Examples of Authentication-method Lists

The following examples show how to configure authentication-method lists. In these examples, the primary authentication method for each is local. The device authenticates access attempts using the locally configured usernames and passwords.

Example 1

To configure an authentication-method list for the Web Management Interface, enter the aaa authentication web-server default command followed by the primary authentication method (and, as an option, authentication methods you want to designate as alternates).

device# configure terminal
device(config)# aaa authentication web-server default local

The example configures the device to use local user accounts to authenticate access to the device through the Web Management Interface. No alternate access methods are configured. If the device does not have a user account that matches the user name and password entered, the user is not granted access.

Example 2

To configure an authentication-method list for SNMP, enter the aaa authentication snmp-server default command followed by the primary authentication method (and, as an option, authentication methods you want to designate as alternates).

device# configure terminal
device(config)# aaa authentication snmp-server default local

The example allows certain incoming SNMP SET operations to be authenticated using the locally configured usernames and passwords. No alternate access methods are configured. When the aaa authentication snmp-server default command is enabled, community string validation is not performed for incoming SNMP V1 and V2c packets. This command takes effect as long as the first varbind for SNMP packets is set to one of the following:

  • snAgGblPassword=" username password " (for AAA method local)
  • snAgGblPassword=" password " (for AAA method line, enable)
Note: Certain SNMP objects require additional validation. These objects include but are not limited to: snAgReload, snAgWriteNVRAM, snAgConfigFromNVRAM, snAgImgLoad, snAgCfgLoad and snAgGblTelnetPassword. For more information, refer to snAgGblPassword in the RUCKUS FastIron MIB Reference.

If AAA is set up to check both the username and password, the string contains the username, followed by a space and then the password. If AAA is set up to authenticate with the current Enable or Line password, the string contains the password only.

Note: The previous configuration can be overridden by the command no snmp-server pw-check , which disables password checking for SNMP SET requests.

Example 3

To configure an authentication-method list for the Privileged EXEC and CONFIG levels of the CLI, enter the aaa authentication enable default command followed by the primary authentication method (and, as an option, authentication methods you want to designate as alternates).

device# configure terminal
device(config)# aaa authentication enable default local

The example configures the device to use local user accounts to authenticate attempts to access the Privileged EXEC and CONFIG levels of the CLI. No alternate methods of authentication are configured.

Example 4

To configure the device to use a RADIUS server first to authenticate access to the Privileged EXEC and CONFIG levels of the CLI, enter the aaa authentication enable default command followed by the keyword radius (and, as an option, authentication methods you want to designate as alternates).

device# configure terminal
device(config)# aaa authentication enable default radius local

The example configures the device to consult a RADIUS server first to authenticate attempts to access the Privileged EXEC and CONFIG levels of the CLI and then to consult the local user accounts if the RADIUS server is unavailable.

Authentication Methods Available

When you enter an authentication list for any of the AAA authentication commands, the first authentication listed is the primary method of authentication. Additional methods of authentication listed are used as alternates if the primary authentication fails.

The following table lists available values that can be entered as authentication methods.

Note: TACACS/TACACS+ and RADIUS authentication options are supported only with the enable and login access parameters.

Authentication method values

Method Parameter

Description

line

Authenticate using the password you configured for Telnet access. The Telnet password is configured using the enable telnet password... command. Refer to Configuring Telnet Remote Access.

enable

Authenticate using the password you configured for the Super User privilege level. This password is configured using the enable super-user-password... command. Refer to Configuring Local User Accounts.

local

Authenticate using a local user name and password you configured on the device. Local user names and passwords are configured using the username... command. Refer to Configuring Local User Accounts.

tacacs

Authenticate using the database on a TACACS server. You also must identify the server to the device using the tacacs-server command.

tacacs+

Authenticate using the database on a TACACS+ server. You also must identify the server to the device using the tacacs-server command.

radius

Authenticate using the database on a RADIUS server. You also must identify the server to the device using the radius-server command. Refer to RADIUS Security.

none

Do not use any authentication method. The device automatically permits access.