cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
355
Views
0
Helpful
3
Replies

aaa new-model lockout danger

tedauction
Level 1
Level 1

Hello, my situation is that  have switches with no enable password configured i.e. simply a username and password.

If I enter the command 'aaa new-model' and do not have the command "aaa authorization exec default local if-authenticated" configured then am I going to be locked out of privileged mode ? i.e .will I have to reset the switch to get back to this level of access ?

3 Replies 3

Reza Sharifi
Hall of Fame
Hall of Fame

If you get locked out of the switch, you have to do a password recovery and reboot possibly multiple times to reset the password.  If these switches are in production, the password recovery procedure will cause downtime.  So, please make sure you don't get locked out.

HTH  

Thank you. I wanted to confirm if the following is correct ?

 

If I enter the command 'aaa new-model' and do not have the command "aaa authorization exec default local if-authenticated" configured then am I going to be locked out of privileged mode ?

Have a look at this link. The function of that command is explained really well by Rick.

https://supportforums.cisco.com/t5/aaa-identity-and-nac/if-authenticated/td-p/1248124

HTH

Review Cisco Networking for a $25 gift card