<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is the difference between authorisation if-authenticate in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/what-is-the-difference-between-authorisation-if-authenticated/m-p/56548#M6348</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks very much for your detailed work.  I can see the difference in your traces but my real interest is in the different behaviour between if-authenticated and none, not if-authenticated and local.  Since all users are authenticated, there appears to me, no difference between an authorization method of none, and one of if-authenticated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many Thanks&lt;/P&gt;&lt;P&gt;Ian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Nov 2002 11:24:58 GMT</pubDate>
    <dc:creator>ipotts</dc:creator>
    <dc:date>2002-11-08T11:24:58Z</dc:date>
    <item>
      <title>What is the difference between authorisation if-authenticated and none</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-difference-between-authorisation-if-authenticated/m-p/56544#M6344</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am working on a AAA configuration, and can't determine the practical difference between authorisation none and authorisation if-authenticated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I realise the obvious difference, that if TACACS is down, with none there is no authorisation if none is used; and if TACACS is down authorisation will allow all commands if if-authenticated is used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, since you must always be authenticated, before authorisation commences, in practical terms, there is no difference that I can see between if-authenticated and none?  Can anyone please explain if there is a practical difference between them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#####################Authorisation if-authenticated#############&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#####################Authorisation none##################&lt;/P&gt;&lt;P&gt;aaa authorization exec default group tacacs+ none&lt;/P&gt;&lt;P&gt;aaa authorization commands 1 default group tacacs+ none&lt;/P&gt;&lt;P&gt;aaa authorization commands 15 default group tacacs+ none&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many Thanks&lt;/P&gt;&lt;P&gt;Ian Potts&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:04:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-difference-between-authorisation-if-authenticated/m-p/56544#M6344</guid>
      <dc:creator>ipotts</dc:creator>
      <dc:date>2020-02-21T18:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference between authorisation if-authenticate</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-difference-between-authorisation-if-authenticated/m-p/56545#M6345</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want to configure a setup where a user is allowed access to the requested function, if they have been authenticated previously, use the if-authenticated method keyword. With this method in place, authenticated users are allowed access to all requested function.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There may be instances where you might not want to run authorization from a particular interface or line. To disable authorization for all actions associated with a particular type of authentication,  use the none method keyword. The network access server does not request authorization information and authorization is not performed over this line/interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could also refer to the document on Configuring Authorization available at the URL:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/software/ios120/12cgcr/secur_c/scprt1/scathor.htm" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/software/ios120/12cgcr/secur_c/scprt1/scathor.htm&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2002 16:29:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-difference-between-authorisation-if-authenticated/m-p/56545#M6345</guid>
      <dc:creator>bwalchez</dc:creator>
      <dc:date>2002-11-07T16:29:06Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference between authorisation if-authenticate</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-difference-between-authorisation-if-authenticated/m-p/56546#M6346</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your reply.  I may not have explained by question clearly.  I have read the CCO documentation multiple times, but it does not answer my question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is basically that a user is always authenticated.  Therefore using authorization methods of none or if-authenticated are identical.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2002 16:46:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-difference-between-authorisation-if-authenticated/m-p/56546#M6346</guid>
      <dc:creator>ipotts</dc:creator>
      <dc:date>2002-11-07T16:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference between authorisation if-authenticate</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-difference-between-authorisation-if-authenticated/m-p/56547#M6347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One use I can think of is where you have both AAA and local configured for exec or command authorization.  Let's say TACACS+ in the following manner:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization exec default tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username admin password &lt;SNIPPED&gt;&lt;/SNIPPED&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you had this configuration without the "if-authenticated" statement and the connection to the TAC+ server goes down or you receive an ERROR in communicating with it such as a mismatched key, then it goes to local for authentication.  