aaa authentication enable
aaa authentication enable
default
method-list
[
method-list
…
]no aaa authentication enable
default
method-list
[ method-list
…
]
The AAA authentication method list is not configured.
By default, the device prompts for a username and password.
Global configuration mode
You can specify a primary authentication method and up to two backup authentication methods. If the configured primary authentication fails due to an error, the device tries the backup authentication methods in the order they appear in the list.
The aaa authorization exec
default
tacacs+ command must be configured before the aaa authentication
login
default
tacacs+ command or the aaa authentication
enable
default
tacacs+ command can be configured. If you attempt to configure
either of these commands first, the following message is displayed: Warning- Please configure exec
authorization using TACACS+ to get user privilege.
Likewise, the aaa authorization exec
default radius command must be configured
before the aaa authentication login
default radius command or the aaa authentication
enable
default radius command can be configured. If you attempt
to configure either of these commands first, the following message is displayed:
Warning- Please configure exec authorization using RADIUS to get user
privilege.
If authentication is enabled on the device, when a user attempts to gain Super User access to the Privileged EXEC and global configuration levels of the CLI, by default the device prompts for a username and password.
From FastIron 09.0.00, the authentication method local can be added only if at least one configured local user is present on the ICX device. Likewise, the last available local user cannot be deleted if either login authentication or web-server authentication is using local as an authentication method.
The
no form of the command removes the authentication method.
The following example shows how to configure TACACS+ as the primary authentication method for securing access to the Privileged EXEC and global configuration levels of the CLI. In this example, TACACS+ is configured to be the primary authentication method for securing access. If TACACS+ authentication fails due to an error with the server, local authentication is used instead.
device# configure terminal device(config)# aaa authentication enable default tacacs+ local