Examples of Authentication-method Lists

The following examples show how to configure authentication-method lists. In these examples, the primary authentication method for each is local. The device authenticates access attempts using the locally configured usernames and passwords.

Example 1

To configure an authentication-method list for the Privileged EXEC and CONFIG levels of the CLI, enter the aaa authentication enable default command followed by the primary authentication method (and, as an option, authentication methods you want to designate as alternatives).

device# configure terminal
device(config)# aaa authentication enable default local

The example configures the device to use local user accounts to authenticate attempts to access the Privileged EXEC and CONFIG levels of the CLI. No alternate methods of authentication are configured.

Example 2

To configure the device to use a RADIUS server first to authenticate access to the Privileged EXEC and CONFIG levels of the CLI, enter the aaa authentication enable default command followed by the keyword radius (and, as an option, authentication methods you want to designate as alternatives).

Note: The aaa authorization exec default radius command must be configured beforehand.

device# configure terminal
device(config)# aaa authorization exec default radius
device(config)# aaa authentication enable default radius local

The example configures the device to consult a RADIUS server first to authenticate attempts to access the Privileged EXEC and CONFIG levels of the CLI and then to consult the local user accounts if the RADIUS server is unavailable.

Example 2

To configure the device to use a RADIUS server first to authenticate Web access, enter the aaa authentication web-server login default command followed by the keyword radius (and, as an option, authentication methods you want to designate as alternatives).

Note: For Web access, only authentication is validated. Authorization and accounting are not validated.

device# configure terminal
device(config)# aaa authentication web-server login default radius local

The example configures the device to consult a RADIUS server first to authenticate Web access and then to consult the local user accounts if the RADIUS server is unavailable.

Authentication Methods Available

When you enter an authentication list for any of the AAA authentication commands, the first authentication listed is the primary method of authentication. Additional methods of authentication listed are used as alternates if the primary authentication fails.

The following table lists available values that can be entered as authentication methods.

Note: TACACS+ and RADIUS authentication options are supported only with the enable and login access parameters.

Authentication method values

Method Parameter

Description

local

Authenticate using a local user name and password you configured on the device. Local user names and passwords are configured using the username... command. Refer to Configuring Local User Accounts.

tacacs+

Authenticate using the database on a TACACS+ server. You also must identify the server to the device using the tacacs-server command.

radius

Authenticate using the database on a RADIUS server. You also must identify the server to the device using the radius-server command. Refer to RADIUS Security.

Default Authentication Values

By default, the following AAA authentication methods are configured:

  • aaa authentication login default local
  • aaa authentication web-server default local