Re: AAA Default and Lists

From: Adam Booth <adam.booth_at_gmail.com>
Date: Tue, 17 May 2011 11:02:21 +1000

Hi Andrew,

Is this example of any help?

If you had a config fragment like:

aaa new-model
aaa authentication login default none
aaa authentication login local-auth local
username test password test
line vty 0 4
 login authentication local-auth

If you were to telnet to the device you will do local pasword database
authentication but if you were to use the console (nothing is specified, so
it's using the default method), you bypass the authentication phase and have
a console

Cheers,
Adam

On Tue, May 17, 2011 at 9:54 AM, ALL From_NJ <all.from.nj_at_gmail.com> wrote:

> Hey team,
>
> I am trying to study a bunch of things tonight, and figured I would 'punt'
> this one to the group to see if anyone has a good link or anything.
>
> Question - when I configure aaa for a particular method, for example ssh,
> ppp, or whatever, and I create a new list name, will this affect the
> default
> list in any way?
>
> For example, lets say I create a list called ppp, but do not change the
> default and only specify my new list on my ppp interfaces. Is the default
> still in effect for the console, web, or vty ports?
>
> My testing says yes, but you know (LOL!!!)... perhaps I am missing
> something
> also (would not be the first time ;-)). Just figured I would send this out
> there to see if anyone had additional comments or thoughts.
>
> Any good suggestions for links?
>
> TIA,
>
> --
> Andrew Lee Lissitz
> all.from.nj_at_gmail.com
>
>
> Blogs and organic groups at http://www.ccie.net
>
> _______________________________________________________________________
> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html

Blogs and organic groups at http://www.ccie.net
Received on Tue May 17 2011 - 11:02:21 ART

This archive was generated by hypermail 2.2.0 : Wed Jun 01 2011 - 09:01:11 ART