SUMMARY STEPS
1.
configure terminal
2.
aaa new-model
3.
aaa authentication login
{
default
|
list-name
}
method1
[
method2...
]
4.
line
[
console
|
tty
|
vty
]
line-number
[
ending-line-number
]
5.
login authentication
{
default
|
list-name
}
6.
end
DETAILED STEPS
Purpose
Command or Action
Enters the global configuration mode.
configure terminal
Example:
Switch#
configure terminal
Step 1
Enables AAA.
aaa new-model
Example:
Switch(config)#
aaa new-model
Step 2
Creates a login authentication method list.
aaa authentication login
{
default
|
list-name
}
method1
[
method2...
]
Step 3
•
To create a default list that is used when a named list is
not
specified in the
login authentication
command, use the
default
keyword followed by the
Example:
Switch(config)#
aaa
methods that are to be used in default situations. The default method list is
automatically applied to all ports.
authentication login default
•
For
list-name
, specify a character string to name the list you are creating.
local
•
For
method1...
, specify the actual method the authentication algorithm tries.
The additional methods of authentication are used only if the previous method
returns an error, not if it fails.
Select one of these methods:
◦
enable
—
Use the enable password for authentication. Before you can
use this authentication method, you must define an enable password
by using the
enable password
global configuration command.
◦
group radius
—
Use RADIUS authentication. Before you can use this
authentication method, you must configure the RADIUS server.
◦
line
—
Use the line password for authentication. Before you can use
this authentication method, you must define a line password. Use the
password password
line configuration command.
Catalyst 2960-XR Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX1
OL-29434-01
67
Configuring RADIUS
Configuring RADIUS Login Authentication