12-01-2015 02:07 PM - edited 03-10-2019 11:17 PM
Hello
I made a rookie mistake today and configured one of our routers to use the following configuration:
aaa authentication login default group tacacs+ enable aaa authentication enable default group tacacs+ enable aaa authorization console aaa authorization exec default local group tacacs+ if-authenticated aaa authorization commands 1 default group tacacs+ if-authenticated aaa authorization commands 15 default group tacacs+ if-authenticated
We are using RADIUS for authentication - and TACACS for authorization, so needless to say I am locked out of the router. I am wondering if the only way to get past this is to password reset the router, or if there is a way for me to reconfigure my RADIUS/TACACS server to allow access for this device with this configuration.
Thanks
Solved! Go to Solution.
12-01-2015 02:19 PM
Since you have "enable" as the fallback method, simply maket the TACACS+ server unavailable to that router (null route somewhere upstream, ACL, etc) and then the router should let you log in using the enable password instead of username/password credentials.
Note: I'm making the assumption that the default authentication applies to the console or VTY lines, but I can't tell if that will be the case since the full configuration was not posted.
12-01-2015 02:19 PM
Since you have "enable" as the fallback method, simply maket the TACACS+ server unavailable to that router (null route somewhere upstream, ACL, etc) and then the router should let you log in using the enable password instead of username/password credentials.
Note: I'm making the assumption that the default authentication applies to the console or VTY lines, but I can't tell if that will be the case since the full configuration was not posted.
12-01-2015 02:23 PM
Hi Javier thanks for the reply
There is no additional configuration on the console or VTY lines to the best of my knowledge.
However, there is only one priviledge 15 user on the system, with no enable password configured.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide