• When you log in to the required Cisco NX-OS device, you can use the Telnet, SSH, or console login
options.
• When you have configured the AAA server groups using the server group authentication method, the
Cisco NX-OS device sends an authentication request to the first AAA server in the group as follows:
• If the AAA server fails to respond, the next AAA server is tried and so on until the remote server
responds to the authentication request.
• If all AAA servers in the server group fail to respond, the servers in the next server group are tried.
• If all configured methods fail, the local database is used for authentication, unless fallback to local
is disabled for the console login.
• If the Cisco NX-OS device successfully authenticates you through a remote AAA server, then the
following possibilities apply:
• If the AAA server protocol is RADIUS, then user roles specified in the cisco-av-pair attribute are
downloaded with an authentication response.
• If the AAA server protocol is , then another request is sent to the same server to get the
user roles specified as custom attributes for the shell.
• If your username and password are successfully authenticated locally, the Cisco NX-OS device logs you
in and assigns you the roles configured in the local database.
"No more server groups left" means that there is no response from any server in all server groups. "No more
servers left" means that there is no response from any server within this server group.
Note
AES Password Encryption and Master Encryption Keys
You can enable strong, reversible 128-bit Advanced Encryption Standard (AES) password encryption, also
known as type-6 encryption. To start using type-6 encryption, you must enable the AES password encryption
feature and configure a master encryption key, which is used to encrypt and decrypt passwords.
After you enable AES password encryption and configure a master key, all existing and newly created clear-text
passwords for supported applications (currently RADIUS and ) are stored in type-6 encrypted
format, unless you disable type-6 password encryption. You can also configure Cisco NX-OS to convert all
existing weakly encrypted passwords to type-6 encrypted passwords.
Licensing Requirements for AAA
The following table shows the licensing requirements for this feature:
License Requirement
Product
AAA requires no license. Any feature not included in a license package is bundled with the
nx-os image and is provided at no extra charge to you. For an explanation of the Cisco NX-OS
licensing scheme, see the
.
Cisco NX-OS
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
13
Configuring AAA
AES Password Encryption and Master Encryption Keys