AAA Servers in Common Criteria Mode

Common Criteria mode requires that devices support NDcPP version 2.1 or above. This standard requires the communication of the device with AAA servers to take place over a TLS-encrypted session.

Even though you can configure multiple TLS-encrypted RADIUS servers, only one connection can be active at any time. If another TLS-encrypted RADIUS session is attempted at the same time as the first RADIUS session, the connection attempt is rejected.

When the device is in Common Criteria Operational mode, and the device has been configured for a TLS encrypted RADIUS server for authentication, only one administrator is able to administer the device. In addition, accounting and authorizing using the TLS-encrypted RADIUS server are disabled.

Note: You must configure users before enabling the aaa console; otherwise, you may be logged off and locked out of the system.

After configuring users, enter the aaa command and enable the AAA console as shown in the following example.
device# configure terminal 
device(config)# aaa authentication login default local
device(config)# enable aaa console