cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
937
Views
0
Helpful
3
Replies

Login username/password looping at login

JakeDuncan
Level 1
Level 1

I have a 2960x switch that I have setup for Radius login with Duo security. When logging into the console or any other means no problem, I login, two factor authenticate and its in; however, when I try to log into the webUI , I type in any registered username/password, receive the Duo response showing a successful login and then am immediately taken back to the login. I have tried removing the two factor with the same results. Tried changing from radius to local login, created an internal username/password, same results. The switch will accept the user information and show it in the running config, but no matter what, it just loops back to the login screen. The only way to login to the webUI is to use the secret with no username. That however creates a security risk due to it automatically logging in with the highest privilege. It also does not work with Duo and in our industry multi factor authentication is required by law on all administrator accounts. I have attached my running config for reference as well. Thank you.

3 Replies 3

Hi

 If you use:

ip http authentication local

When try with local username and pass, does not work?

It does not work with the local username/password, but will work using no username with the secret. 

Would you post the output of

ip http authentication ?

What is the result if you remove

ip http authentication aaa

HTH

Rick
Review Cisco Networking products for a $25 gift card