Configuring AAA
S e n d f e e d b a c k t o n x 5 0 0 0 - d o c f e e d b a c k @ c i s c o . c o m
Configuring Default Login Authentication Methods
The authentication methods include the following:
•
•
•
•
The default method is local.
Before you configure default login authentication methods, configure RADIUS or TACACS+ server
groups as needed. To configure default login authentication methods, perform this task:
Command
Step 1
switch# configure terminal
Step 2
switch(config)# aaa authentication login
default {group group-list [none]| local |
none}
Step 3
switch(config)# exit
Step 4
switch# show aaa authentication
Step 5
switch# copy running-config startup-config
Enabling Login Authentication Failure Messages
When you log in, the login is processed by the local user database if the remote AAA servers do not
respond. If you have enabled the displaying of login failure messages, the following message is
displayed :
Remote AAA servers unreachable; local authentication done.
Remote AAA servers unreachable; local authentication failed.
To enable login authentication failure messages, perform this task:
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
16-8
Global pool of RADIUS servers
Named subset of RADIUS or TACACS+ servers
Local database on the Nexus 5000 Series switch
Username only
Purpose
Enters configuration mode.
Configures the default authentication methods.
The group-list argument consists of a
space-delimited list of group names. The group
names are the following:
•
radius—Uses the global pool of RADIUS
servers for authentication.
•
named-group—Uses a named subset of
TACACS+ or RADIUS servers for
authentication.
The local method uses the local database for
authentication. The none method uses the username
only.
The default login method is local, which is used
when no methods are configured or when all of the
configured methods do not respond.
Exits configuration mode.
(Optional) Displays the configuration of the default
login authentication methods.
(Optional) Copies the running configuration to the
startup configuration.
Chapter 16
Configuring AAA
OL-16597-01