GANYMEDE + and local account

Hi all... Im trying to set up my cisco switch do not use the local account if the RADIUS server is in place. Here's what I have so far... Thank you

AAA new-model
AAA authentication login default group Ganymede + local
AAA authorization config-commands
AAA authorization exec default group Ganymede + authenticated if
AAA authorization commands 15 default group Ganymede + local
AAA accounting send stop-record an authentication failure
orders accounting AAA 1 by default start-stop Ganymede group.
orders accounting AAA 15 by default start-stop Ganymede group.

The current configuration that you will work in your favor.

AAA authentication login default group Ganymede + local

This command indicates the user can connect through //password local username if Ganymede server goes down.

Conclusion: local user will not be able to authenticate in the presence of RADIUS server.

HTH

Regds, jousset

Note the useful posts ~

Tags: Cisco Security

Similar Questions

  • GANYMEDE + and local access connection

    Basic summary is that I want to have GANYMEDE + and local connection to access router on the vty lines.  So, I did the two groups below.  Goody obviously is what will use GANYMEDE and Console uses the local connections.  I divide them between 0-4 and 5-15.  It seems that whoever is more get first priority for authentication.  If I move the Console to 0-4, knit then the local users and GANYMEDE do not.   If I have Goody at 0-4, then GANYMEDE works, but local doesn't work.  I know I'm missing something simple.  Have two RADIUS servers, I doubt that the two will never back down, but in case I want user names Local to work.   If I apply an access list to 4-0 and use SSH, as well as a list of different access to 5 15 and use telnet, it seems to work that way but doesn't help me if the internet goes down and I am trying to access the router via SSH on-site.

    Thanks in advance.

    David

    AAA authentication login Goody group Ganymede + local
    local authentication AAA Console connection

    Line con 0
    the Console connection authentication
    line to 0
    line vty 0 4
    session-timeout 7
    exec-timeout 5 0
    authentication of connection Goody
    entry ssh transport
    line vty 5 15
    session-timeout 7
    exec-timeout 5 0
    the Console connection authentication
    entry ssh transport

    Hi David -.

    Correct me if I'm not understanding this correctly, but you want to use RADIUS servers for authentication ssh/console type and if they fail, you want the network device to use its local database.

    If that is correct you should not need dividing lines and assign authentication lists. The first tribute that you have:

    AAA authentication login Goody group Ganymede + local

    Lists the Ganymede + and the local database as a possible authentication methods. They will be processed in the order they are configured so that the device will be:

    1. use your servers GANYMEDE +.

    2. If the GANYMEDE servers + inaccessible then the local database is used

    You can test this by assigning 'Goody' to all your vty lines and then do your servers GANYMEDE + unavailable. To do as possible you can:

    -Restart the server

    -Stop the server interface

    -Disconnect the device its uplink network

    -Create a list of access on the uplink interface and connection block to the IP addresses of the servers GANYMEDE +.

    I hope that helps!

    Thank you for evaluating useful messages!

  • Windows 8 Mail App and Local account

    I can buy a new laptop to Windows 8.  I have a Microsoft Account my email Hotmail.com.   However, I would like to connect to Windows 8 with a LOCAL ACCOUNT.

    So, I'll be able to use the Mail application?   If not, how can I download my Hotmail, AOL and Gmail accounts?

    In addition, you can give me a link to show me how to use the Windows 8 desktop, please?

    1. No, you can use the desktop version of Skype without interfering with the modern pre-installed version.  I make myself on my computer at home. It has a touch screen, but the screen if sits on a shelf so I rarely actually touch.  It means to me, the office is more useful.  In fact, you can even with the right button and uninstall the Skype modern if you won't use it.
    2. Yes absolutely, you can login with your account MS with Skype, even if you use a local account on the PC.
    3. I don't know what you're talking about with APS, I'm sorry.  Maybe I have not had enough coffee yet.  But almost all purposes, you can certainly use Google Chrome.  I do a lot of work site, so I practically all browsers on my PC to test the various functions.
  • If I update to windows 8.1 through my local account, all my files and all my information are saved?

    I have windows 8 on my desktop, I do not use a Microsoft account to connect to it, I use a local account. If I update to windows 8.1 all my files and all my information stored? and I will be able to connect to my local account without losing any of my information, such as files and app?

    Original title: I have a Local account on windows 8.

    Yes, absolutely.  This 8.1 update is really pretty as a Service Pack or set of updates.

    The only thing I can think of that can only be an impact for you, it's to the point 8.1 of Windows, you cannot use SkyDrive (now called OneDrive) unless you use a Microsoft Account on your profile.  In other words, you can not just use 'on the side '.  That could be a deal breaker if you rely on OneDrive to store all your files and settings.  But if you are not using OneDrive today, then it don't you impact at all.

  • How can I disconnect from my Microsoft account and connect to a local account?

