cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
313
Views
0
Helpful
1
Replies

Using AAA with FWSM

Bruce Summers
Level 1
Level 1

Hi folks,

Have a bit of a delima.  Running Cisco FWSM Version 3.2(2) on Catalyst 6513, in single context mode.

I cant quite figure out the configuration...

When sessioning from the swtich to this module, it appears to use a local account password,

The default escape character is Ctrl-^, then x.
You can also type 'exit' at the remote prompt to end the session
Trying 127.0.0.81 ... Open


User Access Verification

Password:

After entering the password, and entering enable command, it prompts for aaa credentials:

FWSM> en
Username:  xxx

password:   xxx

I'm then allowed access into the context (single). I'm not quite clear on what is causing 1) the first local password prompt and 2) the subsequent aaa prompt

Config as follows:

aaa-server <group> protocol tacas+

aaa-server <group> outside host 10.x.x.x key xxxx

aaa auth enable console <group>

aaa auth http console <group>

aaa auth ssh console <group>

thanks

Bruce

1 Reply 1

Jennifer Halim
Cisco Employee
Cisco Employee

The first password prompt would be the reverse telnet password prompt, which is the password configured using the following command on the FWSM:

passwd

http://www.cisco.com/en/US/docs/security/fwsm/fwsm32/command/reference/p.html#wp1668106

The second enable password is the "aaa authentication enable console " configuration line which would be authentication from tacacs server:

http://www.cisco.com/en/US/docs/security/fwsm/fwsm32/command/reference/a1.html#wp1587766

Hope that helps.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card