AAA and TACACS on everything BUT NOT console

Would like to enable login authentication AND enable authentication on VTY but NOT console. Console should authenticate locally for both user and privilige modes ... I can't seem to seperate the 'enable' piece ... any thoughts?

I do not think you can separate method list for
the enable piece. I've asked Cisco about this
in the past and they told me that it is not
possible. You can have a different method list
for the console for the "exec" mode but not
the enable or privilege mode. It is either
"tacacs" or "enable" or some other
combinations but not a separate method list for "enable" by itself. Maybe cisco added
this new feature in 12.4. I've my my testing
on both 12.2T and 12.3T and, IMHO, it is not
possible to separate the enable piece. Here
is my config:
username cisco password cisco
enable secret cisco
aaa authentication login notac local
aaa authentication login VTY group tacacs+ local
aaa authentication login web local enable
aaa authentication enable default group tacacs+ enable
aaa authorization console
aaa authorization config-commands
aaa authorization exec notac none
aaa authorization exec VTY group tacacs+ if-authenticated none
aaa authorization commands 0 VTY group tacacs+ if-authenticated none
aaa authorization commands 1 VTY group tacacs+ if-authenticated none
aaa authorization commands 15 VTY group tacacs+ if-authenticated none
aaa authorization network VTY group tacacs+ if-authenticated none
aaa accounting exec TAC start-stop group tacacs+
aaa accounting exec VTY start-stop group tacacs+
aaa accounting commands 0 TAC start-stop group tacacs+
aaa accounting commands 0 VTY start-stop group tacacs+
aaa accounting commands 1 TAC start-stop group tacacs+
aaa accounting commands 1 VTY start-stop group tacacs+
aaa accounting commands 10 TAC start-stop group tacacs+
aaa accounting commands 15 TAC start-stop group tacacs+
aaa accounting commands 15 VTY start-stop group tacacs+
aaa accounting network VTY start-stop group tacacs+
aaa accounting connection TAC start-stop group tacacs+
aaa session-id common
line con 0
exec-timeout 0 0
authorization exec notac
accounting commands 0 VTY
accounting commands 1 VTY
accounting commands 15 VTY
accounting exec VTY
logging synchronous
login authentication notac
line vty 0 15
exec-timeout 0 0
authorization commands 0 VTY
authorization commands 1 VTY
authorization commands 15 VTY
authorization exec VTY
accounting commands 0 VTY
accounting commands 1 VTY
accounting commands 15 VTY
accounting exec VTY
login authentication VTY

Similar Messages

  • PC Used to work with XP and airport Extreme Basestation but not with Vista

    Please help, my PC Used to work with XP and airport Extreme Basestation but not now with Vista. I have a MacBook Pro connected and also a Mac Pro connected to the network on it and they still work, i have put the latest software on the PC and the firmware is up to date. The only thing i can see on the network on the PC is the basestation Hard Disk (shared also to the Macs) but i cannot connect with the password, i have tried everything in my knowledge, including formatting the machine and reinsatlling OS and changing security setting to no avail. Any ideas anyone?

    With regard to your printer problem - take a look at this discussion:
    http://discussions.apple.com/thread.jspa?messageID=6312413&tstart=0

  • TS1646 hello  I have problem with regist my visa and I cannot buy from store the message came in the end of form is says the phone number must be a 7-digit number and I have writed but not accepted iam from saudi arabia my mobile is 966504850992 pls answe

    hello 
    I have problem with regist my visa and I cannot buy from store
    the message came in the end of form is says
    the phone number must be a 7-digit number
    and I have writed but not accepted
    iam from saudi arabia
    my mobile is 966504850992
    pls answer
    thanks
    dfr aldossary

    Wow, Karan Taneja, you've just embarrassed yourself on a worldwide support forum.  Not only is your post ridiculous and completely inappropriate for a technical support forum, but it also shows your ignorance as to whom you think the audience is.  Apple is not here.  It's users, like you. 
    If you would have spent half the time actually reading the Terms of Use of this forum that YOU agreed to by signing up to post, as you did composing that usesless, inappropriate post, you (and the rest of us on this forum) would have been much better off.

  • I have a php module which runs fine in Firefox and all other browsers but not Safari. It always run twice - I see a small ? in upper right corner which is causing it to run twice but NO idea why? Help - thank you

    I have a php module which runs fine in Firefox and all other browsers but not Safari. It always run twice - I see a small ? in upper right corner which is causing it to run twice but NO idea why? I read it MAY have something to do with am image it cannot load but I see them all loaded.  Help - thank you

    Could you share a link to the page?
    Seeing it in context and in our browsers is much easier to debug.
    If not, make sure to run the validator here The W3C Markup Validation Service and clear out any problems. HTML errors, especially structural ones, will cause all kinds of display problems in various browsers/versions/platforms.

  • TS3999 I see all of my calendar events in iCal and on my iPhone, but not in the iCloud web app.  Any ideas why?

    I see all of my calendar events in iCal and on my iPhone, but not in the iCloud web app.  Any ideas why?

    If the calendar is on iCoud.com, all you would need to do to get it on your phone is go to Settings>iCloud on your phone, sign into your iCoud account and turn Calendars on.  The iCloud calendars will then download to your phone.

  • TA25361 I have a ton of documents and databases in AppleWorks v 6.0 that I can no longer open on my MacBook Pro.  Is there any way to recover this info?  Some documents can be opened and resaved with textedit, but not my database with all important addres

    I have a ton of documents and databases in AppleWorks v 6.0 that I can no longer open on my MacBook Pro.  Is there any way to recover this info?  Some documents can be opened and resaved with textedit, but not my database with all important addresses.

    I tried Peggy's List > Select All > Copy > Paste into an AW spreadsheet suggestion.
    In my case, pasting into the spreadsheet lost all text formatting (mostly text set to bold). The results of formulas were pasted, and checkboxes were pasted as "on" or "off". The DB did not contain any pop-up menus or radio buttons, but I expect they would transfer as a number showing the list position of the chosen item.
    Pasting the copied List view data into a Numbers table gave a result similar to that with AppleWorks. I selected B2 as the target cell (for top left cell of the pasted data) to avoid any effects of posting into a header row or column. Bold and regular text formatting looked the same as it had in AW's List view.
    Based on that, I'd slip the 'paste into an AppleWorks Spreadsheet step, and paste directly into a Numbers Table.
    Regards,
    Barry

  • I am currently managing 20 iPads on a macbook. I would like to manage the same 20 iPads on a new macbook pro. I have logged into the iTunes account on the new machine and see our apps but not the devices. How do i get the devices to be shown on new comp?

    I am currently managing 20 iPads on a macbook. I would like to manage the same 20 iPads on a new macbook pro. I have logged into the iTunes account on the new machine and see our apps but not the devices. How do i get the devices to be shown on new comp?

    Has anyone used apple cpnfigurator for this purpose?

  • TS1398 help!!!  i am unable to connect to a wifi network and ive tried everything but nothing seems to work!!! can someone help pls

    help!!!  i am unable to connect to a wifi network and ive tried everything but nothing seems to work!!! can someone help pls

    try connecting to another wifi network to isolate the issue. at this point it's impossible to tell if it's your phone or your network

  • Can I change my podcast subscription to only put a new episode as visible and in the cloud, but not actually download it?

    Can I change my podcast subscription to only put a new episode as visible and in the cloud, but not actually download it?

    The person who holds the copyright to it in the UK hasn’t given Apple permission to sell it there; if desired, click here and fill out the form.
    (116905)

  • There was away (before Mavericks) I could single click on an email and it would highlite but not open.  I could either delete or second click and the email would then open.  Can anyone tell me how to configure the prevue pane to that end with Mavericks?

    There was a way (before Mavericks) I could single click on an email in the "prevue pane" and it would highlite but not open.  I could then either delete it or click again and it would open.  With Mavericks that doesn't seem to be available making it impossible to delete an email in the prevue pane before I open it.  Its frustrating to have to go through all the monkey motions when I know I want to delete it from the get-go.  Does anyone know who to configure for that operation?  I'm using an iMac. 

    Wow,  have you ever seen 1 Billion in hard cash?  If not, I assure you it exists as well. 
    Try not to pick apart what others write because you "have not seen it." 
    I run TWO programs for protection of my MAC now and have been for sometime b/c developers of them become complacid thinking MAC is impermeable. 
    My MAC locked me out of it and two externals and when I finally did get back into them Norton Anti-Virus found a "worm."  When I asked the program to find the origin, it was traced back to an email, as you said, that I opened unintentionally.  I still have two external HDs for backup and a cloud backup now. 
    When ClamX ran after Norton was finished, ClamX found what it called as "spyware," and it's origin was in my email also.  I tried to delete the emails after the programs (both) identified the infected files, however once deleted and the computer is restarted, they were still there because I ran the scans again. 
    Now since we are no longer talking about how to turn on and off the view pane in apple mail; riddle me this,  why can't the developers of these antivirus and antispyware/malware programs get together and develop ONE PRODUCT that catches 90-95% of the viruses/worms/spyware/malware ect that get onto MAC's?  Is it because they are too busy thinking they don't exist? 
    I still run both programs and feel protected between the two.  If Norton said it was a "worm" then I believe it was a worm and if ClamX called it "spyware" then I believe it is spyware. 
    I had to wipe my MAC and do a fresh install to get it working again, then I had to open one of those externals (which was very, very difficult) multiple times until finally it displayed the message "you can view, but not change the data."  I exported as much as I could to my cloud and I had to format both of those too. 
    I still run both programs as I feel protected between the two.  If Norton tells me it is a "worm" then I believe it is a "worm;" if ClamX tells me it is "spyware" then I believe it is "spyware."  If it happens again, which my hope is that it won't, I will be more than happy to send the infected files to you!!
    Try not to "forum rage."  Support forums to post experiences and find answers, not nit-pick or claim not existance b/c you have not experienced it for yourself.