If you did not want to use local authorization and want it to succeed exec authorization for this local account, then the "if-authenticated" statement would be needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check out the debugs with:&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization exec default tacacs+ local&lt;/P&gt;&lt;P&gt;AND the TAC+ server is down&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6d21h: AAA/AUTHOR/EXEC (4150549846): Port='tty2' list='' service=EXEC&lt;/P&gt;&lt;P&gt;6d21h: AAA/AUTHOR/EXEC:  (4150549846) user='admin'&lt;/P&gt;&lt;P&gt;6d21h: AAA/AUTHOR/EXEC:  (4150549846) send AV service=shell&lt;/P&gt;&lt;P&gt;6d21h: AAA/AUTHOR/EXEC:  (4150549846) send AV cmd*&lt;/P&gt;&lt;P&gt;6d21h: AAA/AUTHOR/EXEC (4150549846) found list "default"&lt;/P&gt;&lt;P&gt;6d21h: AAA/AUTHOR/EXEC:  (4150549846) Method=TACACS+&lt;/P&gt;&lt;P&gt;6d21h: AAA/AUTHOR/TAC+: (4150549846): user=admin&lt;/P&gt;&lt;P&gt;6d21h: AAA/AUTHOR/TAC+: (4150549846): send AV service=shell&lt;/P&gt;&lt;P&gt;6d21h: AAA/AUTHOR/TAC+: (4150549846): send AV cmd*&lt;/P&gt;&lt;P&gt;core7200-4#&lt;/P&gt;&lt;P&gt;6d21h: AAA/AUTHOR (4150549846): Post authorization status = ERROR&lt;/P&gt;&lt;P&gt;6d21h: AAA/AUTHOR/EXEC:  (4150549846) Method=NOT_SET&lt;/P&gt;&lt;P&gt;6d21h: AAA/AUTHOR/EXEC:  (4150549846) no methods left to try&lt;/P&gt;&lt;P&gt;6d21h: AAA/AUTHOR (4150549846): Post authorization status = FAIL&lt;/P&gt;&lt;P&gt;6d21h: AAA/AUTHOR/EXEC: Authorization FAILED&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOTE, Post authorization fails because there is no method set for EXEC for the local user.  Now, put in "if-authenticated" and test again:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login default tacacs+ local&lt;/P&gt;&lt;P&gt;aaa authorization exec default tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6d22h: AAA/AUTHOR/EXEC (2893174055): Port='tty2' list='' service=EXEC&lt;/P&gt;&lt;P&gt;6d22h: AAA/AUTHOR/EXEC:  (2893174055) user='admin'&lt;/P&gt;&lt;P&gt;6d22h: AAA/AUTHOR/EXEC:  (2893174055) send AV service=shell&lt;/P&gt;&lt;P&gt;6d22h: AAA/AUTHOR/EXEC:  (2893174055) send AV cmd*&lt;/P&gt;&lt;P&gt;6d22h: AAA/AUTHOR/EXEC (2893174055) found list "default"&lt;/P&gt;&lt;P&gt;6d22h: AAA/AUTHOR/EXEC:  (2893174055) Method=TACACS+&lt;/P&gt;&lt;P&gt;6d22h: AAA/AUTHOR/TAC+: (2893174055): user=admin&lt;/P&gt;&lt;P&gt;6d22h: AAA/AUTHOR/TAC+: (2893174055): send AV service=shell&lt;/P&gt;&lt;P&gt;6d22h: AAA/AUTHOR/TAC+: (2893174055): send AV cmd*&lt;/P&gt;&lt;P&gt;6d22h: AAA/AUTHOR (2893174055): Post authorization status = ERROR&lt;/P&gt;&lt;P&gt;6d22h: AAA/AUTHOR/EXEC:  (2893174055) Method=IF_AUTHEN&lt;/P&gt;&lt;P&gt;6d22h: AAA/AUTHOR (2893174055): Post authorization status = PASS_ADD&lt;/P&gt;&lt;P&gt;6d22h: AAA/AUTHOR/EXEC: Authorization successful&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note, the Post authorization passes because of IF_AUTHEN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See the behavior?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Nov 2002 17:29:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-difference-between-authorisation-if-authenticated/m-p/56547#M6347</guid>
      <dc:creator>4brown</dc:creator>
      <dc:date>2002-11-07T17:29:23Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference between authorisation if-authenticate</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-difference-between-authorisation-if-authenticated/m-p/56548#M6348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks very much for your detailed work.  I can see the difference in your traces but my real interest is in the different behaviour between if-authenticated and none, not if-authenticated and local.  Since all users are authenticated, there appears to me, no difference between an authorization method of none, and one of if-authenticated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many Thanks&lt;/P&gt;&lt;P&gt;Ian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Nov 2002 11:24:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-difference-between-authorisation-if-authenticated/m-p/56548#M6348</guid>
      <dc:creator>ipotts</dc:creator>
      <dc:date>2002-11-08T11:24:58Z</dc:date>
    </item>
    <item>
      <title>What is the difference between authorisation if-authenticated an</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-difference-between-authorisation-if-authenticated/m-p/56549#M6350</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no much difference IMO as normally people will use "enable" as fallback authentication motheod, which means a user can always be authenticated when loss of Tacacs servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually I find on some IOS the devices doesn't support "none" keyword at all, while on some other IOS the "if-authenticated" doesn't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think Cisco dev just screwed this by complicating the fallback methods.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which can win the race: increasing bandwidth with new technologies VS QoS?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 May 2013 00:21:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-difference-between-authorisation-if-authenticated/m-p/56549#M6350</guid>
      <dc:creator>networkguy13111</dc:creator>
      <dc:date>2013-05-08T00:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: What is the difference between authorisation if-authenticate</title>
      <link>https://community.cisco.com/t5/network-access-control/what-is-the-difference-between-authorisation-if-authenticated/m-p/4468618#M569782</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;authorization methods of none or if-authenticated ---&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;If you go "authorization none" you are basically stating that any person that authenticates&amp;nbsp; has all privileges&amp;nbsp;to do everything.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if you go if-authenticated, then you are allowed to have the privileges granted by&amp;nbsp;authorization without checking the remote tacacs server for each command that you enter to see if its authorized.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if you go authoritzation methods group tacacs: then each command will be require an answer from the tacacs server as to whether or not the command is authorized to the user. This can actually create quite a noticeable lag on WAN links. Think about each command before executed has to be communicated with tacacs server and then responded to before the command will 'take" and then execute.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Therefore the if-authenticated go ahead an authorize at his login level is preferred, and&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if you are not running a varied privledge level environment then authrorization method none becomes a very good option.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Sep 2021 16:58:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/what-is-the-difference-between-authorisation-if-authenticated/m-p/4468618#M569782</guid>
      <dc:creator>jpflory01</dc:creator>
      <dc:date>2021-09-17T16:58:55Z</dc:date>
    </item>
  </channel>
</rss>

