<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA Console Locked Out in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-console-locked-out/m-p/3686156#M13911</link>
    <description>&lt;P&gt;Thanks for your input.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was able to resolve the issue by creating the same local user account on the TACACS+ server (ISE).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks, ~zK &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 10 Aug 2018 22:15:53 GMT</pubDate>
    <dc:creator>zekebashi</dc:creator>
    <dc:date>2018-08-10T22:15:53Z</dc:date>
    <item>
      <title>ASA Console Locked Out</title>
      <link>https://community.cisco.com/t5/network-security/asa-console-locked-out/m-p/3682685#M13909</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've configured aaa &amp;amp; TACACS+ on an ASA properly where the primary authentication method is ISE and a fallback method is local. I've created enable_15 with priv 15 and another local user account (admin_acct) with priv 15, also. I can ssh using my AD account just fine and when I tried to console in and use the local account (admin_acct) and I was able to login fine. However, it seems that this local user account (admin_acct) doesn't have the proper authorization to execute any priv commands and now I am locked out on the console since I cannot issue any commands nor can I even logout. Is there any command or method that i can exit out of this cosole session so I can log back in using a different user account?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas would be appreciated.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best, ~zK&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:03:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-console-locked-out/m-p/3682685#M13909</guid>
      <dc:creator>zekebashi</dc:creator>
      <dc:date>2020-02-21T16:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Console Locked Out</title>
      <link>https://community.cisco.com/t5/network-security/asa-console-locked-out/m-p/3682772#M13910</link>
      <description>There is no way to clear console session other than restart. Try to create&lt;BR /&gt;a dummy acl on the a switch or router between ISE and ASA to blocked tacacs&lt;BR /&gt;traffic then use local login for console using login command&lt;BR /&gt;</description>
      <pubDate>Tue, 07 Aug 2018 03:04:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-console-locked-out/m-p/3682772#M13910</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2018-08-07T03:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Console Locked Out</title>
      <link>https://community.cisco.com/t5/network-security/asa-console-locked-out/m-p/3686156#M13911</link>
      <description>&lt;P&gt;Thanks for your input.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was able to resolve the issue by creating the same local user account on the TACACS+ server (ISE).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks, ~zK &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Aug 2018 22:15:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-console-locked-out/m-p/3686156#M13911</guid>
      <dc:creator>zekebashi</dc:creator>
      <dc:date>2018-08-10T22:15:53Z</dc:date>
    </item>
  </channel>
</rss>

