<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi,With this configuration , in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/why-quot-enable-password-quot-is-different-when-i-log-onto-asa/m-p/2744207#M192220</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;With this configuration , the Username/Password to login to the SSH.TElnet will be the TACACS credentials.&lt;/P&gt;&lt;P&gt;Enabled password would be the one that you have configured locally.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
    <pubDate>Tue, 01 Sep 2015 01:23:24 GMT</pubDate>
    <dc:creator>Vibhor Amrodia</dc:creator>
    <dc:date>2015-09-01T01:23:24Z</dc:date>
    <item>
      <title>Why "enable password" is different when I log onto ASA using telnet ?</title>
      <link>https://community.cisco.com/t5/network-security/why-quot-enable-password-quot-is-different-when-i-log-onto-asa/m-p/2744205#M192218</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;The configuraiton in the ASA is as below:&lt;/P&gt;&lt;P&gt;aaa authentication enable console TACATS LOCAL&lt;BR /&gt;aaa authentication telnet console LOCAL&amp;nbsp;&lt;BR /&gt;username cisco password cisco&lt;BR /&gt;telnet 0.0.0.0 0.0.0.0 inside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you think the enable password is different when I use SSH or telnet to log onto the ASA? Both ssh and telnet can log onto the asa, and it can pass&amp;nbsp; enable password(tacacs server password and username), but enable password fail if i use telnet log onto the ASA&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:31:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-quot-enable-password-quot-is-different-when-i-log-onto-asa/m-p/2744205#M192218</guid>
      <dc:creator>eigrpy</dc:creator>
      <dc:date>2019-03-12T06:31:36Z</dc:date>
    </item>
    <item>
      <title>Hi,this is my config, which</title>
      <link>https://community.cisco.com/t5/network-security/why-quot-enable-password-quot-is-different-when-i-log-onto-asa/m-p/2744206#M192219</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;this is my config, which works ok &amp;nbsp;I need a local enable password for telnet/ssh&lt;/P&gt;&lt;P&gt;aaa authentication http console TACACS+ LOCAL&lt;BR /&gt;aaa authentication telnet console TACACS+ LOCAL&lt;BR /&gt;aaa authentication ssh console TACACS+ LOCAL&lt;/P&gt;&lt;P&gt;enable password .qlnV1D9xc02BByd encrypted&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Richard&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 01:00:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-quot-enable-password-quot-is-different-when-i-log-onto-asa/m-p/2744206#M192219</guid>
      <dc:creator>Richard Bradfield</dc:creator>
      <dc:date>2015-09-01T01:00:09Z</dc:date>
    </item>
    <item>
      <title>Hi,With this configuration ,</title>
      <link>https://community.cisco.com/t5/network-security/why-quot-enable-password-quot-is-different-when-i-log-onto-asa/m-p/2744207#M192220</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;With this configuration , the Username/Password to login to the SSH.TElnet will be the TACACS credentials.&lt;/P&gt;&lt;P&gt;Enabled password would be the one that you have configured locally.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 01:23:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-quot-enable-password-quot-is-different-when-i-log-onto-asa/m-p/2744207#M192220</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-09-01T01:23:24Z</dc:date>
    </item>
    <item>
      <title>After telnet log onto the ASA</title>
      <link>https://community.cisco.com/t5/network-security/why-quot-enable-password-quot-is-different-when-i-log-onto-asa/m-p/2744208#M192221</link>
      <description>&lt;P&gt;After telnet log onto the ASA, it seems telnet requires the&amp;nbsp;enable password which is different with ssh' enable password. Do you agree ? Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 13:16:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-quot-enable-password-quot-is-different-when-i-log-onto-asa/m-p/2744208#M192221</guid>
      <dc:creator>eigrpy</dc:creator>
      <dc:date>2015-09-01T13:16:48Z</dc:date>
    </item>
    <item>
      <title>Hi,No , The enable password</title>
      <link>https://community.cisco.com/t5/network-security/why-quot-enable-password-quot-is-different-when-i-log-onto-asa/m-p/2744209#M192222</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;No , The enable password would be the same for both as that is a global password to move into the Enable mode.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 15:41:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-quot-enable-password-quot-is-different-when-i-log-onto-asa/m-p/2744209#M192222</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-09-01T15:41:18Z</dc:date>
