Configuring Authentication-method Lists for RADIUS
You can use RADIUS to authenticate Telnet or SSH access and access to the Privileged EXEC and global configuration levels of the CLI. When you configure authentication-method lists for RADIUS, you must create an authentication-method list for Telnet or SSH CLI access and a second separate authentication-method list for access to the Privileged EXEC and global configuration levels of the CLI.
Within the authentication-method list, RADIUS is specified as the primary authentication method, and other authentication methods are specified as alternates. If RADIUS authentication fails, the device tries the alternate authentication methods in the order they appear in the list.
Perform the following steps to configure authentication-method lists for remote and CLI access.
- Enter global configuration mode.
- If it is not already configured, configure the AAA authorization default as RADIUS, followed by any alternative methods you want to configure.
- Enter the
aaa authentication logincommand followed by the desired authentication-method list parameters.Note: Refer to Authentication-Method Values for available RADIUS authentication-method list parameters.The following example creates an authentication-method list for securing remote Telnet or SSH access to the CLI.In the example, the default parameter specifies that the methods listed on the same line form the default authentication-method list. The example configures RADIUS as the primary authentication method for securing remote Telnet or SSH access to the CLI. If RADIUS authentication fails due to a server error, local authentication is used instead. If local authentication fails, access is not granted. - Configure authentication methods
for access to the Privileged EXEC and global configuration levels of the CLI.
Enter the
aaa authentication enablecommand followed by desired parameters.The following example configures authentication methods for securing access to the Privileged EXEC level and CONFIG levels of the CLI.The example configures RADIUS as the primary authentication method for securing access to the Privileged EXEC and CONFIG levels of the CLI. If RADIUS authentication fails due to a server error, local authentication is used instead. If local authentication fails, access to the Privileged EXEC and CONFIG levels of the CLI is not allowed.