    PC settings, Windows 8, I tried to switch to a local account.  However, when I do that, he asked me to do all the stuff of password, I click Next, and he said that 'sorry, we cannot connect to the Microsoft services at this time.  If the problem persists, look for "referee" in the start screen. "what should I do?  My Microsoft account is fine, I have a good Wi - Fi connection, internet is very well, then, what is the problem?  Please help, it's pretty boring!

    Hello

    We get this error message when there are server problems. I suggest you run the utility troubleshooting Microsoft account and check if it helps fix the problem.

    The resolution of the Microsoft account issues scans a system Windows 8 for issues and fixes the problems that are found with regard to your Microsoft Account.

    Here is the link for your reference.

    http://go.Microsoft.com/fwlink/?LinkId=268424

    For more information, see the links.

    http://Windows.Microsoft.com/en-CA/Windows-8/disable-remove-password

    http://Windows.Microsoft.com/en-CA/Windows/user-accounts-FAQ#1TC=Windows-8

    Thank you to post the results and we will be happy to help you.

  • By opting for the local account affects the current files and other documents are store in the pc.

    I have windows 8 is installed in my desktop pc

    I want to move my account to GO to THE LOCAL because of user setting I m tried to synchronize my app Mail for new emails and other stuff his watch still unavailable then, opting for the account local affect current files and other documents are stored in the pc at this moment before I spend.

    Hello

    Passage of the account Microsoft local account will not affect your personal documents saved on the computer.

    Reference: http://support.microsoft.com/kb/2782145

    It would be useful that you could provide more information on the problem faced with synchronization.

    -What is the exact error you get when synchronization Mail app and other apps?

    -Do you use all parameters of proxy to access the internet?

    -Remember to make changes before the show?

    -What anti-virus software is installed on the computer?

    If you encounter the problem of synchronization with all applications, then I ran the http://download.microsoft.com/download/F/2/4/F24D0C03-4181-4E5B-A23B-5C3A6B5974E3/apps.diagcab Apps store

    Navigate through the steps mentioned in http://windows.microsoft.com/en-us/windows-8/what-troubleshoot-problems-app

    Check if you have any proxy enabled. If so, then delete it.

    a. open Internet Explorer.

    b. click on tools and select Internet Options.

    c. click on connections.

    d. click on LAN settings.

    e. remove the check mark next to proxy server.

    f. click OK and check if you are able to synchronize emails.

    If none of the steps work, try to remove the account from the messaging application and add it again and check.

    Go through http://windows.microsoft.com/en-IN/windows-8/mail-app-faq

    Hope this information is useful. Let us know if you have any questions.

  • The Windows 8.1, Firefox runs on a local account but not on a domain account

    I just moved to Surface Pro 3 running Windows Pro 8.1. Firefox works correctly when you are connected to a local account. When you are connected to a domain account, Firefox will run *.html documents properly on a disc, but doesn't show any response to any internet orders. I have disabled the firewall for the domain - no change. I changed the domain account for administrator - no change. I have reset Firefox to default setting - no change. I created a new profile - no change. I disabled the hardware accelerator - no change. I've uninstalled and reinstalled Firefox several times - no change, what should I try then help identify the problem.

    I solved the problem. My browser Internet Explorer (IE) has been configured to use a proxy server. Firefox has been set to "Use system proxy settings", but do not have the name of the proxy server. Remove the IE proxy server solves the problem. Maybe Firefox should use "Autodetect proxy for this network settings' as default, Firefox installation setting is not dependent on the settings of IE year / this.

  • Thunderbird is removal of e-mails from both imap and pop3 accounts, without asking me to do this

    I went to get in my "sent" box to check on an e-mail, but found that they had almost all been deleted. I have imap and pop3 accounts, but this has happened in both. Also happening in the Inbox. I am aware that I asked never to delete e-mails.

    Thank you so much - I have now created a "local folder" (it did not exist previously) and I put in this folder all emails I need to keep. Thank you very much for your advice absolutely great. B June

  • How to convert the local account to a Microsoft account?

    Help please. I'm trying to convert a local account log in on a Windows PC to a microsoft account so I can activate parental controls for my son. God knows why you can't control a local account not more. However, I do not get an option to convert - any help appreciated please.

    You should be able to do it by opening the PC Settings page and select "Accounts" (the fastest way there is in the start menu, click on the picture of the user and select ' edit photo account ").

    Just under the user name, you should see a link: "To connect to a Microsoft account" click on a link and follow the instructions.

  • Connect to local accounts.

    Original title: confused

    I have accounts on my computer that has microsoft as admin and the other a local account and where they have the same email but differ from passwords it won't let connect me on the standard local account, it goes straight to the admin.? Help

    Hi Crystal,

    -What are the names of user defined for each account profile? Is this the same e-mail address?

    Just try to change the name of the Local account and set a new password and check if you are still having the same problem.
    -Press the Windows key and the R key to open the prompt execution.
    -Type compmgmt.msc and press ENTER.
    -Click users and groups, local users, and then select the local user account.
    -Right-click on the local user account and click Rename and rename the name.
    -Then set a new password for this account.
    -You can also change the display name of the account, by right-clicking on it, and then selecting Properties and rename optional full name.

