aaa authentication login

Configures the AAA authentication method for securing access to Telnet or SSH access to the CLI.
Syntax
aaa authentication login default method-list [ method-list ... ]
no aaa authentication login default method-list [ method-list ... ]
aaa authentication login privilege-mode
no aaa authentication login privilege-mode
Command Default

The AAA authentication method list is not configured.

By default, a user enters the User EXEC mode after a successful login through Telnet or SSH.

Parameters
default
Configures the default authentication method list.
method-list
Configures the following authentication methods.
local
Authenticate using a local username and password you configured on the device. Local usernames and passwords are configured using the username command.
radius
Authenticate using the database on a RADIUS server. You also must identify the server to the device using the radius-server command.
tacacs+
Authenticate using the database on a TACACS+ server. You also must identify the server to the device using the tacacs-server command.
privilege-mode
Configures the device to enter the privileged EXEC mode after a successful login through Telnet or SSH.
Modes

Global configuration mode

Usage Guidelines

You can specify a primary authentication method and two backup authentication methods. If the configured primary authentication fails due to an error, the device tries the backup authentication methods in the order they appear in the list.

The aaa authorization exec default tacacs+ command must be configured before the aaa authentication login default tacacs+ command or the aaa authentication enable default tacacs+ command can be configured. If you attempt to configure either of these commands first, the following message is displayed: Warning- Please configure exec authorization using TACACS+ to get user privilege.

Likewise, the aaa authorization exec default radius command must be configured before the aaa authentication login default radius command or the aaa authentication enable default radius command can be configured. If you attempt to configure either of these commands first, the following message is displayed: Warning- Please configure exec authorization using RADIUS to get user privilege.

From FastIron 09.0.10a, the authentication method local can be added only if at least one configured local user is present on the ICX device. Likewise, the last available local user cannot be deleted if either login authentication or web-server authentication is using local as an authentication method.

The user privilege level is based on the privilege level granted during login. By default, a user enters User EXEC mode after a successful login through Telnet or SSH. Use the login privilege-mode option to allow a user to enter Privileged EXEC mode after a Telnet or SSH login.

The no form of the command removes the authentication method.

Examples

The following example shows how to configure RADIUS as the primary authentication method for securing Telnet access to the CLI. If RADIUS authentication fails due to an error with the server, local authentication is used instead.

device# configure terminal
device(config)# aaa authentication login default radius local

The following example shows how to configure RADIUS as the primary authentication method and other backup authentication methods.

device(config)# aaa authentication login default radius tacacs+ local

The following example shows how to configure the device so that a user enters Privileged EXEC mode after a Telnet or SSH login.

device(config)# aaa authentication login privilege-mode
History
Release version Command history
08.0.90 The command was modified as described in the usage guidelines.
09.0.00 The command was modified to remove these options: enable, none, line, tacacs, and login privilege-mode.
09.0.10h, 10.0.10a This command was modified to align with the following command behavior in the 08.0.95 release: The aaa authorization exec command must be configured for TACACS+ or RADIUS as the default before the respective server type can be enabled and before login privileges can be set.
09.0.10h, 10.0.10b This command was modified to reintroduce the login privilege-mode option.