Separating Authentication Methods; Disable Tacacs+ Authentication For Console - Cisco ASR 5500 System Administration Manual

Hide thumbs Also See for ASR 5500:
Table of Contents

Advertisement

Separating Authentication Methods

current session state
current privilege level
remote client application
remote client ip address
last server reply status
total TACACS+ sessions
Important
Separating Authentication Methods
You can configure separate authentication methods for accessing the Console port and establishing SSH/telnet
sessions (vty lines).
If you configure TACACS+ globally, access to the Console and vty lines are both authenticated using that
method.
Since the Console port is a last resort access to StarOS, you can configure local authentication for the Console
and employ TACACS+ for the vty lines.
Important
Separating authentication methods (Console versus vty lines) requires disabling Console access for users
based on the type of authentication.

Disable TACACS+ Authentication for Console

A noconsole keyword for the Global Configuration mode aaa tacacs+ command disables TACACS+
authentication on the Console line.
configure
aaa tacacs+ noconsole
exit
By default, TACACS+ server authentication is performed for login from a Console or vty line. With noconsole
enabled, TACACS+ authentication is bypassed in favor of local database authentication for a console line;
on vty lines, TACACS+ remains enabled.
Important
ASR 5500 System Administration Guide, StarOS Release 21.5
44
For details on all TACACS+ maintenance commands, refer to the Command Line Interface Reference.
This feature extends to AAA (Authentication, Authorization and Accounting) service as well as local
users. For example, local-users may have only Console access and AAA (VPN context) users with access
only via vty lines.
When aaa tacacs+ noconsole is configured, a local user with valid credentials can log into a Console port
even if on-authen-fail stop and on-unknown-user stop are enabled via the TACACS+ Configuration
mode. If the user is not a TACACS+ user, he/she cannot login on a vty line.
: user login complete
: 15
: ssh
: 111.11.11.11
: -1
: 1
System Settings

Advertisement

Table of Contents
loading

Table of Contents