  • Why is apple id being disabled .? and i rs this  . but not replay my email ?

    why is apple id being disabled .? and i rs this  . but not replay my email ?

    Don't post your IDs or other personal information here. These are user-to-user support forums, not a method for communicating with Apple. I've asked the Communities Hosts to remove your personal information.
    As to your problem, if you have forgotten the password to your Apple ID, try this web page:
    https://iforgot.apple.com
    If that does not help, you will need to call Apple Support, ask to speak with Account Security, and work with them to reset your password.
    Regards.

  • Why can I open attachments (pptx and PDF) on iPhone but not on Mac?

    Why can I open attachments (pptx and PDF) on iPhone but not on my MacAir (OS X 10.9.2)? Generally, I can open PDFs on my Mac, but in this case, I opened on iPhone, and not on computer! Also pptx file from one sender opened on iPhone, and not on Mac, and the same pptx sent from another person wouldn't open on either! Help!

    Hi there.  I think as far as PowerPoint files go (pptx) you will need a copy of Office or some other compatible software (e.g. Keynote) to open it on your Mac.  On an iPhone there is a viewer built in just so you can take a look at most common attachment types.  If you have a copy of Microsoft Office on your Mac you should be able to open the pptx files in PowerPoint.
    OS X definitely has a PDF viewer, it's called Preview.  I think you can also load Adobe Acrobat if you want but I've stayed away from it for years as I find Preview faster and better.
    If you still can't open a PDF file attached to an email message on your MacAir by double clicking on it, could you let us know what error message you get, or what happens?  That will help people to help you.
    Ivan

  • AAA and TACACS servers

    Hello All,
    I want to download a free, yet reliable AAA and TACACS servers, can you guide me? Also, I need help with configuring them for study purpose.

    You may download the eval version ACS 4.2.0.124, if you've access to cisco.com
    ACS v4.2.0.124 90-Days Evaluation Software
    eval-ACS-4.2.0.124-SW.zip
    http://tools.cisco.com/squish/9B37e
    Path:
    Cisco.com > Downloads Home > Products > Cloud and Systems Management > Security and Identity Management
    > Cisco Secure Access Control Server Products > Cisco Secure Access Control Server for Windows > Cisco Secure ACS 4.2 for Windows > Secure Access Control Server (ACS) for Windows-4.2.0.124
    ~BR
    Jatin Katyal
    **Do rate helpful posts**

  • I have CC and other apps load but not PS

    I have CC and other apps load but not PS

    Without proper technical info like system specs nobody can say anything.
    Mylenium

  • When I look up the creation date for files on my Macbook I get the date and month in brackets, but not the year.  Why is this and how can I look up the year?

    When I look up the creation date for files on my Macbook (using "get info", or the information window in Iphoto) I get the date and month in brackets, but not the year.  Why is this and how can I look up the year? 

    Does the Date Modified column in a window set to List view show the date correctly, or does it also display it incorrectly?
    To add additional columns to a Finder (folder) window, with that window open and active open the View Options for it. You can do that by pressing Command-J or by selecting View Options from the View menu in the main menubar.

Maybe you are looking for

  • Can i run more than one app in my Asha 303 mobile?

    Hello,, my mobile: Nokia asha 303, updated... *in my last smart phone i was able to run many apps at the same time and navigate between them, but in my new asha phone idnt know how to open many apps in the same time and also idnt know if this feature

  • REP-1401, FATAL PL/SQL ERROR ....

    HI, I am trying to open a text file in oracle reports in one of the fomula column and it gives me the REP-1401 error. The syntax is as below. Is there any idea why its behaving so ? "UPC_Folder" and "UPCFile" are the two user parameters, that I am pa

  • Signal booster time capsule

    I have a time capsule and have very slow connectivity at some places in my home.  Is there a way to boost the signal?  I've read Airport Express, Airport Extreme, and some Linksys devices.  Any reason to choose one over the other?  Will boosting the

  • How do I get to control from my iPad the various elements needed for fonts, etc?

    I would like to be able to control fonts, colours, etc. from my iPad, when using my HP "all in one" wireless printer, when writing a document. Is this possible ? There doesn't even seem a way to do this from the little printer screen! RJGB

  • Tape trouble check vtr

    when i am logging and capturing, capturing stops and i get the message tape trouble check vtr. i read some post that it was an AJA problem and i called their tek support and they sent me the pulling txt file to put in my pluggins folder and the probl