Purpose
Command or Action
•
To create a default list that is used when a named list is
not
specified in
the
login authentication
command, use the
default
keyword followed
Example:
Switch(config)#
aaa authentication
by the methods that are to be used in default situations. The default
method list is automatically applied to all ports.
login default local
•
For
list-name
, specify a character string to name the list you are creating.
•
For
method1...
, specify the actual method the authentication algorithm
tries. The additional methods of authentication are used only if the
previous method returns an error, not if it fails.
Select one of these methods:
◦
enable
—
Use the enable password for authentication. Before you
can use this authentication method, you must define an enable
password by using the
enable password
global configuration
command.
◦
group radius
—
Use RADIUS authentication. Before you can use
this authentication method, you must configure the RADIUS server.
◦
line
—
Use the line password for authentication. Before you can
use this authentication method, you must define a line password.
Use the
password password
line configuration command.
◦
local
—
Use the local username database for authentication. You
must enter username information in the database. Use the
username name password
global configuration command.
◦
local-case
—
Use a case-sensitive local username database for
authentication. You must enter username information in the
database by using the
username password
global configuration
command.
◦
none
—
Do not use any authentication for login.
Enters line configuration mode, and configure the lines to which you want to
apply the authentication list.
line
[
console
|
tty
|
vty
]
line-number
[
ending-line-number
]
Example:
Switch(config)#
line 1 4
Step 5
Applies the authentication list to a line or set of lines.
login authentication
{
default
|
list-name
}
Step 6
•
If you specify
default
, use the default list created with the
aaa
authentication login
command.
Example:
Switch(config)#
login
authentication default
•
For
list-name
, specify the list created with the
aaa authentication login
command.
Catalyst 2960-X Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX
OL-29048-01
87
Configuring RADIUS
Configuring RADIUS Login Authentication