<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AAA question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/aaa-question/m-p/4272562#M1077310</link>
    <description>This is very strange. Based on your config, console access shouldn't work.&lt;BR /&gt;&lt;BR /&gt;Open an ssh session, debug aaa authentication with term monitor, then login&lt;BR /&gt;to console and post the output. Let's see what happens.&lt;BR /&gt;&lt;BR /&gt;***** please remember to rate useful posts&lt;BR /&gt;</description>
    <pubDate>Thu, 14 Jan 2021 16:35:09 GMT</pubDate>
    <dc:creator>Mohammed al Baqari</dc:creator>
    <dc:date>2021-01-14T16:35:09Z</dc:date>
    <item>
      <title>AAA question</title>
      <link>https://community.cisco.com/t5/network-security/aaa-question/m-p/4271948#M1077275</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;I am the process of updating and standardizing our AAA configs. This is a current section:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;BR /&gt;aaa authentication login console none&lt;BR /&gt;aaa authorization config-commands&lt;BR /&gt;aaa authorization exec default group tacacs+ if-authenticated&lt;BR /&gt;aaa authorization exec console none&lt;BR /&gt;aaa authorization commands 15 default group tacacs+ if-authenticated&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is are "aaa authentication login console none" and "aaa authorization exec console none" doing anything? I remember being told years ago they are there for some obscure login scenario but I cant remember what it is. Taking them out doesn't seem to have any effect. Thoughts?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 22:40:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aaa-question/m-p/4271948#M1077275</guid>
      <dc:creator>kelly.conley</dc:creator>
      <dc:date>2021-01-13T22:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: AAA question</title>
      <link>https://community.cisco.com/t5/network-security/aaa-question/m-p/4272169#M1077281</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;With your config, console access is blocked. Any user who tries to access&lt;BR /&gt;console and authenticate with fail. Some high security firms adopt that&lt;BR /&gt;model but the counter to this that you can't do console troubleshooting.&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Thu, 14 Jan 2021 08:05:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aaa-question/m-p/4272169#M1077281</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2021-01-14T08:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: AAA question</title>
      <link>https://community.cisco.com/t5/network-security/aaa-question/m-p/4272494#M1077303</link>
      <description>Thanks for the response. You would think that is the case but it is not.&lt;BR /&gt;Console access works with a local user as well as with tacacs.&lt;BR /&gt;</description>
      <pubDate>Thu, 14 Jan 2021 15:37:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aaa-question/m-p/4272494#M1077303</guid>
      <dc:creator>kelly.conley</dc:creator>
      <dc:date>2021-01-14T15:37:09Z</dc:date>
    </item>
    <item>
      <title>Re: AAA question</title>
      <link>https://community.cisco.com/t5/network-security/aaa-question/m-p/4272503#M1077305</link>
      <description>&lt;P&gt;Hi there,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The &lt;STRONG&gt;none&lt;/STRONG&gt; keyword instructs the aaa AuthC process to not look at any user datastores. The credentials must be stored on the line. What does &lt;STRONG&gt;sh run | beg line con&lt;/STRONG&gt; look like?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers,&lt;/P&gt;
&lt;P&gt;Seb.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 15:45:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aaa-question/m-p/4272503#M1077305</guid>
      <dc:creator>Seb Rupik</dc:creator>
      <dc:date>2021-01-14T15:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: AAA question</title>
      <link>https://community.cisco.com/t5/network-security/aaa-question/m-p/4272513#M1077306</link>
      <description>line con 0&lt;BR /&gt;exec-timeout 30 0&lt;BR /&gt;logging synchronous&lt;BR /&gt;</description>
      <pubDate>Thu, 14 Jan 2021 15:58:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aaa-question/m-p/4272513#M1077306</guid>
      <dc:creator>kelly.conley</dc:creator>
      <dc:date>2021-01-14T15:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: AAA question</title>
      <link>https://community.cisco.com/t5/network-security/aaa-question/m-p/4272530#M1077307</link>
      <description>&lt;P&gt;It appears that because I have this line:&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then this line:&lt;/P&gt;&lt;P&gt;aaa authentication login console none&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That "login default" applies to the console and therefore "aaa authentication login console none" does nothing and console access is allowed if tacacs is not available.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 16:14:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aaa-question/m-p/4272530#M1077307</guid>
      <dc:creator>kelly.conley</dc:creator>
      <dc:date>2021-01-14T16:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: AAA question</title>
      <link>https://community.cisco.com/t5/network-security/aaa-question/m-p/4272562#M1077310</link>
      <description>This is very strange. Based on your config, console access shouldn't work.&lt;BR /&gt;&lt;BR /&gt;Open an ssh session, debug aaa authentication with term monitor, then login&lt;BR /&gt;to console and post the output. Let's see what happens.&lt;BR /&gt;&lt;BR /&gt;***** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Thu, 14 Jan 2021 16:35:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aaa-question/m-p/4272562#M1077310</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2021-01-14T16:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: AAA question</title>
      <link>https://community.cisco.com/t5/network-security/aaa-question/m-p/4272609#M1077322</link>
      <description>&lt;P&gt;So when the tacacs is available console login does not work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jan 14 17:39:51.965: AAA/AUTHEN/LOGIN (0000001B): Pick method list 'default'&lt;/P&gt;&lt;P&gt;So I assume that this:&lt;/P&gt;&lt;P&gt;aaa authentication login default group tacacs+ local&lt;/P&gt;&lt;P&gt;is being used. when tacacs is not available console access fails to local even if "aaa authentication login console none" is used.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 17:45:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aaa-question/m-p/4272609#M1077322</guid>
      <dc:creator>kelly.conley</dc:creator>
      <dc:date>2021-01-14T17:45:24Z</dc:date>
    </item>
  </channel>
</rss>

