<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Console authorization issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/console-authorization-issue/m-p/2492619#M87401</link>
    <description>&lt;P&gt;Hi, all.&lt;/P&gt;&lt;P&gt;I'm getting “% Authorization Failed.” on the console when logging in despite the config below - have I missed something here?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default local&lt;BR /&gt;aaa authentication login VTY_AUTH group radius local&lt;BR /&gt;aaa authorization exec default none&lt;BR /&gt;aaa authorization exec VTY_AUTH group radius local&lt;BR /&gt;aaa accounting exec default start-stop group radius&lt;BR /&gt;!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt;&amp;nbsp;password 7 XXXXXXXXXXXXXX&lt;BR /&gt;line vty 0 4&lt;BR /&gt;&amp;nbsp;access-class VTY_ACL in&lt;BR /&gt;&amp;nbsp;password 7 XXXXXXXXXXXXXX&lt;BR /&gt;&amp;nbsp;authorization exec VTY_AUTH&lt;BR /&gt;&amp;nbsp;login authentication VTY_AUTH&lt;BR /&gt;&amp;nbsp;transport input ssh&lt;BR /&gt;&amp;nbsp;transport output ssh&lt;BR /&gt;line vty 5 15&lt;BR /&gt;&amp;nbsp;transport input none&lt;BR /&gt;!&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Debug output when I login:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;AAA/AUTHEN/LOGIN (000004B6): Pick method list 'default'&lt;BR /&gt;AAA/AUTHOR (0x4B6): Pick method list 'VTY_AUTH'&lt;BR /&gt;AAA/AUTHOR/EXEC(000004B6): Authorization FAILED&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I can’t for the life of me figure out why it’s trying the “VTY_AUTH” list - any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is on a 3750-X stack running 12.2(55)SE3 at ipbase license level.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 04:30:50 GMT</pubDate>
    <dc:creator>James Horne</dc:creator>
    <dc:date>2019-03-11T04:30:50Z</dc:date>
    <item>
      <title>Console authorization issue</title>
      <link>https://community.cisco.com/t5/network-access-control/console-authorization-issue/m-p/2492619#M87401</link>
      <description>&lt;P&gt;Hi, all.&lt;/P&gt;&lt;P&gt;I'm getting “% Authorization Failed.” on the console when logging in despite the config below - have I missed something here?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default local&lt;BR /&gt;aaa authentication login VTY_AUTH group radius local&lt;BR /&gt;aaa authorization exec default none&lt;BR /&gt;aaa authorization exec VTY_AUTH group radius local&lt;BR /&gt;aaa accounting exec default start-stop group radius&lt;BR /&gt;!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt;&amp;nbsp;password 7 XXXXXXXXXXXXXX&lt;BR /&gt;line vty 0 4&lt;BR /&gt;&amp;nbsp;access-class VTY_ACL in&lt;BR /&gt;&amp;nbsp;password 7 XXXXXXXXXXXXXX&lt;BR /&gt;&amp;nbsp;authorization exec VTY_AUTH&lt;BR /&gt;&amp;nbsp;login authentication VTY_AUTH&lt;BR /&gt;&amp;nbsp;transport input ssh&lt;BR /&gt;&amp;nbsp;transport output ssh&lt;BR /&gt;line vty 5 15&lt;BR /&gt;&amp;nbsp;transport input none&lt;BR /&gt;!&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Debug output when I login:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;AAA/AUTHEN/LOGIN (000004B6): Pick method list 'default'&lt;BR /&gt;AAA/AUTHOR (0x4B6): Pick method list 'VTY_AUTH'&lt;BR /&gt;AAA/AUTHOR/EXEC(000004B6): Authorization FAILED&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I can’t for the life of me figure out why it’s trying the “VTY_AUTH” list - any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is on a 3750-X stack running 12.2(55)SE3 at ipbase license level.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 04:30:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/console-authorization-issue/m-p/2492619#M87401</guid>
      <dc:creator>James Horne</dc:creator>
      <dc:date>2019-03-11T04:30:50Z</dc:date>
    </item>
    <item>
      <title>Hello,Yeah does not seems</title>
      <link>https://community.cisco.com/t5/network-access-control/console-authorization-issue/m-p/2492620#M87403</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Yeah does not seems good,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Quick question, did you add the command:&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: rgb(119, 119, 119); font-size: 14px;"&gt;aaa authorization console&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;This is required to enable authorization on the console line,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: rgb(119, 119, 119); font-size: 14px;"&gt;I&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2014 05:00:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/console-authorization-issue/m-p/2492620#M87403</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2014-03-11T05:00:10Z</dc:date>
    </item>
    <item>
      <title>I would get ride of this line</title>
      <link>https://community.cisco.com/t5/network-access-control/console-authorization-issue/m-p/2492621#M87405</link>
