AAA beginners question

Unanswered Question
Feb 12th, 2008
User Badges:

I have set up an ASA 5520 that will allow us to authenticate via SSH using Cisco Secure ACS. My issue is that once you ssh into the inside interface of the device, it will ask you for a login. I type in my domain account login and I SSH just fine. My issue lies when I attempt to use enable mode. When trying, I noticed in the syslog that everytime I tried my enable password, the syslog would say my domain account has been denied. Is there a way to fix this? I guess if it is happening on the ASA/Pix, it will happen on routers and switches as well.

How can this be fixed?



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Collin Clark Tue, 02/12/2008 - 12:12
User Badges:
  • Purple, 4500 points or more


Just want to make sure I got this right. You use your Domain password for the initial login and you want to use it for enable mode? If yes, read on.

In ACS, under your user account, then under TACACS+ Enable Password, select Windows Database.

In the ASA you will have to add the following line (assuming you're using TACACS):

aaa authentication enable console TACACS+ LOCAL

Please test this on a non-production box first .



This Discussion