05-19-2004 07:31 PM - edited 03-10-2019 07:49 AM
I have configured the authentication method for PIX 515 firewall. I can pass the authentication process when I use "telnet" login. After that, I try to enter the privilege mode with "enable" command. The system prompt me for the password (no username prompt), then I enter the password, which same with the user "$enab15$" of the TACACS+ server. But the authentication failed. Please advice.
PIX device :-
aaa-server TACACS+ protocol tacacs+
aaa-server TACACS+ (inside) host 10.1.1.1 cisco timeout 5
aaa authentication telnet console TACACS+
aaa authentication enable console TACACS+
05-25-2004 12:59 PM
It's a known bug aaa authentication does not work with enable password.
06-03-2004 09:39 AM
Are you talking about bug#CSCdy64251 that was introduced in 6.2(2). Do you know if that bug still exist as 6.3(3)
06-04-2004 02:31 PM
Hi,
This bug is fixed in PIX 6.3(3) code. But, what you are experiencing can be ressolved by defining enable password in the same user profile as telnet. If you are using ACS Windows, you may need to turn on Advance tacacs+ option under the Interface configuraytion, and then configure the enable password in the userprofile. I would suggest to upgrade to 6.3.3 code for AAA. Thanks,
Mynul
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide