cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1835
Views
10
Helpful
4
Replies

AAA lock out recovery

utawakevou
Level 4
Level 4

Been working on activating AAA via RADIUS access to my Nexus and Cisco 3750 and a 2800 router. Works well but I did a change on the 2800 and now I'm locked out of it as  I get authenticated when login in but the enable  password (local) doesn't work

 

Ran the "show aaa method-lists authentication" on the prompt and this shows up


authen queue=AAA_ML_AUTHEN_LOGIN
name=default valid=TRUE id=0 :state=ALIVE : SERVER_GROUP ROLE_ICT_Network_Equipment_Access
name=console valid=TRUE id=A000001 :state=ALIVE : LOCAL
authen queue=AAA_ML_AUTHEN_ENABLE
name=default valid=TRUE id=0 :state=ALIVE : SERVER_GROUP radius SERVER_GROUP ROLE_ICT_Network_Equipment_Access
authen queue=AAA_ML_AUTHEN_PPP
authen queue=AAA_ML_AUTHEN_SGBP
authen queue=AAA_ML_AUTHEN_ARAP
authen queue=AAA_ML_AUTHEN_DOT1X
authen queue=AAA_ML_AUTHEN_EAPOUDP
authen queue=AAA_ML_AUTHEN_8021X
permanent lists
name=Permanent Enable None valid=TRUE id=0 :state=ALIVE : ENABLE NONE
name=Permanent Enable valid=TRUE id=0 :state=ALIVE : ENABLE
name=Permanent None valid=TRUE id=0 :state=ALIVE : NONE
name=Permanent Local valid=TRUE id=0 :state=ALIVE : LOCAL

 

Seems like my fall back to the local didn't work as well. Any help will be really appreciated

 

 

2 Accepted Solutions

Accepted Solutions

Hello,

 

try and disconnect the router from any network connection, then connect via console and see if local authentication works. 

Rebooting the router might helped if you haven't saved the AAA configuration to memory.

 

If anything else fails, do a password recovery: Which 2800 do you have (the ISR or the old model) ?

View solution in original post

Hello,

 

yes, the password recovery access will give you local admin access through the console port. Procedure is in the link below:

 

https://www.cisco.com/c/en/us/support/docs/routers/2600-series-multiservice-platforms/22188-pswdrec-2600.html

View solution in original post

4 Replies 4

Hello,

 

try and disconnect the router from any network connection, then connect via console and see if local authentication works. 

Rebooting the router might helped if you haven't saved the AAA configuration to memory.

 

If anything else fails, do a password recovery: Which 2800 do you have (the ISR or the old model) ?

@Georg Pauwen Local authentication via console doesn't work as well when I disconnect from the network. Will the password recovery procedure enables be to remove that AAA line that I added ? If so then Ill do that. It is a Cisco 2811 router

Hello,

 

yes, the password recovery access will give you local admin access through the console port. Procedure is in the link below:

 

https://www.cisco.com/c/en/us/support/docs/routers/2600-series-multiservice-platforms/22188-pswdrec-2600.html

I've got this sorted with the password recovery process but remove AAA then reconfigured it again properly once I manage to log in

 

Thanks, this sort things out for me

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Innovations in Cisco Full Stack Observability - A new webinar from Cisco