<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No AAA authentication on Console port in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/no-aaa-authentication-on-console-port/m-p/146039#M438018</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;authorization exec no_autho  &amp;lt;--this is your menthod name&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mynul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 10 Jun 2003 22:54:26 GMT</pubDate>
    <dc:creator>mhoda</dc:creator>
    <dc:date>2003-06-10T22:54:26Z</dc:date>
    <item>
      <title>No AAA authentication on Console port</title>
      <link>https://community.cisco.com/t5/network-access-control/no-aaa-authentication-on-console-port/m-p/146036#M438015</link>
      <description>&lt;P&gt;I would like to configure our routers to use our ACS server for authentication and enable authorization for all telnet access but not use the ACS when connected to the console port. I was able to get the router configured so that console username and password access was local. However, when I attempt to go into enable mode from the console port the router still goes after the ACS server for the enble password. How do I get around this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 14:21:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-aaa-authentication-on-console-port/m-p/146036#M438015</guid>
      <dc:creator>jrhofman</dc:creator>
      <dc:date>2019-03-10T14:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: No AAA authentication on Console port</title>
      <link>https://community.cisco.com/t5/network-access-control/no-aaa-authentication-on-console-port/m-p/146037#M438016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You cannot disable enable authentication on the console or create a new method for the console enable authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only option you have is to enable exec authorization on the console and give the priviledged user "priv=15" under shell so that they will not be asked for enable password and dropped into the enable mode directly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Sujit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jun 2003 16:08:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-aaa-authentication-on-console-port/m-p/146037#M438016</guid>
      <dc:creator>sghosh</dc:creator>
      <dc:date>2003-06-10T16:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: No AAA authentication on Console port</title>
      <link>https://community.cisco.com/t5/network-access-control/no-aaa-authentication-on-console-port/m-p/146038#M438017</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm running 12.2.10 code. I don;t see the command for giving enable exec authorization on the console port as an option.  Can you show me an example?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jun 2003 21:30:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-aaa-authentication-on-console-port/m-p/146038#M438017</guid>
      <dc:creator>jrhofman</dc:creator>
      <dc:date>2003-06-10T21:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: No AAA authentication on Console port</title>
      <link>https://community.cisco.com/t5/network-access-control/no-aaa-authentication-on-console-port/m-p/146039#M438018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;authorization exec no_autho  &amp;lt;--this is your menthod name&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mynul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jun 2003 22:54:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-aaa-authentication-on-console-port/m-p/146039#M438018</guid>
      <dc:creator>mhoda</dc:creator>
      <dc:date>2003-06-10T22:54:26Z</dc:date>
    </item>
    <item>
      <title>Re: No AAA authentication on Console port</title>
      <link>https://community.cisco.com/t5/network-access-control/no-aaa-authentication-on-console-port/m-p/146040#M438019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually, this is incorrect.  You need to enable authorization for the console users to drop them automatically into an enable prompt. For example,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username admin privilege 15 password cisco&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login console local&lt;/P&gt;&lt;P&gt;aaa authorization exec console local&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt; login authentication console&lt;/P&gt;&lt;P&gt; authorization exec console&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps...&lt;/P&gt;&lt;P&gt;Marcus&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jun 2003 01:52:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-aaa-authentication-on-console-port/m-p/146040#M438019</guid>
      <dc:creator>msitzman</dc:creator>
      <dc:date>2003-06-11T01:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: No AAA authentication on Console port</title>
      <link>https://community.cisco.com/t5/network-access-control/no-aaa-authentication-on-console-port/m-p/146041#M438020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is not incorrect, I just didn't provide the details of the method list.  Thought, the post is just looking for the command required for exec authorization under the line console.  In your case, you defined the method name console and then apply the same way for the authorization under the console line as I mentioned in my post  &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;   Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mynul &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jun 2003 03:46:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-aaa-authentication-on-console-port/m-p/146041#M438020</guid>
      <dc:creator>mhoda</dc:creator>
      <dc:date>2003-06-11T03:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: No AAA authentication on Console port</title>
      <link>https://community.cisco.com/t5/network-access-control/no-aaa-authentication-on-console-port/m-p/146042#M438021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;--begin ciscomoderator note-- The following post has been edited to remove potentially confidential information. Please refrain from posting confidential information on the site to reduce security risks to your network. -- end ciscomoderator note -- &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks this does help. However, I'm still running into and issue. My ultimate goal is to have all users authenticate and get enable access through our ACS server based on there corporate NT domain username/pw. If the ACS server is unavailable go to the local data base. This is working fine for user telneting to the routers and also works for the console port (if the ACS server is unavailable). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, with the ACS server active, when I console in I authenticate based on the local database admin/cisco. But when I attempt to go into enable mode the router still goes after the ACS server for a password. I would like console port users to always use the local enable password. &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;I'm just trying to protect myself from a possible misbehaved ACS server. &lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;aaa new-model &lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local &lt;/P&gt;&lt;P&gt;aaa authentication login console local &lt;/P&gt;&lt;P&gt;aaa authentication enable default group tacacs+ enable &lt;/P&gt;&lt;P&gt;aaa authorization exec console local &lt;/P&gt;&lt;P&gt;enable secret 5 --moderator edit--&lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;username --moderator edit--privilege 15 password 0 --moderator edit--&lt;/P&gt;&lt;P&gt;! &lt;/P&gt;&lt;P&gt;line con 0 &lt;/P&gt;&lt;P&gt;exec-timeout 300 0 &lt;/P&gt;&lt;P&gt;authorization exec console &lt;/P&gt;&lt;P&gt;login authentication console &lt;/P&gt;&lt;P&gt;line aux 0 &lt;/P&gt;&lt;P&gt;line vty 0 4 &lt;/P&gt;&lt;P&gt;password --moderator edit--&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jun 2003 12:42:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-aaa-authentication-on-console-port/m-p/146042#M438021</guid>
      <dc:creator>jrhofman</dc:creator>
      <dc:date>2003-06-11T12:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: No AAA authentication on Console port</title>
      <link>https://community.cisco.com/t5/network-access-control/no-aaa-authentication-on-console-port/m-p/146043#M438022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With the newer version of  code, by default, authorization on the console is turned off with the "no aaa authorization console" hidden command.  But,  authorization exec console  should take care of that.  Can you please add the following line:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization console &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please lets know the results.  Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mynul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jun 2003 17:30:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-aaa-authentication-on-console-port/m-p/146043#M438022</guid>
      <dc:creator>mhoda</dc:creator>
      <dc:date>2003-06-11T17:30:05Z</dc:date>
    </item>
    <item>
      <title>Re: No AAA authentication on Console port</title>
      <link>https://community.cisco.com/t5/network-access-control/no-aaa-authentication-on-console-port/m-p/146044#M438023</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Works great.  Just what I was looking for.  Thanks for the help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jun 2003 22:21:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-aaa-authentication-on-console-port/m-p/146044#M438023</guid>
      <dc:creator>jrhofman</dc:creator>
      <dc:date>2003-06-12T22:21:47Z</dc:date>
    </item>
    <item>
      <title>Re: No AAA authentication on Console port</title>
      <link>https://community.cisco.com/t5/network-access-control/no-aaa-authentication-on-console-port/m-p/146045#M438024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Perfect! Thanx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Nov 2006 12:52:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/no-aaa-authentication-on-console-port/m-p/146045#M438024</guid>
      <dc:creator>jsteffensen</dc:creator>
      <dc:date>2006-11-15T12:52:40Z</dc:date>
    </item>
  </channel>
</rss>

