10 messages in net.nether.puck.cisco-nsp[c-nsp] aaa different for console log...
FromSent OnAttachments
Jon LewisJan 11, 2005 2:17 pm 
Jon LewisJan 11, 2005 3:08 pm 
Oliver Boehmer (oboehmer)Jan 11, 2005 3:34 pm 
John LyonsJan 11, 2005 3:50 pm 
Jon LewisJan 11, 2005 8:50 pm 
Oliver Boehmer (oboehmer)Jan 12, 2005 4:11 am 
Jon LewisJan 12, 2005 7:04 am 
Oliver Boehmer (oboehmer)Jan 12, 2005 7:36 am 
Jon LewisJan 12, 2005 8:18 am 
Oliver Boehmer (oboehmer)Jan 12, 2005 8:30 am 
Actions with this message:
Paste this link in email or IM:
Paste this link in email or IM:
Atom feed for this thread
Paste this URL into your reader:
Subject:[c-nsp] aaa different for console logins?Actions...
From:Oliver Boehmer (oboehmer) (oboe@cisco.com)
Date:Jan 11, 2005 3:34:08 pm
List:net.nether.puck.cisco-nsp

Anyone know why when using aaa for administrative login authentication, returning Service-Type = Administrative-User will give enable access to a telnet user, but only exec access to a console login?

aaa new-model aaa authentication login default group radius local aaa authorization exec default group radius local aaa accounting exec default start-stop group radius

by default, console sessions are not authorized via AAA (a safeguard against a misconfigured authorization). configure "aaa authorization console" (could be hidden, depending on IOS release) if you want to change this behaviour.

oli