<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA authentication login default command in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023364#M587614</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1474290"&gt;@117222400&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;that is the order of authentication, so local happens first and if the account is not found locally then use ISE to authenticate.&lt;/P&gt;</description>
    <pubDate>Fri, 23 Feb 2024 11:31:25 GMT</pubDate>
    <dc:creator>Ruben Cocheno</dc:creator>
    <dc:date>2024-02-23T11:31:25Z</dc:date>
    <item>
      <title>AAA authentication login default command</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023355#M587612</link>
      <description>&lt;P&gt;Hi Experts&lt;/P&gt;&lt;P&gt;Recently we upgraded Catalyst c9200-48P to 17.9.04a which is the recommended version.&lt;/P&gt;&lt;P&gt;But the strange is that it seems the radius authentication failed when login to SSH by Putty.&lt;/P&gt;&lt;P&gt;Before upgrade, it is working, when login by an AD account, it prompts below and works good. Also the local user is also working good.&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic"&gt;Using username "domainadm".&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="batang,apple gothic"&gt;Keyboard-interactive authentication prompts from server:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="batang,apple gothic"&gt;| Password: &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="batang,apple gothic"&gt;End of keyboard-interactive prompts from server&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;After upgrade, it didn't prompt, just like below, and also the password is incorrect and login failed.&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic"&gt;Using username "domainadm".&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="batang,apple gothic"&gt;domainadm@10.2.5.7's password:&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;But if I use a local user to login, it prompts and I can use the local username and password to login.&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic"&gt;login as: SFnet&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="batang,apple gothic"&gt;Keyboard-interactive authentication prompts from server:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="batang,apple gothic"&gt;| Password: &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="batang,apple gothic"&gt;End of keyboard-interactive prompts from server&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;There isn't any change about the aaa authentication configurations. And both radius user login and local user login are good working before upgrade.&lt;/P&gt;&lt;P&gt;&lt;FONT face="batang,apple gothic"&gt;aaa authentication login default local group SF_CISCO_ISE&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="batang,apple gothic"&gt;aaa authentication dot1x default group SF_CISCO_ISE&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="batang,apple gothic"&gt;aaa authorization exec default local group SF_CISCO_ISE &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="batang,apple gothic"&gt;aaa authorization network default group SF_CISCO_ISE &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="batang,apple gothic"&gt;aaa accounting update newinfo periodic 2880&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="batang,apple gothic"&gt;aaa accounting dot1x default start-stop group SF_CISCO_ISE&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="batang,apple gothic"&gt;aaa accounting exec default start-stop group SF_CISCO_ISE&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="batang,apple gothic"&gt;aaa accounting network default start-stop group SF_CISCO_ISE&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="batang,apple gothic"&gt;aaa accounting connection default start-stop group SF_CISCO_ISE&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="batang,apple gothic"&gt;aaa accounting system default start-stop group SF_CISCO_ISE&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also I am a little confused about the command :&amp;nbsp;&lt;FONT face="batang,apple gothic"&gt;aaa authentication login default local group SF_CISCO_ISE ,&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Why it allows both local user and the radius user as default? how 2x defaults? who has higher priority?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;And the prompts: &lt;FONT face="batang,apple gothic"&gt;Keyboard-interactive authentication prompts from server:&amp;nbsp;&lt;FONT face="arial,helvetica,sans-serif"&gt;Is it for radius users only? or for all users?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;FONT face="batang,apple gothic"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;What configurations should I check? or is there a bug ?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;FONT face="batang,apple gothic"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Thanks&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;FONT face="batang,apple gothic"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;Best regards&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;&lt;FONT face="batang,apple gothic"&gt;&lt;FONT face="arial,helvetica,sans-serif"&gt;George&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 11:04:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023355#M587612</guid>
      <dc:creator>117222400</dc:creator>
      <dc:date>2024-02-23T11:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication login default command</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023363#M587613</link>
      <description>&lt;P&gt;can I see radius server config in SW&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 11:30:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023363#M587613</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-02-23T11:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication login default command</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023364#M587614</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1474290"&gt;@117222400&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;that is the order of authentication, so local happens first and if the account is not found locally then use ISE to authenticate.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 11:31:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023364#M587614</guid>
      <dc:creator>Ruben Cocheno</dc:creator>
      <dc:date>2024-02-23T11:31:25Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication login default command</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023367#M587615</link>
      <description>&lt;P&gt;I was looking at the same thing. The line "aaa authentication login default local group SF_CISCO_ISE" should be changed imo to this:&lt;/P&gt;
&lt;P&gt;aaa authentication login default group SF_CISCO_ISE local&lt;/P&gt;
&lt;P&gt;The keyword default in that line refers to the default method list, think about it as a name rather than as a default setting.&lt;/P&gt;
&lt;P&gt;When you place the "local" keyword at the end it means the switch will try first to authenticate the users via RADIUS, and only if RADIUS server is unavailable it will then authenticate the users against the local database.&lt;/P&gt;
