07-28-2021 01:44 AM
Hi, I am new to Cisco devices.
I have a question regarding ISR 4321. after i load the configuration as per below, i will not be able to login the router via console. can anyone help me to verify if my configuration is correct? or did i missed out anything.
Thank you !
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
logging buffered 99999
no logging console
username maxis$enterprise privilege 15 secret xxx
privilege exec level 8 show
privilege exec level 8 show configuration
enable secret xxxx
service password-encryption
clock timezone MYT 8
ip ssh version 2
ip scp server enable
no ip http server
no ip http secure-server
no ip domain lookup
ip domain name maxis.com.my
crypto key generate rsa
1024
aaa new-model
aaa group server tacacs+ ADMIN
server 121.x.x.x
server 121.x.x.x
ip vrf forwarding xxx
ip tacacs source-interface Loopback1
aaa authentication login CONSOLE local
aaa authentication login ADMIN group ADMIN local
aaa authentication enable default none
aaa authorization config-commands
aaa authorization exec ADMIN group ADMIN local
aaa authorization commands 15 ADMIN group ADMIN local
tacacs-server host 121.x.x.x
tacacs-server host 121.x.x.x
tacacs-server directed-request
tacacs-server key xxxx
vrf definition xxx
rd 9534:14008
address-family ipv4
exit-address-family
ip ssh version 2
snmp-server ifindex persist
snmp ifmib ifalias long
snmp-server group x10 v3 priv access REMOTE_MGMT
snmp-server user x10 x10 v3 auth sha xxx priv aes 128 xxx access REMOTE_MGMT
snmp-server trap-source Loopback1
snmp-server enable traps snmp authentication linkdown linkup coldstart warmstart
snmp-server enable traps entity-perf throughput-notif
snmp-server enable traps tty
snmp-server enable traps config
snmp-server enable traps entity
snmp-server enable traps cpu threshold
snmp-server enable traps syslog
snmp-server enable traps entity-state
snmp-server enable traps entity-qfp mem-res-thresh throughput-notif
snmp-server enable traps entity-diag boot-up-fail hm-test-recover hm-thresh-reached scheduled-test-fail
snmp-server host 121x.x.x vrf xxx xxx
snmp-server host 121.x.x.x vrf xxx xxxx
ip access-list standard REMOTE_MGMT
permit 121.x.x.x
permit 121.x.x.x
permit 121.x.x.x
line con 0
login authentication CONSOLE
logging synchronous
exec-timeout 5 0
line vty 0 4
authorization commands 15 ADMIN
authorization exec ADMIN
logging synchronous
exec-timeout 5 0
login authentication ADMIN
transport input ssh
access-class REMOTE_MGMT in vrf-also
07-28-2021 02:43 AM - edited 07-28-2021 02:44 AM
aaa authentication login CONSOLE local
Note: In this case, a username and password have to be configured in the local database of the router. The list must also be applied to the line or interface.
if the config not save, reload the device, so you get access to console again, make sure you understand the command before you paste or lock yourself.
check below document help you :
07-28-2021 02:54 AM
Hi Balaji, thanks for your reply. do you mean i need to add the command as per below:
username maxis$enterprise privilege 15 secret xxx
07-28-2021 03:53 AM
yes correct you need to have local username to work.
i never (or tested) - username have special character - so simplyfy - add user and test it before you enable AAA
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide