Re: CISCO - IAS Authentication

From: Harald Astrand (harald_astrand_at_REMOVE_hot_mail.comX)
Date: 09/07/04


Date: Tue, 7 Sep 2004 10:05:30 +0200

Hi,

First you define a local username on the router:

Router(config)# username USERNAME password PASSWORD

Then you specify that you first want to authenticate using radius and then the local database:

Router(config)# aaa authentication login default group radius local

Hope that helps!

Regards,

Harald

<MJC> wrote in message news:u8NcNDRkEHA.3372@TK2MSFTNGP09.phx.gbl...
> I know this may not fall under the heading of this newsgroup...but I'm
> hoping I can find help here.
>
> We recently enabled Radius authentication on our Cisco routers...to comply
> with SOX. We want to make sure that if for some reason our Radius pool blows
> up we can get in via a local account on the router. Does anyonw know the
> commands for IOS??
>
> Basically we want the default login to be radius...if that fails use the
> local database.



Relevant Pages

  • 5300 Access Server
    ... We have been using radius till now to validate dialup users, ... If the person connects with a valid username and password that should work ... aaa authentication login use-radius radius local ... aaa accounting exec Caller-ID start-stop radius ...
    (comp.dcom.sys.cisco)
  • Cisco Security Advisory: RADIUS Authentication Bypass
    ... Cisco Security Advisory: RADIUS Authentication Bypass ... Cisco has made free software available to address this vulnerability. ...
    (Bugtraq)
  • [Full-disclosure] Cisco Security Advisory: RADIUS Authentication Bypass
    ... Cisco Security Advisory: RADIUS Authentication Bypass ... Cisco has made free software available to address this vulnerability. ...
    (Full-Disclosure)
  • [NEWS] An Analysis of the RADIUS Authentication Protocol
    ... An Analysis of the RADIUS Authentication Protocol ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ...
    (Securiteam)
  • Re: wireless network disconnects when using IEEE 802.1x authentica
    ... > If your hardware can perform WPA PSK, ... > Change that authentication key say every six months. ... > individually setting keys in clients. ... > RADIUS server to do that, and it works best if you've got an Active ...
    (microsoft.public.windowsxp.security_admin)