<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA killed my reverse telnet in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/aaa-killed-my-reverse-telnet/m-p/62821#M858</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Take a look at this line:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization reverse-access &lt;/P&gt;&lt;P&gt;default local group radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May want to change it to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization reverse-access &lt;/P&gt;&lt;P&gt;radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A good link on this is below:&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/software/ios120/12cgcr/secur_r/srprt1/srauth.htm#xtocid1560415" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/software/ios120/12cgcr/secur_r/srprt1/srauth.htm#xtocid1560415&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 13 May 2002 13:03:25 GMT</pubDate>
    <dc:creator>mmellet</dc:creator>
    <dc:date>2002-05-13T13:03:25Z</dc:date>
    <item>
      <title>AAA killed my reverse telnet</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-killed-my-reverse-telnet/m-p/62820#M857</link>
      <description>&lt;P&gt;I am trying to allow my users to reverse telnet to a US Robotics Sportster 56K modem which is connected to the auxilary port of a Cisco 1710.   First I want them to authenticate either the local or radius user databases.  I have been able to reverse telnet into the modem using the configuration listed below if I disable the aaa new-model and telnet in without authentication.  I have preformed debugging on AAA Authentication and AAA Authorization and only receive this output while attempting to authenticate:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;02:55:33: AAA/AUTHEN/LOGIN (00000025): Pick method list 'default'&lt;/P&gt;&lt;P&gt;02:55:39: AAA/AUTHOR/CONN(00000025): Authorization FAILED for tty5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At which point I will get a message stating that my connection has been closed by foreign host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The same local user account works fine when attempting to telnet to a vty port in EXEC mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also attempted to set all the aaa defaults none so that no authentication takes place and it still terminates my connections in the same way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Additionally in posibly a related issue when I do a "show user" the user field is blank.  On other routers I have done this with it shows the name of the user that is logged onto the port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FYI - This configuration is a work in progress there are some things such as radius client configurations that I have not yet configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;version 12.2&lt;/P&gt;&lt;P&gt;no parser cache&lt;/P&gt;&lt;P&gt;no service single-slot-reload-enable&lt;/P&gt;&lt;P&gt;service timestamps debug uptime&lt;/P&gt;&lt;P&gt;service timestamps log uptime&lt;/P&gt;&lt;P&gt;service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname mycisco1710&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;logging rate-limit console 10 except errors&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication login default local group radius&lt;/P&gt;&lt;P&gt;aaa authentication ppp default local group radius&lt;/P&gt;&lt;P&gt;aaa authorization exec default local group radius&lt;/P&gt;&lt;P&gt;aaa authorization network default local group radius&lt;/P&gt;&lt;P&gt;aaa authorization reverse-access default local group radius&lt;/P&gt;&lt;P&gt;aaa session-id common&lt;/P&gt;&lt;P&gt;enable secret 5 XXXXXXXXXXXXXXX&lt;/P&gt;&lt;P&gt;enable password 7 XXXXXXXXXXXXXXX&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;username test password 7 XXXXXXXXXXXXXXXX&lt;/P&gt;&lt;P&gt;memory-size iomem 20&lt;/P&gt;&lt;P&gt;mmi polling-interval 60&lt;/P&gt;&lt;P&gt;no mmi auto-configure&lt;/P&gt;&lt;P&gt;no mmi pvc&lt;/P&gt;&lt;P&gt;mmi snmp-timeout 180&lt;/P&gt;&lt;P&gt;ip subnet-zero&lt;/P&gt;&lt;P&gt;no ip routing&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip host modem 2005 140.188.164.47&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip audit notify log&lt;/P&gt;&lt;P&gt;ip audit po max-events 100&lt;/P&gt;&lt;P&gt;ip ssh time-out 120&lt;/P&gt;&lt;P&gt;ip ssh authentication-retries 3&lt;/P&gt;&lt;P&gt;no ip dhcp-client network-discovery&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto mib ipsec flowmib history tunnel size 200&lt;/P&gt;&lt;P&gt;crypto mib ipsec flowmib history failure size 200&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Ethernet0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; no ip mroute-cache&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; half-duplex&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0&lt;/P&gt;&lt;P&gt; ip address 172.16.11.1 255.255.255.0&lt;/P&gt;&lt;P&gt; no ip route-cache&lt;/P&gt;&lt;P&gt; no ip mroute-cache&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; half-duplex&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Async5&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; encapsulation ppp&lt;/P&gt;&lt;P&gt; async mode interactive&lt;/P&gt;&lt;P&gt; ppp authentication chap pap&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip classless&lt;/P&gt;&lt;P&gt;no ip http server&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt; exec-timeout 0 0&lt;/P&gt;&lt;P&gt; modem InOut&lt;/P&gt;&lt;P&gt; modem autoconfigure type default&lt;/P&gt;&lt;P&gt; transport preferred none&lt;/P&gt;&lt;P&gt; transport input all&lt;/P&gt;&lt;P&gt; autoselect during-login&lt;/P&gt;&lt;P&gt; autoselect ppp&lt;/P&gt;&lt;P&gt; stopbits 1&lt;/P&gt;&lt;P&gt; speed 115200&lt;/P&gt;&lt;P&gt; flowcontrol hardware&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; exec-timeout 0 0&lt;/P&gt;&lt;P&gt;line vty 5 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:59:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-killed-my-reverse-telnet/m-p/62820#M857</guid>
      <dc:creator>kevtown</dc:creator>
      <dc:date>2020-02-21T17:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: AAA killed my reverse telnet</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-killed-my-reverse-telnet/m-p/62821#M858</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Take a look at this line:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization reverse-access &lt;/P&gt;&lt;P&gt;default local group radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May want to change it to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authorization reverse-access &lt;/P&gt;&lt;P&gt;radius&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A good link on this is below:&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/software/ios120/12cgcr/secur_r/srprt1/srauth.htm#xtocid1560415" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/software/ios120/12cgcr/secur_r/srprt1/srauth.htm#xtocid1560415&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 May 2002 13:03:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-killed-my-reverse-telnet/m-p/62821#M858</guid>
      <dc:creator>mmellet</dc:creator>
      <dc:date>2002-05-13T13:03:25Z</dc:date>
    </item>
    <item>
      <title>Re: AAA killed my reverse telnet</title>
      <link>https://community.cisco.com/t5/network-access-control/aaa-killed-my-reverse-telnet/m-p/62822#M859</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kevtown,&lt;/P&gt;&lt;P&gt;Looking at yr AAA config why do you need the word local after default , try:&lt;/P&gt;&lt;P&gt;aaa authorization reverse-access default group radius &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also go to Cisco Documentation: Configuring Authorization.&lt;/P&gt;&lt;P&gt;Cisco has good examples for reverse telnet via ACS/AAA server authentication.&lt;/P&gt;&lt;P&gt;Sarkis&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Jun 2002 21:42:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/aaa-killed-my-reverse-telnet/m-p/62822#M859</guid>
      <dc:creator>skaragozian</dc:creator>
      <dc:date>2002-06-17T21:42:18Z</dc:date>
    </item>
  </channel>
</rss>

