<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 15.2(7)E10 not using named authorization list on console in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/15-2-7-e10-not-using-named-authorization-list-on-console/m-p/5161631#M591246</link>
    <description>&lt;P&gt;AAA authorization is disabled on the console by default. If AAA authorization is enabled on the console, disable it by configuring the &lt;STRONG&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;no aaa authorization console &lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/STRONG&gt; command during the AAA configuration stage. AAA should be disabled on the console for user authentication.&lt;/P&gt;
&lt;P&gt;The logs also tells that it is looking for enable password but none is configured.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="lia-code-sample  language-markup"&gt;&lt;CODE&gt;ug 15 13:45:49.876: AAA/AUTHEN/START (1746517121): console enable - default to enable password (if any)
Aug 15 13:45:49.876: AAA/AUTHEN/START (1746517121): Method=ENABLE
Aug 15 13:45:49.876: AAA/AUTHEN(1746517121): can't find any passwords
Aug 15 13:45:49.876: AAA/AUTHEN (1746517121): status = ERROR&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 16 Aug 2024 03:45:09 GMT</pubDate>
    <dc:creator>poongarg</dc:creator>
    <dc:date>2024-08-16T03:45:09Z</dc:date>
    <item>
      <title>15.2(7)E10 not using named authorization list on console</title>
      <link>https://community.cisco.com/t5/network-access-control/15-2-7-e10-not-using-named-authorization-list-on-console/m-p/5161576#M591240</link>
      <description>&lt;P&gt;I configured a 2960x not to require authentication on the console port.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;aaa authentication login NoPassword none
line con 0
 exec-timeout 0 0
 privilege level 15
 login authentication NoPassword
 stopbits 1&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But on firmware version&amp;nbsp;15.2(7)E10 if I also have the default authorization policy (see below) I cannot connect via console. I get the error "&lt;FONT face="terminal,monaco"&gt;% Authorization failed.&lt;/FONT&gt;". But on&amp;nbsp;15.2(7)E7 it does work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;aaa authorization exec default local &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Furthermore, I created a new aaa authorization policy with none and applied it on the line and it still not working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;aaa authentication login NoPassword none
aaa authorization console
aaa authorization exec NoPassword none
line con 0
 exec-timeout 0 0
 authorization exec NoPassword
 login authentication NoPassword
 stopbits 1&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Debug aaa authorization shows that the switch is somehow still using the default list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Aug 15 16:32:57.000: AAA/BIND(00000022): Bind i/f
Aug 15 16:32:57.000: AAA/AUTHEN/LOGIN (00000022): Pick method list 'NoPassword'
Aug 15 16:32:57.000: AAA/AUTHOR (0x22): Pick method list 'default'
Aug 15 16:32:57.000: AAA/AUTHOR/EXEC(00000022): Authorization FAILED&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;On&amp;nbsp;15.2(7)E7 we can the authentication flow doesn't touch the authorization policy at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Aug 15 13:37:43.088: AAA/BIND(00000014): Bind i/f
Aug 15 13:37:43.088: AAA/AUTHEN/LOGIN (00000014): Pick method list 'NoPassword'&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I remove the default authorization entry the console login flow on 15.2(7)E10 looks like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Aug 15 16:43:04.517: AAA/BIND(00000025): Bind i/f
Aug 15 16:43:04.520: AAA/AUTHEN/LOGIN (00000025): Pick method list 'NoPassword'
Aug 15 16:43:04.520: AAA/AUTHOR (00000025): Method list id=0 not configured. Skip author
Aug 15 16:43:12.661: AAA/AUTHOR: auth_need : user= '' ruser= '&amp;lt;&amp;gt;'rem_addr= '127.0.0.5' priv= 0 list= '' AUTHOR-TYPE= 'commands'
Aug 15 16:43:12.661: AAA: parse name=tty2 idb type=-1 tty=-1
Aug 15 16:43:12.661: AAA: name=tty2 flags=0x11 type=5 shelf=0 slot=0 adapter=0 port=2 channel=0
Aug 15 16:43:12.661: AAA/MEMORY: create_user (0xEEFF104) user='NULL' ruser='NULL' ds0=0 port='tty2' rem_addr='127.0.0.5' authen_type=ASCII service=ENABLE priv=15 initial_task_id='0', vrf= (id=0)
Aug 15 16:43:12.661: AAA/AUTHEN/START (1151806892): port='tty2' list='' action=LOGIN service=ENABLE
Aug 15 16:43:12.661: AAA/AUTHEN/START (1151806892): console enable - default to enable password (if any)
Aug 15 16:43:12.661: AAA/AUTHEN/START (1151806892): Method=ENABLE
Aug 15 16:43:12.661: AAA/AUTHEN(1151806892): can't find any passwords
Aug 15 16:43:12.661: AAA/AUTHEN (1151806892): status = ERROR
Aug 15 16:43:12.661: AAA/AUTHEN/START (1151806892): Method=NONE
Aug 15 16:43:12.661: AAA/AUTHEN (1151806892): status = PASS
Aug 15 16:43:12.661: AAA/MEMORY: free_user (0xEEFF104) user='NULL' ruser='NULL' port='tty2' rem_addr='127.0.0.5' authen_type=ASCII service=ENABLE priv=15 vrf= (id=0)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;But on&amp;nbsp;15.2(7)E7 it looks like this&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Aug 15 13:45:44.052: AAA/BIND(00000017): Bind i/f
Aug 15 13:45:44.052: AAA/AUTHEN/LOGIN (00000017): Pick method list 'NoPassword'
Aug 15 13:45:49.872: AAA: parse name=tty0 idb type=-1 tty=-1
Aug 15 13:45:49.872: AAA: name=tty0 flags=0x11 type=4 shelf=0 slot=0 adapter=0 port=0 channel=0
Aug 15 13:45:49.872: AAA/MEMORY: create_user (0xC60F7EC) user='NULL' ruser='NULL' ds0=0 port='tty0' rem_addr='async' authen_type=ASCII service=ENABLE priv=15 initial_task_id='0', vrf= (id=0)
