09-06-2005 07:12 AM - edited 03-10-2019 02:18 PM
Hi all,
we have an ACS server (3.3)
which we use for Login and Enable authentication for all our routers & switches without any problems.
I am setting up an Aironet 1231G with IOS 12.3(7)JA
I am able to get the login to authenticate OK, but when you try to enable, it returns "REJECTED".
the ACS Failed Attempts.csv shows the following:
06/09/2005 15:59:00 Authen failed $enab15$ .. .. External DB auth failed .. .. 0 10.139.251.201
Can anyone please tell me what I'm doing wrong?
Aironet Startup-config is attached
Many Thanks.
09-12-2005 05:43 AM
Radius will always send $enab15$ as the username and there is no way to change that. The best option is to use TACACS+ for login authentication or not use enable authentication to Radius.
09-13-2005 02:29 AM
Thanks for the response, but Tacacs didn't work either.
We eventually figured it out.. we'd missed off the
aaa authentication enable default group radius enable
command.
added this and all was well.
Cheers,
Nick
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide