<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Backup AAA for PIX in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/backup-aaa-for-pix/m-p/180679#M436824</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no backup authorization method for the PIX.  As you're aware, if the TACACS server is down you can login with "pix" and the enable password, but that doesn't help for authorization.  The only thing you can do is wait for the TACACS server to come back up.  Sorry.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 21 Apr 2003 23:43:29 GMT</pubDate>
    <dc:creator>gfullage</dc:creator>
    <dc:date>2003-04-21T23:43:29Z</dc:date>
    <item>
      <title>Backup AAA for PIX</title>
      <link>https://community.cisco.com/t5/network-access-control/backup-aaa-for-pix/m-p/180678#M436823</link>
      <description>&lt;P&gt;I have a PIX with the following configuration:&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ (inside) host 192.168.1.1 77777 timeout 5&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius&lt;/P&gt;&lt;P&gt;aaa-server RADIUS (inside) host 192.168.1.1 77777 timeout 10&lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local&lt;/P&gt;&lt;P&gt;aaa authentication serial console TACACS+&lt;/P&gt;&lt;P&gt;aaa authentication enable console TACACS+&lt;/P&gt;&lt;P&gt;aaa authorization command TACACS+&lt;/P&gt;&lt;P&gt;aaa accounting match aaa_acl inside RADIUS&lt;/P&gt;&lt;P&gt;Everything works fine when the TACACS server is available.  When it is not available, I can login with the username "PIX" and "password" just fine.  The problem is, once I've logged in, I cannot get proper authorization to perform any commands.  Does anyone know of a command similar to the "if-authenticated" for routers that I can use?&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:15:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/backup-aaa-for-pix/m-p/180678#M436823</guid>
      <dc:creator>collinss</dc:creator>
      <dc:date>2019-03-10T14:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: Backup AAA for PIX</title>
      <link>https://community.cisco.com/t5/network-access-control/backup-aaa-for-pix/m-p/180679#M436824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no backup authorization method for the PIX.  As you're aware, if the TACACS server is down you can login with "pix" and the enable password, but that doesn't help for authorization.  The only thing you can do is wait for the TACACS server to come back up.  Sorry.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Apr 2003 23:43:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/backup-aaa-for-pix/m-p/180679#M436824</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2003-04-21T23:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: Backup AAA for PIX</title>
      <link>https://community.cisco.com/t5/network-access-control/backup-aaa-for-pix/m-p/180680#M436825</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's what I was afraid of.  Thanks for the help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2003 11:03:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/backup-aaa-for-pix/m-p/180680#M436825</guid>
      <dc:creator>collinss</dc:creator>
      <dc:date>2003-04-22T11:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: Backup AAA for PIX</title>
      <link>https://community.cisco.com/t5/network-access-control/backup-aaa-for-pix/m-p/180681#M436826</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;i cann´t get tihs commad througth my PIX 535: Authorization and Accounting&lt;/P&gt;&lt;P&gt;------------------------------------------------------&lt;/P&gt;&lt;P&gt;TKFW101(config)# aaa authorization command acs1&lt;/P&gt;&lt;P&gt;service must be: "telnet", "ftp", "http", "tcp/0", "none", or "tcp/###"&lt;/P&gt;&lt;P&gt;Type help or '?' for a list of available commands.&lt;/P&gt;&lt;P&gt;TKFW101(config)# &lt;/P&gt;&lt;P&gt;----------------------&lt;/P&gt;&lt;P&gt;how dit you get it on your PIX ? i am running pix 0s 6.1(4)&lt;/P&gt;&lt;P&gt;thanks for any  help&lt;/P&gt;&lt;P&gt;AE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Apr 2003 14:15:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/backup-aaa-for-pix/m-p/180681#M436826</guid>
      <dc:creator>aessome</dc:creator>
      <dc:date>2003-04-28T14:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: Backup AAA for PIX</title>
      <link>https://community.cisco.com/t5/network-access-control/backup-aaa-for-pix/m-p/180682#M436827</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On version 6.1.4, you don't have the command authorization option.  Thats why you are unable to enter it.  It was first introduced in 6.2 code.  Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mynul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 May 2003 21:22:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/backup-aaa-for-pix/m-p/180682#M436827</guid>
      <dc:creator>mhoda</dc:creator>
      <dc:date>2003-05-15T21:22:20Z</dc:date>
    </item>
  </channel>
</rss>

