Using AAA with FWSM

Unanswered Question
Jun 19th, 2010

Hi folks,

Have a bit of a delima.  Running Cisco FWSM Version 3.2(2) on Catalyst 6513, in single context mode.

I cant quite figure out the configuration...

When sessioning from the swtich to this module, it appears to use a local account password,

The default escape character is Ctrl-^, then x.
You can also type 'exit' at the remote prompt to end the session
Trying 127.0.0.81 ... Open


User Access Verification

Password:

After entering the password, and entering enable command, it prompts for aaa credentials:

FWSM> en
Username:  xxx

password:   xxx

I'm then allowed access into the context (single). I'm not quite clear on what is causing 1) the first local password prompt and 2) the subsequent aaa prompt

Config as follows:

aaa-server <group> protocol tacas+

aaa-server <group> outside host 10.x.x.x key xxxx

aaa auth enable console <group>

aaa auth http console <group>

aaa auth ssh console <group>

thanks

Bruce

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Jennifer Halim Sat, 06/19/2010 - 08:49

The first password prompt would be the reverse telnet password prompt, which is the password configured using the following command on the FWSM:

passwd

http://www.cisco.com/en/US/docs/security/fwsm/fwsm32/command/reference/p.html#wp1668106

The second enable password is the "aaa authentication enable console " configuration line which would be authentication from tacacs server:

http://www.cisco.com/en/US/docs/security/fwsm/fwsm32/command/reference/a1.html#wp1587766

Hope that helps.

Actions

This Discussion