radius
tacacs
Default Configuration
If the default list is not set, only the enable password is checked. This has the same effect as
the command aaa authentication enable default enable.
On the console, the enable password is used if it exists. If no password is set, the process still
succeeds. This has the same effect as using the command aaa authentication enable default
enable none.
Command Mode
Global Configuration mode
User Guidelines
•
The default and optional list names created with the aaa authentication enable command are
used with the enable authentication command.
•
The additional methods of authentication are used only if the previous method returns an
error, not if it fails. To ensure that the authentication succeeds even if all methods return an
error, specify none as the final method in the command line.
•
All aaa authentication enable default requests sent by the device to a RADIUS or TACACS+
server include the username $enabx$., where x is the requested privilege level.
Example
The following example sets the enable password for authentication when accessing higher
privilege levels.
Console(config)# aaa authentication enable default enable
login authentication
The login authentication Line Configuration mode command specifies the login
authentication method list for a remote telnet or console. To return to the default configuration
specified by the aaa authentication login command, use the no form of this command.
D E L L C O N F I D E N T I A L – P R E L I M I N A R Y 9 / 1 3 / 0 6 – F O R P R O O F O N LY
Uses the list of all RADIUS servers for authentication. Uses username
$enabx$., where x is the privilege level.
Uses the list of all TACACS+ servers for authentication. Uses username
"$enabx$." where x is the privilege level.
75
AAA Commands