08-01-2013 03:41 AM - edited 03-10-2019 08:43 PM
hello
i use windows 2003 IAS as radius server
the ASA use 8.3(2)
now my question is :
before i config AAA ,i use LOCAL database to login SSH and enable everything is ok
now i config AAA to login SSH , i can login ASA and but i can't use enable password to login EXEC mode.....
my ASA config about AAA
aaa-server cisco protocol radius
aaa-server cisco (inside) host 10.10.10.22
key *****
aaa authentication http console LOCAL
aaa authentication ssh console cisco LOCAL
aaa authentication enable console LOCAL
08-01-2013 03:56 AM
IPCC-ASA> EN
Password: ********
Password: ********
Password:
Access denied.
08-01-2013 04:28 AM
Could you please try "login" instead of "enable"
IPCC-ASA> login
~BR
Jatin Katyal
**Do rate helpful posts**
08-01-2013 04:39 AM
hi Jatin
i use login and the ASA request the username password is in LOCAL
i change the command aaa authen enable cons cisco LOCAL the ASA also request the LOCAL username password
why can't use radius to login ??
and why i can't use enable???
08-01-2013 04:52 AM
HI Jatin
sorry i ready doc.
From user EXEC mode, you can log in as any username in the local database using the login command.
i know the login conmmand is use local database user to login......
but i don't understand why i can't use enable password to login...
08-01-2013 05:44 AM
Could you please remove this command from the configuration
aaa authentication enable console LOCAL
and try again.
Just wanted to make sure, you read the same doc:
From user EXEC mode, you can log in to privileged EXEC mode as any username in the local database using the
logincommand. The login command is similar to the enable command when you have enable authentication turned on (see the aaa authentication console command). Unlike enable authentication, the login command can only use the local username database, and authentication is always required with this command. You can also change users using the
login command from any CLI mode.
http://www.cisco.com/en/US/partner/docs/security/asa/asa82/command/reference/l2.html#wp1774775
~BR
Jatin Katyal
**Do rate helpful posts**
08-02-2013 01:21 AM
hi Jatin
i remove the command and then login use enable
IPCC-ASA> en
Password: ********
Invalid password
invalid password.......
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide