<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic If you use the &amp;quot;Login&amp;quot; in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/aaa-authentication-serial-console/m-p/2765070#M192368</link>
    <description>&lt;P&gt;If you use the "Login" command under the user mode&lt;/P&gt;&lt;P&gt;ciscoasa&amp;gt;login&lt;/P&gt;&lt;P&gt;And then use your credentials, does it work?&amp;nbsp;&lt;/P&gt;&lt;P&gt;The serial, only authenticates to the console port, but not the exec mode, for that you will need to have authorization configured (as far as I remember, anyone else, please feel free to jump in).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With version 9.2, you can use the auto-enable option:&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/A-H/cmdref1/a1.html#pgfId-1595724&lt;/P&gt;&lt;P&gt;Mike.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Aug 2015 18:46:57 GMT</pubDate>
    <dc:creator>Maykol Rojas</dc:creator>
    <dc:date>2015-08-26T18:46:57Z</dc:date>
    <item>
      <title>aaa authentication serial console</title>
      <link>https://community.cisco.com/t5/network-security/aaa-authentication-serial-console/m-p/2765069#M192364</link>
      <description>&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;i'm trying to figure out what's wrong with my AAA config.&lt;/P&gt;&lt;P&gt;when I SSH/telnet to the ASA using my TACACS+ account is fine.&lt;/P&gt;&lt;P&gt;but i can't seem to login on our OBM server when I use the same TACACS+ account and also tried the enable password on the ASA.&lt;/P&gt;&lt;P&gt;appreciate anyone advise.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;NORMAL REMOTE ACSESS:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;User Access Verification&lt;/P&gt;&lt;P&gt;Username: John&lt;BR /&gt;Password: ********&lt;BR /&gt;Type help or '?' for a list of available commands.&lt;BR /&gt;ciscoasa/admin&amp;gt; en&lt;BR /&gt;Password: ********&lt;/P&gt;&lt;P&gt;ciscoasa/admin# sh run&amp;nbsp; | i aaa&lt;BR /&gt;aaa-server TACACS protocol tacacs+&lt;BR /&gt;aaa-server TACACS (inside) host 172.27.1.1&lt;BR /&gt;aaa authentication ssh console TACACS LOCAL&lt;BR /&gt;aaa authentication http console TACACS LOCAL&lt;BR /&gt;aaa authentication enable console TACACS LOCAL&lt;BR /&gt;&lt;SPAN style="color:#FF0000;"&gt;aaa authentication serial console TACACS LOCAL&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;aaa authorization command TACACS LOCAL&lt;BR /&gt;aaa authorization exec authentication-server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;OBM/jump server:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Console session started.&amp;nbsp; Press ~[ENTER] to exit.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Username: John&lt;BR /&gt;Password: ********&lt;BR /&gt;Type help or '?' for a list of available commands.&lt;BR /&gt;ciscoasa&amp;gt; en&lt;BR /&gt;Password: ********&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;&amp;lt;&amp;lt; USED TACACS+ PW&lt;BR /&gt;Invalid password&lt;BR /&gt;Password: ********&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;&amp;lt;&amp;lt; USED THE ASA CONFIGURED enable password&lt;BR /&gt;Invalid password&lt;BR /&gt;Password: ******&lt;BR /&gt;Invalid password&lt;BR /&gt;Access denied.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:30:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aaa-authentication-serial-console/m-p/2765069#M192364</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2019-03-12T06:30:01Z</dc:date>
    </item>
    <item>
      <title>If you use the "Login"</title>
      <link>https://community.cisco.com/t5/network-security/aaa-authentication-serial-console/m-p/2765070#M192368</link>
      <description>&lt;P&gt;If you use the "Login" command under the user mode&lt;/P&gt;&lt;P&gt;ciscoasa&amp;gt;login&lt;/P&gt;&lt;P&gt;And then use your credentials, does it work?&amp;nbsp;&lt;/P&gt;&lt;P&gt;The serial, only authenticates to the console port, but not the exec mode, for that you will need to have authorization configured (as far as I remember, anyone else, please feel free to jump in).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With version 9.2, you can use the auto-enable option:&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/A-H/cmdref1/a1.html#pgfId-1595724&lt;/P&gt;&lt;P&gt;Mike.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Aug 2015 18:46:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aaa-authentication-serial-console/m-p/2765070#M192368</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2015-08-26T18:46:57Z</dc:date>
    </item>
    <item>
      <title>hi,login doesn't work.what</title>
      <link>https://community.cisco.com/t5/network-security/aaa-authentication-serial-console/m-p/2765071#M192372</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;login doesn't work.&lt;/P&gt;&lt;P&gt;what authorization line should i add?&lt;/P&gt;&lt;P&gt;it only gives me the option to add LOCAL and authentication-server (which i already have).&lt;/P&gt;&lt;P&gt;ASA code is 8.3(2).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Console session started.&amp;nbsp; Press ~[ENTER] to exit.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Username: John&lt;BR /&gt;Password: ********&lt;BR /&gt;Type help or '?' for a list of available commands.&lt;BR /&gt;ciscoasa&amp;gt; login&lt;BR /&gt;Username: John&lt;BR /&gt;Password: ********&lt;BR /&gt;%Login failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ciscoasa/admin(config)# aaa authorization exec ?&lt;/P&gt;&lt;P&gt;configure mode commands/options:&lt;BR /&gt;&amp;nbsp; LOCAL&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Use authorization attributes of corresponding local&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; user&lt;BR /&gt;&amp;nbsp; authentication-server&amp;nbsp; Use authenticating servers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2015 01:09:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aaa-authentication-serial-console/m-p/2765071#M192372</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2015-08-27T01:09:02Z</dc:date>
    </item>
  </channel>
</rss>

