Home > AAA TACACS+ and RADIUS Tutorial

AAA TACACS+ and RADIUS Tutorial

October 18th, 2018 Go to comments

In this part we will have some configuration of Authentication to help you grasp it.

Question

Suppose we configure AAA as follows.

aaa authentication login NO_AUTH none

line console 0
login authentication NO_AUTH

Which login credentials are required when connecting to the console port in this output?

Answer: The console port is authenticated with NO_AUTH list. But this list does not contain any authentication method (it uses “none”) so no authentication is required when connecting to the console port.

Question

Which login credentials are required when connecting to the VTY port in this output?

Router(config)#aaa authentication login default group radius local line

Answer: We used “default” method list so the authentication is applied to all login connections (even if there is no login authentication command). A group of “RADIUS, local and line” is defined so the device will first contact RADIUS server, then local username and finally line password.

Because we are using the list default in the aaa authentication login command, login authentication is automatically applied for all login connections (such as tty, vty, console and aux).

Question

Which login credentials are required when connecting to the VTY port in this output?

Router(config)# aaa authentication login default tacacs+ enable

Answer: The router first attempts to use the TACACS+ method for authentication, then the enable method. Therefore, the enable password is used to authenticate users if the device cannot contact the TACACS+ server.

Note: All the above configuration only uses the first “A” (Authentication) for demonstration. If you wish to learn about two other “A”s (Authorization and Accounting) please visit the Cisco links below:

+ Authorization: https://www.cisco.com/c/en/us/td/docs/ios/12_2/security/configuration/guide/fsecur_c/scfathor.html
+ Accounting: https://www.cisco.com/c/en/us/td/docs/ios/12_2/security/configuration/guide/fsecur_c/scfacct.html

Reference:

http://www.cisco.com/c/dam/en/us/products/collateral/security/secure-access-control-server-windows/prod_white_paper0900aecd80737943.pdf

https://www.cisco.com/c/en/us/support/docs/security-vpn/terminal-access-controller-access-control-system-tacacs-/10384-security.html

Comments (15) Comments
Comment pages
1 2 3 4228
  1. Anonymous
    October 15th, 2019

    ehab03291 at gmail.com

  2. ehab abdallah
    October 15th, 2019

    Please, can anyone send me 200-125 test dumps Please ehab03291 at gmail.com

  3. 9tut am greatful
    October 17th, 2019

    please share new update dumps for ccna rns 200-125 any one have please share with me on fredbons zero zero seven at gmail dot com

  4. irfan
    October 20th, 2019

    i have my ccna exam this 30th. any one please tell me which labs are coming during these days.
    share me on this iak4614(at)outlook(dot)com

  5. Anonymous
    October 20th, 2019

    If any one have latest Dumps for ccna 200-125 please share with me. I have exam on 30th on this month. iak4614(at)outlook(dot)com

  6. dmitry
    October 24th, 2019

    Pls send me dumps 200-125, my mail {email not allowed}

  7. ehab
    November 5th, 2019

    i’m taking the icnd1 exam soon, can anybody send me icnd1 dumps, that would be amazing, tamem2010ar @ gmail . com

  8. Nector
    November 13th, 2019

    Here is what you need dwz.win/qRc

  9. Anonymous
    November 19th, 2019

    pls am in dear need of recent dumps for CCNA 200-125 exams is in less than 1 week osuntobs (at) gmail

  10. Anonymous
    November 20th, 2019

    Please share the latest dumps for ccna 200-125 to {email not allowed}

  11. martial
    November 26th, 2019

    please help me share the lastest dump for ccna 200-125

  12. Anonymous
    December 3rd, 2019

    share please your latest dump for ccna 200-125, cbads @ hotmail . com

  13. Anonymous
    December 9th, 2019

    hi everyone, hopefully someone can help my exam, Please sned my latest dump of 200-125 exam at ehrgs30atgmaildotcom

  14. x.sk/vL9oh
    December 10th, 2019

    Here you GO. Just put “i” at beginning of my name and you will get the download link.
    Thank you

  15. Anonymous
    December 11th, 2019

    I have my exam in a week and would like the latest dumps for the 200-125 to test my knowledge.
    cynthia.fritz123 at gmail dot com

Comment pages
1 2 3 4228
Add a Comment