Aug 15 13:45:49.876: AAA/AUTHEN/START (1746517121): port='tty0' list='' action=LOGIN service=ENABLE
Aug 15 13:45:49.876: AAA/AUTHEN/START (1746517121): console enable - default to enable password (if any)
Aug 15 13:45:49.876: AAA/AUTHEN/START (1746517121): Method=ENABLE
Aug 15 13:45:49.876: AAA/AUTHEN(1746517121): can't find any passwords
Aug 15 13:45:49.876: AAA/AUTHEN (1746517121): status = ERROR
Aug 15 13:45:49.876: AAA/AUTHEN/START (1746517121): Method=NONE
Aug 15 13:45:49.876: AAA/AUTHEN (1746517121): status = PASS
Aug 15 13:45:49.876: AAA/MEMORY: free_user (0xC60F7EC) user='NULL' ruser='NULL' port='tty0' rem_addr='async' authen_type=ASCII service=ENABLE priv=15 vrf= (id=0)&lt;/LI-CODE&gt;</description>
      <pubDate>Thu, 15 Aug 2024 21:45:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/15-2-7-e10-not-using-named-authorization-list-on-console/m-p/5161576#M591240</guid>
      <dc:creator>Breathing</dc:creator>
      <dc:date>2024-08-15T21:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: 15.2(7)E10 not using named authorization list on console</title>
      <link>https://community.cisco.com/t5/network-access-control/15-2-7-e10-not-using-named-authorization-list-on-console/m-p/5161585#M591241</link>
      <description>&lt;P&gt;&lt;STRONG&gt;aaa authorization console &amp;lt;&amp;lt;- add this command and check authz&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;MHM&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 22:27:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/15-2-7-e10-not-using-named-authorization-list-on-console/m-p/5161585#M591241</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-08-15T22:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: 15.2(7)E10 not using named authorization list on console</title>
      <link>https://community.cisco.com/t5/network-access-control/15-2-7-e10-not-using-named-authorization-list-on-console/m-p/5161621#M591245</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp;thank you, but I already added that command prior to posting here (see my third code block).&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 02:16:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/15-2-7-e10-not-using-named-authorization-list-on-console/m-p/5161621#M591245</guid>
      <dc:creator>Breathing</dc:creator>
      <dc:date>2024-08-16T02:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: 15.2(7)E10 not using named authorization list on console</title>
      <link>https://community.cisco.com/t5/network-access-control/15-2-7-e10-not-using-named-authorization-list-on-console/m-p/5161631#M591246</link>
      <description>&lt;P&gt;AAA authorization is disabled on the console by default. If AAA authorization is enabled on the console, disable it by configuring the &lt;STRONG&gt;&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;no aaa authorization console &lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/STRONG&gt; command during the AAA configuration stage. AAA should be disabled on the console for user authentication.&lt;/P&gt;
&lt;P&gt;The logs also tells that it is looking for enable password but none is configured.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="lia-code-sample  language-markup"&gt;&lt;CODE&gt;ug 15 13:45:49.876: AAA/AUTHEN/START (1746517121): console enable - default to enable password (if any)
Aug 15 13:45:49.876: AAA/AUTHEN/START (1746517121): Method=ENABLE
Aug 15 13:45:49.876: AAA/AUTHEN(1746517121): can't find any passwords
Aug 15 13:45:49.876: AAA/AUTHEN (1746517121): status = ERROR&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 03:45:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/15-2-7-e10-not-using-named-authorization-list-on-console/m-p/5161631#M591246</guid>
      <dc:creator>poongarg</dc:creator>
      <dc:date>2024-08-16T03:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: 15.2(7)E10 not using named authorization list on console</title>
      <link>https://community.cisco.com/t5/network-access-control/15-2-7-e10-not-using-named-authorization-list-on-console/m-p/5163226#M591303</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/66272"&gt;@poongarg&lt;/a&gt;&amp;nbsp;these lines in the logs are when I did&amp;nbsp;&lt;STRONG&gt;&lt;SPAN class=""&gt;no aaa authorization console and no aaa&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;STRONG&gt;authorization exec default&amp;nbsp;&lt;/STRONG&gt;and &lt;STRONG&gt;I'm actually able to log in&lt;/STRONG&gt; (albeit not in exec mode). If you look further down the logs you can notice it passing authentication&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Aug 15 13:45:49.876: AAA/AUTHEN (1746517121): status = PASS&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Update:&lt;/STRONG&gt;&lt;BR /&gt;This is weird, now on&amp;nbsp;15.2(7)E7 I'm getting the same error.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Update2:&lt;BR /&gt;&lt;/STRONG&gt;I've managed to make it work by adding the below config&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;aaa authorization exec default none
line vty 0 15
priv level 15
line con 0
priv level 15&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This doesn't explain the behavior and the fact that the custom authorization list is ignored, and that I'm getting conflicting results on the same firmware, but it works now so I'll leave it as is.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 14:03:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/15-2-7-e10-not-using-named-authorization-list-on-console/m-p/5163226#M591303</guid>
      <dc:creator>Breathing</dc:creator>
      <dc:date>2024-08-20T14:03:48Z</dc:date>
    </item>
  </channel>
</rss>