    </item>
    <item>
      <title>Thanks for your reply. I</title>
      <link>https://community.cisco.com/t5/network-security/why-quot-enable-password-quot-is-different-when-i-log-onto-asa/m-p/2744210#M192223</link>
      <description>&lt;P&gt;Thanks for your reply. I think you are right.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now,&amp;nbsp;It is very strange regarding the command "aaa authentication enable console TACACS&amp;nbsp;LOCAL", When I am using the command, ssh can pass enable password, but telnet cannot pass enable password. Then I remove TACACS from the command, the situation is reverse: telnet canpass enable password, and ssh cannot pass enable password. What is wrong ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is full config:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;aaa authentication ssh console TACACS LOCAL&lt;BR /&gt;aaa authentication telnet console LOCAL&amp;nbsp;&lt;BR /&gt;aaa authentication enable console TACACS LOCAL&amp;nbsp;&lt;BR /&gt;aaa accounting enable console TACACS&lt;BR /&gt;aaa accounting ssh console TACACS&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 19:59:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-quot-enable-password-quot-is-different-when-i-log-onto-asa/m-p/2744210#M192223</guid>
      <dc:creator>eigrpy</dc:creator>
      <dc:date>2015-09-01T19:59:10Z</dc:date>
    </item>
    <item>
      <title>I got it. After I add TACACS</title>
      <link>https://community.cisco.com/t5/network-security/why-quot-enable-password-quot-is-different-when-i-log-onto-asa/m-p/2744211#M192224</link>
      <description>&lt;P&gt;I got it. After I add TACACS to command aaa authentication telnet console LOCAL, it can work. but i do not know the reason.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 20:31:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-quot-enable-password-quot-is-different-when-i-log-onto-asa/m-p/2744211#M192224</guid>
      <dc:creator>eigrpy</dc:creator>
      <dc:date>2015-09-01T20:31:25Z</dc:date>
    </item>
    <item>
      <title>Hi,Let me try to clarify</title>
      <link>https://community.cisco.com/t5/network-security/why-quot-enable-password-quot-is-different-when-i-log-onto-asa/m-p/2744212#M192225</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Let me try to clarify things here:-&lt;/P&gt;&lt;P&gt;aaa authentication ssh console TACACS LOCAL&lt;BR /&gt;aaa authentication telnet console LOCAL&amp;nbsp;&lt;BR /&gt;aaa authentication enable console TACACS LOCAL&amp;nbsp;&lt;/P&gt;&lt;P&gt;These commands are only to instruct the ASA device to tell the ASA where to look for the Username/Password information.&lt;/P&gt;&lt;P&gt;Now , as a test , try this:-&lt;/P&gt;&lt;P&gt;Create same username/Password in TACACS server and on the ASA LOCAL database.&lt;/P&gt;&lt;P&gt;Configure these commands:-&lt;/P&gt;&lt;P&gt;aaa authentication ssh console TACACS LOCAL&lt;BR /&gt;aaa authentication telnet console TACACS LOCAL&amp;nbsp;&lt;BR /&gt;aaa authentication enable console TACACS LOCAL&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now , try to check if both of them works or not ?&lt;/P&gt;&lt;P&gt;The problem which you might be seeing was that the TACACS and LOCAL database would be having different Username/Password combinations.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 21:00:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-quot-enable-password-quot-is-different-when-i-log-onto-asa/m-p/2744212#M192225</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-09-01T21:00:29Z</dc:date>
    </item>
    <item>
      <title>Thank you so much. You might</title>
      <link>https://community.cisco.com/t5/network-security/why-quot-enable-password-quot-is-different-when-i-log-onto-asa/m-p/2744213#M192226</link>
      <description>&lt;P&gt;Thank you so much. You might not have seen my updated last post. I got the same as you suggested.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;aaa authentication ssh console TACACS LOCAL&lt;/SPAN&gt;&lt;BR style="font-size: 14.3999996185303px;" /&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;aaa authentication telnet console TACACS LOCAL&amp;nbsp;&lt;/SPAN&gt;&lt;BR style="font-size: 14.3999996185303px;" /&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;aaa authentication enable console TACACS LOCAL&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;These can work well. Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2015 21:05:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-quot-enable-password-quot-is-different-when-i-log-onto-asa/m-p/2744213#M192226</guid>
      <dc:creator>eigrpy</dc:creator>
      <dc:date>2015-09-01T21:05:43Z</dc:date>
    </item>
  </channel>
</rss>

