cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1018
Views
0
Helpful
6
Replies

ASA use AAA login ssh

bo liu
Level 4
Level 4

hello

i use windows 2003 IAS as radius server

the ASA use 8.3(2)

now my question is :

before i config AAA ,i use LOCAL database to login SSH and enable everything is ok

now i config AAA to login SSH , i can login ASA and but i can't use enable password to login EXEC mode.....

my ASA config about AAA

aaa-server cisco protocol radius

aaa-server cisco (inside) host 10.10.10.22

key *****

aaa authentication http console LOCAL

aaa authentication ssh console cisco LOCAL

aaa authentication enable console LOCAL

6 Replies 6

bo liu
Level 4
Level 4

IPCC-ASA> EN

Password: ********

Password: ********

Password:

Access denied.

Could you please try "login" instead of "enable"

IPCC-ASA> login

~BR
Jatin Katyal

**Do rate helpful posts**

~Jatin

hi Jatin

i use login and the ASA request the username password is in LOCAL

i change the command aaa authen enable cons cisco LOCAL the ASA also request the LOCAL username password

why can't use radius to login ??

and why i can't use enable???

HI Jatin

sorry i ready doc.

From user EXEC mode, you can log in as any username in the local database using the login command.

i know the login conmmand is use local database user to login......

but i don't understand why i can't use enable password to login...

Could you please remove this command from the configuration

aaa authentication enable console LOCAL

and try again.

Just wanted to make sure, you read the same doc:

From user EXEC mode, you can log in to privileged EXEC mode as any username in the local database using the

logincommand. The  login command is similar to the  enable command when you have enable authentication turned on (see the aaa authentication console command). Unlike enable authentication, the login command can only use the local username database, and authentication is  always required with this command. You can also change users using the

login command from any CLI mode.

http://www.cisco.com/en/US/partner/docs/security/asa/asa82/command/reference/l2.html#wp1774775

~BR
Jatin Katyal

**Do rate helpful posts**

~Jatin

hi Jatin

i remove the command and then login use enable

IPCC-ASA> en

Password: ********

Invalid password

invalid password.......