&lt;P&gt;I think the keyboard interactive message is applicable to any connection to the switch, and I believe the keyword "server" in that message refers to the switch itself not to the RADIUS server.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 11:35:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023367#M587615</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-02-23T11:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication login default command</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023372#M587616</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1474290"&gt;@117222400&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;the correct way to configure this is&amp;nbsp;&lt;STRONG&gt;aaa authentication login default group SF_CISCO_ISE&amp;nbsp;local&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The rule is as follows: the device tries the first authentication method, in your case local, and IF that method is&amp;nbsp;&lt;/SPAN&gt;unavailable, that is not responsive, it goes to the second method - ISE server.&lt;/P&gt;
&lt;P&gt;In case one of the method responds that it doesn't know the user or the password is incorrect, it DOESN'T go the check other methods.&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 11:41:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023372#M587616</guid>
      <dc:creator>liviu.gheorghe</dc:creator>
      <dc:date>2024-02-23T11:41:04Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication login default command</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023374#M587617</link>
      <description>&lt;P&gt;Thanks for your reply, and the below is radius config:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa group server radius SF_CISCO_ISE&lt;BR /&gt;server name SF3-ISE01&lt;BR /&gt;server name SF4-ISE01&lt;BR /&gt;ip radius source-interface Loopback0&lt;BR /&gt;timeout 30&lt;/P&gt;&lt;P&gt;radius server SF3-ISE01&lt;BR /&gt;address ipv4 10.2.5.33 auth-port 1812 acct-port 1813&lt;BR /&gt;key 7 073B746A4D2C4C2439391A261133077020&lt;BR /&gt;!&lt;BR /&gt;radius server SF4-ISE01&lt;BR /&gt;address ipv4 10.2.20.33 auth-port 1812 acct-port 1813&lt;BR /&gt;key 7 046F5E200C04196F2732143D0712205022&lt;BR /&gt;!&lt;BR /&gt;!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 11:44:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023374#M587617</guid>
      <dc:creator>117222400</dc:creator>
      <dc:date>2024-02-23T11:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication login default command</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023388#M587618</link>
      <description>&lt;P&gt;Thanks Aref and Liviu&lt;/P&gt;&lt;P&gt;I have only one local user SFnet on the SW, so if it is a method list, then put "local" in the front might be faster response.&lt;/P&gt;&lt;P&gt;But still not sure why it didn't prompt message and can't log in by the AD user, should I check something on the ISE (radius server) or change the key to re-connect the ISE?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 11:55:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023388#M587618</guid>
      <dc:creator>117222400</dc:creator>
      <dc:date>2024-02-23T11:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication login default command</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023392#M587619</link>
      <description>&lt;P&gt;Putting "local" before the RADIUS group would allow the switch to check the local users database first, and if the user is not found locally, it will "fall-back" to the RADIUS group. I don't believe there is nothing to be changed on ISE. One thing you can do is enabling aaa authentication debugs "deb aaa authentication" and see if the output gives anything interesting.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 12:10:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023392#M587619</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-02-23T12:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication login default command</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023394#M587620</link>
      <description>&lt;P&gt;The ideea îs that the local authentication method is always available, so if you don't have the user you are trying to authenticate defined on the local switch, domainadm, it won't go to the second method -&amp;nbsp;&lt;SPAN&gt;SF_CISCO_ISE.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;That is the reason we suggested putting the group&amp;nbsp;SF_CISCO_ISE first and local second.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 12:13:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023394#M587620</guid>
      <dc:creator>liviu.gheorghe</dc:creator>
      <dc:date>2024-02-23T12:13:27Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication login default command</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023395#M587621</link>
      <description>&lt;P&gt;This behavior explains by one statement&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Aaa new-model&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Command is missing after upgrading&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why the local can access?&lt;/P&gt;
&lt;P&gt;I think this is defualt for vty line.&lt;/P&gt;
&lt;P&gt;So check aaa&amp;nbsp; new-model command&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 12:27:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023395#M587621</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-02-23T12:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication login default command</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023400#M587622</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArefAlsouqi_0-1708691591635.png" style="width: 1024px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/210932iE67C4AB53008A549/image-dimensions/1024x279?v=v2" width="1024" height="279" role="button" title="ArefAlsouqi_0-1708691591635.png" alt="ArefAlsouqi_0-1708691591635.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security-vpn/terminal-access-controller-access-control-system-tacacs-/200606-aaa-authentication-login-default-local.html" target="_blank"&gt;Understanding an AAA Authentication Command on a Cisco IOS Device - Cisco&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Same concept applies for RADIUS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 12:33:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023400#M587622</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2024-02-23T12:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: AAA authentication login default command</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023415#M587625</link>
      <description>&lt;P&gt;I stand corrected - if user is not present in local database, it will go to the next authentication method.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 13:04:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-authentication-login-default-command/m-p/5023415#M587625</guid>
      <dc:creator>liviu.gheorghe</dc:creator>
      <dc:date>2024-02-23T13:04:20Z</dc:date>
    </item>
  </channel>
</rss>

