cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3456
Views
0
Helpful
5
Replies

AAA authentication on ASA

Colin Higgins
Level 2
Level 2

I am trying to configure an ASA 5545X running 8.3+ to use a tacacs+ server for authentication, but to failover to local authentication if the tacacs+ server is not available.

 

when I use the command aaa authentication ssh console TACACS+ LOCAL

 

it tells me "range already exists" and it doesn't take

 

What is the command for this? Can't seem to find it in documentation

1 Accepted Solution

Accepted Solutions

Hi,

I don't think it should. As the SSH connection is already established on the ASA device.

Still , you can try to add the other command using some other management access like telnet or ASDM if possible.

Thanks and Regards,

Vibhor Amrodia

View solution in original post

5 Replies 5

Vibhor Amrodia
Cisco Employee
Cisco Employee

Hi,

If you are seeing this prompt , it means that the configuration is already there.

Can you check using this command from the Privilege mode on ASA:-

"show run aaa" and you should see the command in the configuration.

Thanks and Regards,

Vibhor Amrodia

I type the command

 

aaa authentication ssh console TACACS+ LOCAL

 

and it tells me "range already exists"

 

If I do a show run aaa I get

 

aaa authentication ssh console TACACS+

 

no LOCAL.

 

I should point out that this is an ASA blade for a 6500 switch running 8.5(1)

Hi,

Okay , just remove this command:-

no aaa authentication ssh console TACACS+

and then add the required one:-

aaa authentication ssh console TACACS+ LOCAL

Thanks and Regards,

Vibhor Amrodia

If I issue the command

no aaa authentication ssh console TACACS+

while ssh'd into the device, will it lock me out?

Hi,

I don't think it should. As the SSH connection is already established on the ASA device.

Still , you can try to add the other command using some other management access like telnet or ASDM if possible.

Thanks and Regards,

Vibhor Amrodia

Review Cisco Networking for a $25 gift card