695852#M422285</guid>
      <dc:creator>ms4561</dc:creator>
      <dc:date>2019-03-10T21:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-problem/m-p/695853#M422286</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have  authorization only with tacacs+, can you try following command&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ none &lt;/P&gt;&lt;P&gt;M.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Dec 2006 07:19:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-problem/m-p/695853#M422286</guid>
      <dc:creator>m.sir</dc:creator>
      <dc:date>2006-12-13T07:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication problem</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-problem/m-p/695854#M422287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree that the configuration of aaa authentication login looks ok (I would probably use line as the alternative method instead of enable - but it should work with either) and that the issue is the configuration of authorization:&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ &lt;/P&gt;&lt;P&gt;this provides no alternative method. And I suspect that if you look carefully at the error message when you attempt to login without TACACS the error is actually about authorization rather than about authentication. The suggestion of:&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ none &lt;/P&gt;&lt;P&gt;should be ok. I have used this way with success:&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Dec 2006 18:03:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-problem/m-p/695854#M422287</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2006-12-13T18:03:53Z</dc:date>
    </item>
  </channel>
</rss>