      <description>&lt;P&gt;I would get ride of this line as I have the feeling that it is causing issues for you.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: rgb(119, 119, 119); font-size: 14px;"&gt;aaa authentication login default local&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If that does not fix it you can also add:&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: rgb(119, 119, 119); font-size: 14px;"&gt;aaa authentication login console line&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: rgb(119, 119, 119); font-size: 14px;"&gt;line con 0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: rgb(119, 119, 119); font-size: 14px;"&gt;login authentication console&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2014 05:11:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/console-authorization-issue/m-p/2492621#M87405</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2014-03-11T05:11:18Z</dc:date>
    </item>
    <item>
      <title>well check the syntax and if</title>
      <link>https://community.cisco.com/t5/network-access-control/console-authorization-issue/m-p/2492622#M87407</link>
      <description>&lt;P&gt;well check the syntax and if you are using the groups make sure they are avaiable in the radius and raduis server is clearly defined and reachable.&lt;/P&gt;&lt;P class="pB1_Body1"&gt;&lt;B class="cBold"&gt;aaa authentication login default &lt;/B&gt;{&lt;B class="cBold" style="font-weight: bold"&gt;group &lt;/B&gt;&lt;SPAN style="color: Black; font-style: italic; font-weight: normal"&gt;group-list &lt;/SPAN&gt;[&lt;B class="cBold"&gt;none&lt;/B&gt;]| &lt;B class="cBold"&gt;local &lt;/B&gt;&lt;/P&gt;&lt;P&gt;group-list—Space-separated list of server groups that can include any configured RADIUS or TACACS+ server group name.&lt;/P&gt;&lt;P&gt;local—Specifies the local database of the&lt;BR /&gt;Cisco CG-OS router for authentication.&lt;/P&gt;&lt;P&gt;none—Uses no authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2014 13:55:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/console-authorization-issue/m-p/2492622#M87407</guid>
      <dc:creator>kaaftab</dc:creator>
      <dc:date>2014-03-11T13:55:40Z</dc:date>
    </item>
    <item>
      <title>debugs indicates that while</title>
      <link>https://community.cisco.com/t5/network-access-control/console-authorization-issue/m-p/2492623#M87410</link>
      <description>&lt;P&gt;debugs indicates that while you were trying to connect from console, it picked the right authentication method and wrong authorization method. I guess you might have globally enabled console authorization but then also it should not pick VTY_AUTH method list.&lt;/P&gt;&lt;P&gt;Can you try this if possible:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: rgb(119, 119, 119); font-size: 14.44444465637207px; background-color: rgb(247, 247, 247);"&gt;username &amp;lt;username&amp;gt; privilege 15 password &amp;lt;password&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: rgb(119, 119, 119); font-size: 14.44444465637207px; background-color: rgb(247, 247, 247);"&gt;aaa authentication login CON default local&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: rgb(119, 119, 119); font-size: 14.44444465637207px; background-color: rgb(247, 247, 247);"&gt;aaa authorization exec CON default local&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: rgb(119, 119, 119); font-size: 14.44444465637207px; background-color: rgb(247, 247, 247);"&gt;aaa authorization console&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: rgb(119, 119, 119); font-size: 14.44444465637207px; background-color: rgb(247, 247, 247);"&gt;!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: rgb(119, 119, 119); font-size: 14.44444465637207px; background-color: rgb(247, 247, 247);"&gt;line console 0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: rgb(119, 119, 119); font-size: 14.44444465637207px; background-color: rgb(247, 247, 247);"&gt;login authentication CON&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: rgb(119, 119, 119); font-size: 14.44444465637207px; background-color: rgb(247, 247, 247);"&gt;authorization exec CON&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: rgb(119, 119, 119); font-size: 14.44444465637207px; background-color: rgb(247, 247, 247);"&gt;exit&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: rgb(119, 119, 119); font-size: 14.44444465637207px; background-color: rgb(247, 247, 247);"&gt;Please try again and let me know if that works.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Jatin Katyal&lt;/P&gt;&lt;P&gt;**Do rate helpful posts**&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2014 17:47:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/console-authorization-issue/m-p/2492623#M87410</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2014-03-11T17:47:20Z</dc:date>
    </item>
    <item>
      <title>The aaa authorization console</title>
      <link>https://community.cisco.com/t5/network-access-control/console-authorization-issue/m-p/2492624#M87414</link>
      <description>&lt;P&gt;The &lt;STRONG&gt;aaa authorization console&lt;/STRONG&gt; command is not in use - this idea is to have the console only ever use the local database. As you can see in my original post, the default method is set to local for login (and is selected correctly) and "none" is set for the default exec authorization (and is skipped?).&lt;BR /&gt;&lt;BR /&gt;I'm sure it would work if I define a new list but one would assume that if the default is set it should use that (if at all)?&lt;BR /&gt;&lt;BR /&gt;I have also tried setting the default to "if-authenticated" etc. but it goes to use the 'VTY_AUTH' in all cases. Though interestingly, when the RADIUS servers are unreachable the local login does work - I assume this is because&amp;nbsp; the fallback authorization mode is local?&lt;BR /&gt;&lt;BR /&gt;Seems like it could be a bug?&lt;BR /&gt;&lt;BR /&gt;I will be back on site to test tomorrow morning.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2014 01:15:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/console-authorization-issue/m-p/2492624#M87414</guid>
