Separating Authentication Methods - Cisco ASR 5000 Series Administration Manual

Staros release 21.4
Hide thumbs Also See for ASR 5000 Series:
Table of Contents

Advertisement

Separating Authentication Methods

Important
Separating Authentication Methods
You can configure separate authentication methods for accessing the Console port and establishing SSH/telnet
sessions (vty lines).
If you configure TACACS+ globally, access to the Console and vty lines are both authenticated using that
method.
Since the Console port is a last resort access to StarOS, you can configure local authentication for the Console
and employ TACACS+ for the vty lines.
Important
Separating authentication methods (Console versus vty lines) requires disabling Console access for users
based on the type of authentication.
Disable TACACS+ Authentication for Console
A noconsole keyword for the Global Configuration mode aaa tacacs+ command disables TACACS+
authentication on the Console line.
configure
aaa tacacs+ noconsole
exit
By default, TACACS+ server authentication is performed for login from a Console or vty line. With noconsole
enabled, TACACS+ authentication is bypassed in favor of local database authentication for a console line;
on vty lines, TACACS+ remains enabled.
Important
Disable AAA-based Authentication for Console
A noconsole keyword for the Global Configuration mode local-user allow-aaa-authentication command
disables AAA-based authentication on the Console line.
configure
local-user allow-aaa-authentication noconsole
exit
ASR 5500 System Administration Guide, StarOS Release 21.4
64
For details on all TACACS+ maintenance commands, refer to the Command Line Interface Reference.
This feature extends to AAA (Authentication, Authorization and Accounting) service as well as local
users. For example, local-users may have only Console access and AAA (VPN context) users with access
only via vty lines.
When aaa tacacs+ noconsole is configured, a local user with valid credentials can log into a Console port
even if on-authen-fail stop and on-unknown-user stop are enabled via the TACACS+ Configuration
mode. If the user is not a TACACS+ user, he/she cannot login on a vty line.
System Settings

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asr 5500

Table of Contents