cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2356
Views
0
Helpful
3
Replies

Console password is not working Cisco ISR 4321

Dos3110
Level 1
Level 1

Hi, I am new to Cisco devices.

 

I have a question regarding ISR 4321. after i load the configuration as per below, i will not be able to login the router via console. can anyone help me to verify if my configuration is correct? or did i missed out anything.

 

Thank you !

 

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

 

logging buffered 99999 

no logging console 

 

username maxis$enterprise privilege 15 secret xxx

privilege exec level 8 show 

privilege exec level 8 show configuration 

enable secret xxxx

service password-encryption 

 

clock timezone MYT 8 

 

ip ssh version 2 

ip scp server enable 

 

no ip http server 

no ip http secure-server 

 

no ip domain lookup 

ip domain name maxis.com.my 

crypto key generate rsa 

1024 

 

aaa new-model 

aaa group server tacacs+ ADMIN 

server 121.x.x.x

server 121.x.x.x 

ip vrf forwarding xxx 

ip tacacs source-interface Loopback1 

 

aaa authentication login CONSOLE local 

aaa authentication login ADMIN group ADMIN local 

aaa authentication enable default none 

aaa authorization config-commands 

aaa authorization exec ADMIN group ADMIN local 

aaa authorization commands 15 ADMIN group ADMIN local 

 

tacacs-server host 121.x.x.x

tacacs-server host 121.x.x.x

tacacs-server directed-request 

tacacs-server key xxxx

 

vrf definition xxx

rd 9534:14008 

address-family ipv4 

exit-address-family 

 

ip ssh version 2 

snmp-server ifindex persist 

snmp ifmib ifalias long 

snmp-server group x10 v3 priv access REMOTE_MGMT  

snmp-server user x10 x10 v3 auth sha xxx priv aes 128 xxx access REMOTE_MGMT 

snmp-server trap-source Loopback1 

snmp-server enable traps snmp authentication linkdown linkup coldstart warmstart 

snmp-server enable traps entity-perf throughput-notif 

snmp-server enable traps tty 

snmp-server enable traps config 

snmp-server enable traps entity 

snmp-server enable traps cpu threshold 

snmp-server enable traps syslog 

snmp-server enable traps entity-state 

snmp-server enable traps entity-qfp mem-res-thresh throughput-notif 

snmp-server enable traps entity-diag boot-up-fail hm-test-recover hm-thresh-reached scheduled-test-fail 

snmp-server host 121x.x.x vrf xxx xxx 

snmp-server host 121.x.x.x vrf xxx xxxx

ip access-list standard REMOTE_MGMT 

permit 121.x.x.x

permit 121.x.x.x

permit 121.x.x.x

   

line con 0 

login authentication CONSOLE 

logging synchronous 

exec-timeout 5 0 

 

line vty 0 4 

authorization commands 15 ADMIN 

authorization exec ADMIN 

logging synchronous 

exec-timeout 5 0 

login authentication ADMIN 

transport input ssh 

access-class REMOTE_MGMT in vrf-also 

3 Replies 3

balaji.bandi
Hall of Fame
Hall of Fame
aaa authentication login CONSOLE local 

Note: In this case, a username and password have to be configured in the local database of the router. The list must also be applied to the line or interface.

 

if the config not save, reload the device, so you get access to console again, make sure you understand the command before you paste or lock yourself.

 

 

check below document help you :

 

https://www.cisco.com/c/en/us/support/docs/security-vpn/terminal-access-controller-access-control-system-tacacs-/10384-security.html

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi Balaji, thanks for your reply. do you mean i need to add the command as per below:

 

username maxis$enterprise privilege 15 secret xxx

yes correct you need to have local username to work.

 

i never (or tested) - username have special character - so simplyfy - add user and test it before you enable AAA

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help