09.12.2012 Views

Understanding the network.pdf - Back to Home

Understanding the network.pdf - Back to Home

Understanding the network.pdf - Back to Home

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

local-AS#config t<br />

Enter configuration commands, one per line. End with CNTL/Z.<br />

local-AS(config)#aaa new-mode<br />

local-AS(config)#^Z<br />

local-AS#<br />

Unlike old-mode, when new-mode au<strong>the</strong>ntication is enabled, it is up<br />

<strong>to</strong> <strong>the</strong> administra<strong>to</strong>r <strong>to</strong> define <strong>the</strong> au<strong>the</strong>ntication options <strong>the</strong> router<br />

will use.<br />

New-mode au<strong>the</strong>ntication supports both a local static user table and<br />

<strong>the</strong> security au<strong>the</strong>ntication pro<strong>to</strong>cols mentioned earlier. If you use a<br />

remote security pro<strong>to</strong>col, it is a good idea <strong>to</strong> create a local backup<br />

account in case your au<strong>the</strong>ntication server fails and you need <strong>to</strong><br />

access <strong>the</strong> router.<br />

It's possible <strong>to</strong> have privileged EXEC and configuration EXEC modes<br />

au<strong>the</strong>nticated remotely as well. This latter option does not work well<br />

with RADIUS, so unless you do not have Cisco's TACACS, it should be<br />

avoided. It is just as easy <strong>to</strong> build an enable password file and update<br />

your router monthly using TFTP.<br />

One o<strong>the</strong>r thing about new-mode is that, unlike old-mode, it can apply<br />

au<strong>the</strong>ntication <strong>to</strong> all line interfaces (including <strong>the</strong> console) when using<br />

<strong>the</strong> "default" list.<br />

Setting Up Login Au<strong>the</strong>ntication<br />

Always create <strong>the</strong> local administrative account first. Then, enable<br />

. After AAA has been enabled, <strong>the</strong> au<strong>the</strong>ntication<br />

service type and list are defined:<br />

Router#config t<br />

Enter configuration commands, one per line. End with CNTL/Z<br />

Router(config)#username root! password anypass<br />

Router(config)#aaa new-mode<br />

Router(config)#aaa au<strong>the</strong>ntication login default radius local

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!