Examples of Authentication-method Lists
The following examples show how to configure authentication-method lists. In these examples, the primary authentication method for each is local. The device authenticates access attempts using the locally configured usernames and passwords.
To configure an authentication-method list for the Web Management Interface, enter
the
aaa authentication web-server default command followed by the primary authentication method (and, as an option, authentication
methods you want to designate as alternates).
device# configure terminal device(config)# aaa authentication web-server default local
The example configures the device to use local user accounts to authenticate access to the device through the Web Management Interface. No alternate access methods are configured. If the device does not have a user account that matches the user name and password entered, the user is not granted access.
To configure an authentication-method list for SNMP, enter the
aaa authentication snmp-server default command followed by the primary authentication method (and, as an option, authentication
methods you want to designate as alternates).
device# configure terminal device(config)# aaa authentication snmp-server default local
The example allows certain incoming SNMP SET operations to be authenticated using
the locally configured usernames and passwords. No alternate access methods are configured.
When the
aaa authentication snmp-server default command is enabled, community string validation is not performed for incoming SNMP
V1 and V2c packets. This command takes effect as long as the first varbind for SNMP
packets is set to one of the following:
- snAgGblPassword=" username password " (for AAA method local)
- snAgGblPassword=" password " (for AAA method line, enable)
If AAA is set up to check both the username and password, the string contains the username, followed by a space and then the password. If AAA is set up to authenticate with the current Enable or Line password, the string contains the password only.
To configure an authentication-method list for the Privileged EXEC and CONFIG levels
of the CLI, enter the
aaa authentication enable default command followed by the primary authentication method (and, as an option, authentication
methods you want to designate as alternates).
device# configure terminal device(config)# aaa authentication enable default local
The example configures the device to use local user accounts to authenticate attempts to access the Privileged EXEC and CONFIG levels of the CLI. No alternate methods of authentication are configured.
To configure the device to use a RADIUS server first to authenticate access to the
Privileged EXEC and CONFIG levels of the CLI, enter the
aaa authentication enable default command followed by the keyword radius (and, as an option, authentication methods
you want to designate as alternates).
device# configure terminal device(config)# aaa authentication enable default radius local
The example configures the device to consult a RADIUS server first to authenticate attempts to access the Privileged EXEC and CONFIG levels of the CLI and then to consult the local user accounts if the RADIUS server is unavailable.
Authentication Methods Available
When you enter an authentication list for any of the AAA authentication commands, the first authentication listed is the primary method of authentication. Additional methods of authentication listed are used as alternates if the primary authentication fails.
The following table lists available values that can be entered as authentication methods.
Authentication method values
Method Parameter |
Description |
|---|---|
line |
Authenticate using the password you configured for Telnet access. The Telnet password is configured using the enable telnet password... command. Refer to Configuring Telnet Remote Access. |
enable |
Authenticate using the password you configured for the Super User privilege level. This password is configured using the enable super-user-password... command. Refer to Configuring Local User Accounts. |
local |
Authenticate using a local user name and password you configured on the device. Local user names and passwords are configured using the username... command. Refer to Configuring Local User Accounts. |
tacacs |
Authenticate using the database on a TACACS server. You also must identify the server to the device using the tacacs-server command. |
tacacs+ |
Authenticate using the database on a TACACS+ server. You also must identify the server to the device using the tacacs-server command. |
radius |
Authenticate using the database on a RADIUS server. You also must identify the server to the device using the radius-server command. Refer to RADIUS Security. |
none |
Do not use any authentication method. The device automatically permits access. |