<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX AAA Enable Local not working in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/pix-aaa-enable-local-not-working/m-p/662006#M422448</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To use local enable password, can you configure the following in your active PIX, then sync with standby unit:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication enable console LOCAL --&amp;gt; use local enable password&lt;/P&gt;&lt;P&gt;aaa authentication serial console LOCAL --&amp;gt; authenticate console access via local userID&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to skip TACACS+ first to test the access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 Nov 2006 12:03:12 GMT</pubDate>
    <dc:creator>a.kiprawih</dc:creator>
    <dc:date>2006-11-15T12:03:12Z</dc:date>
    <item>
      <title>PIX AAA Enable Local not working</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-aaa-enable-local-not-working/m-p/662005#M422447</link>
      <description>&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have lost the ability to ping the inside interface of my failover firewall. When I try to console into the Failover, I cannot get into enable mode.  I have the following Commands specified in the config:&lt;/P&gt;&lt;P&gt;aaa authentication serial console TACACS+ LOCAL&lt;/P&gt;&lt;P&gt;aaa authentication enable console TACACS+ LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can get in with the userid and password which has a privilege level of 15 however I cannot get into enable mode.  It prompts for password but does not accept it.  I have specified a new enable password and done a write standby but still doesn't work.  &lt;/P&gt;&lt;P&gt;The Pixes are using 6.3(5).  There are no authorization commands specified.  The authentication works fine on the primary firewall with Tacacs as it can contact the ACS Server on its inside interface.  It is just the local enable part on the failover firewall that is not working.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:50:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-aaa-enable-local-not-working/m-p/662005#M422447</guid>
      <dc:creator>brian.oflynn</dc:creator>
      <dc:date>2019-03-10T21:50:36Z</dc:date>
    </item>
    <item>
      <title>Re: PIX AAA Enable Local not working</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-aaa-enable-local-not-working/m-p/662006#M422448</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To use local enable password, can you configure the following in your active PIX, then sync with standby unit:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication enable console LOCAL --&amp;gt; use local enable password&lt;/P&gt;&lt;P&gt;aaa authentication serial console LOCAL --&amp;gt; authenticate console access via local userID&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to skip TACACS+ first to test the access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Nov 2006 12:03:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-aaa-enable-local-not-working/m-p/662006#M422448</guid>
      <dc:creator>a.kiprawih</dc:creator>
      <dc:date>2006-11-15T12:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: PIX AAA Enable Local not working</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-aaa-enable-local-not-working/m-p/662007#M422449</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Strange one this, I tried the aaa authen enable cons LOCAL also and it wouldn't let me get into enable.  However, when I removed AAA for enable altogether it worked using the local enable password!&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Nov 2006 13:48:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-aaa-enable-local-not-working/m-p/662007#M422449</guid>
      <dc:creator>brian.oflynn</dc:creator>
      <dc:date>2006-11-15T13:48:04Z</dc:date>
    </item>
    <item>
      <title>Re: PIX AAA Enable Local not working</title>
      <link>https://community.cisco.com/t5/network-access-control/pix-aaa-enable-local-not-working/m-p/662008#M422450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just test it by removing the "aaa authentication enable console LOCAL".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the console, I can't get to enable mode. But you can do this if yo type 'login' where you need to use local user account (mine with priv 15).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Else, after logging in using the above (login) method, change the enable password to a new one. Exit from the priv mode (#), then type enable. Use the new password to get to the enable mode. It should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And if I put back the "aaa authentication enable console LOCAL", I can login using my local account again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;AK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Nov 2006 14:43:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/pix-aaa-enable-local-not-working/m-p/662008#M422450</guid>
      <dc:creator>a.kiprawih</dc:creator>
      <dc:date>2006-11-15T14:43:00Z</dc:date>
    </item>
  </channel>
</rss>

