aaa authentication snmp-server
aaa authentication snmp-server
default
method-list
[
method-list
...
]
no aaa authentication snmp-server
default
method-list
[
method-list
...
]
The AAA authentication method list is not configured.
- method-list
- Configures the following authentication methods.
- enable
- Authenticate using the password you configured for the Super User privilege level.
This password is configured using the
enable super-user-passwordcommand. - line
- Authenticate using the password you configured for Telnet access. The Telnet password
is configured using the
enable telnet passwordcommand - local
- Authenticate using a local username and password you configured on the device. Local
usernames and passwords are configured using the
usernamecommand. - radius
- Authenticate using the database on a RADIUS server. You also must identify the server
to the device using the
radius-servercommand. - tacacs
- Authenticate using the database on a TACACS server. You also must identify the server
to the device using the
tacacs-servercommand.
Global configuration mode
You can specify a primary authentication method and up to six backup authentication methods. If the configured primary authentication fails due to an error, the device tries the backup authentication methods in the order they appear in the list.
From FastIron release 08.0.90, the method "local" will be removed from all aaa configurations if the last user is removed from the device. The configuration "enable aaa console" will be removed automatically if the last local user is removed from the device and the only authentication method is local. This prevents users from being locked out of the device.
When this command is enabled, community string validation is not performed for incoming SNMP v1and v2c packets. This command takes effect as long as the first varbind for SNMP packets is set to one of the following:
- snAgGblPassword=" username password " (for AAA method local)
- snAgGblPassword=" password " (for AAA method line, enable)
If AAA is set up to check both the username and password, the string contains the
username, followed by a space and then the password. If AAA is set up to authenticate
with the current Enable or Line password, the string contains the password only. The
configuration can be overridden by the
no snmp-server pw-check command, which disables password checking for SNMP SET requests.
The
no form of the command removes the authentication method.
| Release version | Command history |
|---|---|
| 08.0.90 | The command was modified as described in the usage guidelines. |