aaa authentication login
aaa authentication
login
default
method-list
[
method-list
...
]no aaa authentication
login
default
method-list
[
method-list
...
]aaa authentication
login
privilege-modeno aaa authentication
login
privilege-modeThe AAA authentication method list is not configured.
By default, a user enters the User EXEC mode after a successful login through Telnet or SSH.
Global configuration mode
You can specify a primary authentication method and two backup authentication methods. If the configured primary authentication fails due to an error, the device tries the backup authentication methods in the order they appear in the list.
The aaa authorization exec
default
tacacs+ command must be configured before the aaa authentication
login
default
tacacs+ command or the aaa authentication
enable
default
tacacs+ command can be configured. If you attempt to configure
either of these commands first, the following message is displayed: Warning- Please configure exec
authorization using TACACS+ to get user privilege.
Likewise, the aaa authorization exec
default radius command must be configured
before the aaa authentication login
default radius command or the aaa authentication
enable
default radius command can be configured. If you attempt
to configure either of these commands first, the following message is displayed:
Warning- Please configure exec authorization using RADIUS to get user
privilege.
From FastIron 09.0.10a, the authentication method local can be added only if at least one configured local user is present on the ICX device. Likewise, the last available local user cannot be deleted if either login authentication or web-server authentication is using local as an authentication method.
The user privilege level is based on the privilege level granted during login. By default, a user enters User EXEC mode after a successful login through Telnet or SSH. Use the login privilege-mode option to allow a user to enter Privileged EXEC mode after a Telnet or SSH login.
The
no form of the command removes the authentication method.
The following example shows how to configure RADIUS as the primary authentication method for securing Telnet access to the CLI. If RADIUS authentication fails due to an error with the server, local authentication is used instead.
device# configure terminal device(config)# aaa authentication login default radius local
The following example shows how to configure RADIUS as the primary authentication method and other backup authentication methods.
device(config)# aaa authentication login default radius tacacs+ local