Re: aaa new-model

From: Marc La Porte (marc.a.laporte@gmail.com)
Date: Mon Sep 03 2007 - 13:23:47 ART


That would work fine, if the assignment is to configure aaa with basically
no authentication. Usually you are asked to configure aaa authentication
with either local, TACACS+ or RADIUS authentication. You could always put
the none keyword at the end (if that's permitted in the assignment), it
would just take you a long time then before you can finally login

On 9/3/07, devecchio turner <dt30083@gmail.com> wrote:
>
> On 9/3/07 10:56 AM, "ini akpabio" <iakpabio@swiftng.com> wrote:
>
> > Guys the VTY and CONSOLE terms u used are just the name of the
> > authentication line so both of them are correct.
> >
> > You can also use - aaa authentication login default line local
> >
> > You don't have to re-apply it to the vty lines since its d default once
> u
> > enable aaa..
> >
> > -----Original Message-----
> > From: nobody@groupstudy.com [mailto:nobody@groupstudy.com] On Behalf Of
> Marc
> > La Porte
> > Sent: Monday, September 03, 2007 4:03 PM
> > To: ISolveSystems
> > Cc: Pat More; ccielab@groupstudy.com
> > Subject: Re: aaa new-model
> >
> > Weren't you talking about telnet login? Should it not be:
> >
> > aaa authentication login VTY line local
> > !
> > line vty 0 15
> > password cisco
> > login authentication VTY
> >
> >
> >
> > On 9/3/07, ISolveSystems <support@isolvesystems.com> wrote:
> >>
> >> Do this:-
> >> aaa authentication login CONSOLE line local
> >>
> >> line con 0
> >> password abc123
> >> login authentication CONSOLE
> >>
> >>
> >> On 9/3/07, Pat More <more2go@hotmail.com> wrote:
> >>>
> >>> Hi group,
> >>>
> >>> As you aware that, once you configure aaa new-model, the IOS will
> change
> >>> the way of telnet login. It will aspecting a username and password.
> >>>
> >>> Can someone advise what precaution I have to take in order not to lock
> >> the
> How aboult
>
> Aaa new-model
> Aaa authentication login default none
> And then apply specfic methods for the lines you want to secure.. The key
> is
> not to lock urself out.. So by defining none as the default..ur goal is
> accomplished?
>
>
>
> >>> router/switch in lab?
> >>> I am not sure how the script will access the router for marking.
> >>>
> >>> regards
> >>> _________________________________________________________________
> >>> News, entertainment and everything you care about at Live.com. Get it
> >> now!
> >>> http://www.live.com/getstarted.aspx
> >>>
> >>>
> _______________________________________________________________________
> >>> Subscription information may be found at:
> >>> http://www.groupstudy.com/list/CCIELab.html
> >>
> >> _______________________________________________________________________
> >> Subscription information may be found at:
> >> http://www.groupstudy.com/list/CCIELab.html
> >
> > _______________________________________________________________________
> > Subscription information may be found at:
> > http://www.groupstudy.com/list/CCIELab.html
> >
> > _______________________________________________________________________
> > Subscription information may be found at:
> > http://www.groupstudy.com/list/CCIELab.html



This archive was generated by hypermail 2.1.4 : Sat Oct 06 2007 - 12:01:09 ART