<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Very Simple AAA Question for AAA gurus in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/very-simple-aaa-question-for-aaa-gurus/m-p/297886#M434949</link>
    <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anybody know why authentication always succeeds if I login to a router as "any_nonexistent_user" with the following config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login test local none&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; login authentication test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and doesn't succeed with the following config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login test group tacacs+ none&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; login authentication test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The user "any_nonexistent_user" really doesn't exist &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; in the local database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this behaviour contradict the documentation: "The additional methods of authentication are used only if the previous method returns an error, not if it fails".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Oleg Tipisov,&lt;/P&gt;&lt;P&gt;REDCENTER,&lt;/P&gt;&lt;P&gt;Moscow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 14:38:12 GMT</pubDate>
    <dc:creator>ovt</dc:creator>
    <dc:date>2019-03-10T14:38:12Z</dc:date>
    <item>
      <title>Very Simple AAA Question for AAA gurus</title>
      <link>https://community.cisco.com/t5/network-access-control/very-simple-aaa-question-for-aaa-gurus/m-p/297886#M434949</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anybody know why authentication always succeeds if I login to a router as "any_nonexistent_user" with the following config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login test local none&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; login authentication test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and doesn't succeed with the following config:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login test group tacacs+ none&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; login authentication test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The user "any_nonexistent_user" really doesn't exist &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; in the local database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this behaviour contradict the documentation: "The additional methods of authentication are used only if the previous method returns an error, not if it fails".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Oleg Tipisov,&lt;/P&gt;&lt;P&gt;REDCENTER,&lt;/P&gt;&lt;P&gt;Moscow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:38:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/very-simple-aaa-question-for-aaa-gurus/m-p/297886#M434949</guid>
      <dc:creator>ovt</dc:creator>
      <dc:date>2019-03-10T14:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: Very Simple AAA Question for AAA gurus</title>
      <link>https://community.cisco.com/t5/network-access-control/very-simple-aaa-question-for-aaa-gurus/m-p/297887#M434951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have witnessed this same behavior.  It appears that the "local" auth type is an exception to the rule.  If the user does not exist in the local list, then the next method is tried.  This is not the case with tacacs or radius.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Jan 2004 17:30:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/very-simple-aaa-question-for-aaa-gurus/m-p/297887#M434951</guid>
      <dc:creator>d.parks</dc:creator>
      <dc:date>2004-01-20T17:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: Very Simple AAA Question for AAA gurus</title>
      <link>https://community.cisco.com/t5/network-access-control/very-simple-aaa-question-for-aaa-gurus/m-p/297888#M434952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you look at this web site:&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/iosswrel/ps1835/products_command_reference_chapter09186a00800c6c62.html#1017794" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/iosswrel/ps1835/products_command_reference_chapter09186a00800c6c62.html#1017794&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and read this sample info: &lt;/P&gt;&lt;P&gt;The following example creates an AAA authentication list called MIS-access. This authentication first tries to contact a TACACS+ server. If no server is found, TACACS+ returns an error and AAA tries to use the enable password. If this attempt also returns an error (because no enable password is configured on the server), the user is allowed access with no authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication login MIS-access group tacacs+ enable none &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will see that using the work 'none' will authenticate a user without requiring authentication&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Feb 2004 19:35:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/very-simple-aaa-question-for-aaa-gurus/m-p/297888#M434952</guid>
      <dc:creator>jay.silveus</dc:creator>
      <dc:date>2004-02-10T19:35:20Z</dc:date>
    </item>
  </channel>
</rss>