      <dc:creator>James Horne</dc:creator>
      <dc:date>2014-03-12T01:15:05Z</dc:date>
    </item>
    <item>
      <title>Following up on this, I have</title>
      <link>https://community.cisco.com/t5/network-access-control/console-authorization-issue/m-p/2492625#M87417</link>
      <description>&lt;P&gt;Following up on this, I have tried most suggestions with the config currently as follows:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default local&lt;BR /&gt;aaa authentication login CON0 local&lt;BR /&gt;aaa authentication login VTY_AUTH group radius local&lt;BR /&gt;aaa authorization console&lt;BR /&gt;aaa authorization exec default none&lt;BR /&gt;aaa authorization exec CON0 if-authenticated&lt;BR /&gt;aaa authorization exec VTY_AUTH group radius local&lt;BR /&gt;aaa accounting exec default start-stop group radius&lt;BR /&gt;!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt;&amp;nbsp;password 7 XXXXXXXXXXXXXX&lt;BR /&gt;&amp;nbsp;authorization exec CON0&lt;BR /&gt;&amp;nbsp;login authentication CON0&lt;BR /&gt;line vty 0 4&lt;BR /&gt;&amp;nbsp;access-class VTY_ACL in&lt;BR /&gt;&amp;nbsp;password 7 XXXXXXXXXXXXXX&lt;BR /&gt;&amp;nbsp;authorization exec VTY_AUTH&lt;BR /&gt;&amp;nbsp;login authentication VTY_AUTH&lt;BR /&gt;&amp;nbsp;transport input ssh&lt;BR /&gt;&amp;nbsp;transport output ssh&lt;BR /&gt;line vty 5 15&lt;BR /&gt;&amp;nbsp;transport input none&lt;BR /&gt;!&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Debug output on login - you’ll notice that this is still picking the wrong list:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;AAA/BIND(000004DE): Bind i/f &amp;nbsp;&lt;BR /&gt;AAA/AUTHEN/LOGIN (000004DE): Pick method list 'CON0'&lt;BR /&gt;AAA/AUTHOR (0x4DE): Pick method list 'VTY_AUTH'&lt;BR /&gt;AAA/AUTHOR/EXEC(000004DE): Authorization FAILED&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any further ideas?&lt;/P&gt;</description>
      <pubDate>Sat, 15 Mar 2014 03:09:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/console-authorization-issue/m-p/2492625#M87417</guid>
      <dc:creator>James Horne</dc:creator>
      <dc:date>2014-03-15T03:09:58Z</dc:date>
    </item>
    <item>
      <title>Came on to post about</title>
      <link>https://community.cisco.com/t5/network-access-control/console-authorization-issue/m-p/2492626#M87421</link>
      <description>&lt;P&gt;&lt;SPAN style="color: #00ff00; font-size: 18pt;"&gt;&lt;STRONG&gt;CONCLUSION&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Came on to post about something else and saw this, remembering that I had never returned to update it with the final working config:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;aaa new-model&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;aaa authentication login default local&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;aaa authentication login CON0 local&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;aaa authorization console&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;aaa authorization exec default none&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;aaa authorization exec CON0 if-authenticated&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;aaa session-id common&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;line con 0&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;password 7&amp;nbsp;XXXXXXXXXXXXXX&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;authorization exec CON0&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&amp;nbsp;login authentication CON0&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Version is now 15.2(1)E2 and none of this worked until I moved off the version mentioned in the initial post.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2015 01:37:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/console-authorization-issue/m-p/2492626#M87421</guid>
      <dc:creator>James Horne</dc:creator>
      <dc:date>2015-12-18T01:37:03Z</dc:date>
    </item>
    <item>
      <title>James, glad you were able to</title>
      <link>https://community.cisco.com/t5/network-access-control/console-authorization-issue/m-p/2492627#M87423</link>
      <description>&lt;P&gt;James, glad you were able to solve your issue! Also, thank you for taking the time to come back here and provide the solution (+5 from me).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, since the issue is resolved, you should mark the thread as "answered" &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Dec 2015 01:57:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/console-authorization-issue/m-p/2492627#M87423</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2015-12-19T01:57:54Z</dc:date>
    </item>
  </channel>
</rss>

