Error-Enabled Status - Cisco MDS 9000 Series Configuration Manual

Security
Hide thumbs Also See for MDS 9000 Series:
Table of Contents

Advertisement

Configuring Security Features on an External AAA Server
Caution
Cisco MDS NX-OS supports user names that are created with alphanumeric characters or specific special
characters (+ [plus], = [equal], _ [underscore], - [hyphen] , \ [backslash], and . [period]) whether created
remotely (using TACACS+ or RADIUS) or locally, provided the user name starts with an alphabetical character.
Local user names cannot be created with all numbers or with any special characters (apart from those specified).
If a numeric-only user name or a non-supported special character user name exists on an AAA server, and is
entered during login, then the user is denied access.
Note
Even if local is not specified as one of the options, it is tried by default if all AAA servers configured for
authentication are unreachable. User has the flexibility to disable this fallback.
When RADIUS times out, local login is attempted depending on the fallback configuration. For this local
login to be successful, a local account for the user with the same password should exist, and the RADIUS
timeout and retries should take less than 40 seconds. The user is authenticated if the username and password
exist in the local authentication configuration.
The following table provides the related CLI command for each AAA service configuration option.
Table 3: AAA Service Configuration Commands
AAA Service Configuration Option
Telnet or SSH login (Cisco Fabric Manager and Device Manager login)
Console login
iSCSI authentication
FC-SP authentication
Accounting
Note
If we do not configure any authentication method for the console, the default authentication method will be
applied for both console and Telnet or SSH.

Error-Enabled Status

When you log in, the login is processed by rolling over to local user database if the remote AAA servers do
not respond. In this situation, the following message is displayed on your screen if you have enabled the
error-enabled feature:
Remote AAA servers unreachable; local authentication done.
To enable this message display, use the aaa authentication login error-enable command.
To disable this message display, use the no aaa authentication login error-enable command.
Cisco MDS 9000 Series Security Configuration Guide, Release 8.x
Error-Enabled Status
Related Command
aaa authentication login default
aaa authentication login console
aaa authentication iscsi default
aaa authentication dhchap default
aaa accounting default
33

Advertisement

Table of Contents
loading

Table of Contents