cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
755
Views
0
Helpful
7
Replies

Login Problem to PIX if TACACS fails

lvrak2102
Level 1
Level 1

Hi All,

I tried to integrate PIX535 with tacacs, under normal circumstences everything is working fine. But tacacs fails i'm unable to get the login.

7 Replies 7

a.kiprawih
Level 7
Level 7

Hi,

Unlike router, PIX does not provide you the option to use local database if the AAA server unreachable or failed.

Normally, you need to specify the tacacs+ server & group, then tie the access method to the tacacs using "aaa authentication " command.

Maybe you should consider using LOCAL database via ssh as a backup.

Rgds,

AK

Hi,

Appreciate your help, I'm trying to access from outside interface which works on ssh as telnet doesn't work on the outside interface.

How do you go about this.

Rgds,

lvrk

Hi,

If you are using version 7 you can use local authentication as a backup as you would on standard IOS. You may be able to do it on the version prior but not 100% about that.

Regards

Miron

altaf007
Level 1
Level 1

I think u can use "pix" as username and "pix" as password. No quotation ..I had to do it last year when AAA was down..

altaf

If that works, it should be username 'pix' and for password the enable-password or secret of the unit.

Actually, "pix" is the default username of the ssh user. The default password of this account is "cisco", and can be changed with the "passwd" command (same password if you have telnet enabled). Hopefully the person who has their password set to pix changes that since someone can DoS your RADIUS/TACACS server and then use pix/pix to login. That's not very secure!

jason.drury
Level 1
Level 1

If the PIX fails to communicate with the tacacs server after 3 attempts, it will allow you to login as the user "pix". This is the default local user when you enable SSH.