    Please try these steps and let us know the result.

  • I can map a network drive by using the appropriate credentials, but access is denied (by default local account for navigation)

    I have a laptop running XP SP3.  If I connect locally to the laptop and you try to map a network from a server drive on my network, it invites me for a username and password that I offer and the player must then be mapped.  The problem is that when I click on the new player, I get an access denied message.  It tries to connect to the share with my local account that has no access privileges.  Previously it tempt me a username and password, but apparently, I changed some security settings and it doesn't do this more.

    The same thing happens if I use the command net use.  I can map the drive by providing an appropriate user name and password, but I can't browse it in windows Explorer.  I really want to understand the context that controls if you get a prompt when you access a resource on the network.  I think that it is related to the setting of security strategy for network access: sharing and security for local accounts.  I played a bit with it, but in vain.

    I realize that I could probably add an account with the same username / password for my local account on the server and give access to my file shared.  I don't want to do that.  I have several users who share the laptop and access the local account access (I realize this is not ideal, but it is inevitable at the present time).  I don't want to have access to this network share.

    Can someone help me get my login prompt?  I searched on google for the last 2 days trying all kinds of suggested solutions, but I couldn't find one that works.

    Too bad... I was hoping that was the problem.  But at least it now asks you a name of user and password :-)

    Apart from that, you could look to make sure that NetBios over TCP (NetBT) is enabled on the client.  Deactivation of this force a direct hosting of SMB which sometimes has problems.

    "Hosting of SMB over TCP/IP direct".
    <>http://support.Microsoft.com/kb/204279 >

    Your latest comments seem to point to a followed initial connection or bad connect more or maybe you is not authenticated as expected.  A few quick tests, I did showed that if you connect using TCP/IP address instead of the computer name and specify everything, including the scope of user name online net "use", it reduces the network traffic needed to establish a connection.  As a test on a client, from a command prompt, try a syntax such as:

    NET use * \\192.168.1.10\share /user:192.168.1.10\username password

    Where "192.168.1.10" is the IP address of the server, 'share' is the name of the action that you want to connect to and "username" is the local user on the server to which you authenticate you.  If you use domain identification information, substutite for "192.168.1.10" domain name in the "/ user:" part.  If you log to a local account server from a name of user and password graphic prompt, try to including the name of the computer and the user name in the user name as in Nom_ordinateur\Nom_utilisateur area.  If it does not, unless there is really something wrong with the access permissions, I'm out of ideas.

    Good luck
    JW

  • User (and files) account settings not saved at shutdown

    Hi, I recently got Windows Vista Ultimate 32-bit installed on my PC of house built... the problem I run into is that whenever I stop, when I turn it on again it is still as if it were my first time logging into the user account (I get the Welcome Center window, none of my settings to before I stop were saved)... even though I installed all programs still appear to be installed.

    Also, I'm a little confused about how the "personal file" my account user works (I mean the folder that opens when I click on "Brian" in the start menu, in the upper right).  First of all, my settings, all files in there seem to have erased when I stopped (excluding the makings of the sample).  Second, this personal file does not seem to be the same folder as I get to by going to computer > disc Local (c) > users > Brian 1; even if they are both set in place with the default subfolders (photos, music, video etc.).

    Thus, the settings and files in the personal folder for my user expect to get erased on shutdown... does anyone have a solution for this?

    I appreciate the help!

    Thank you
    Brian

    Your original user is damaged. Make a new user account and copy the data from the old account to the new. After you have all your stuff, you can delete the old damaged account.

    User - recommended configuration (Vista and Win7) accounts

    You absolutely don't want to have only one user account. As XP and all other Windows 7, Vista, and modern operating systems are operating systems multi-user with integrated system of accounts as default Administrator and comments. These accounts should be left alone because they are part of the structure of the operating system.

    In particular, you do not want account only one user with administrator privileges on Vista and Windows 7 because the administrator account integrated (normally only used in emergencies) is disabled by default. If you use as an administrator for your daily work, and this account is corrupt, things will be difficult. It is not impossible to activate the built-in administrator to rescue things, but it may require more work you want to do. Better not to get into a bad situation at first.

    The user account that is for your daily work must be a Standard user, with the extra administrative user (call it something like 'CompAdmin' or 'Tech' or similar) only it for elevation purposes. As a user Standard is recommended for security reasons and will help protect your computer against infections. After you have created "CompAdmin", connect to it and change your normal user account Standard. Then log on to your regular account.

    If you want to go directly to the desktop and ignore the Welcome screen with the icons of the user accounts, you can do this:

    Start Orb > Search box > type: netplwiz [Enter]
    Click continue (or provide an administrator password) when you are prompted by UAC

    Uncheck "users must enter a user name and password to use this computer". Select a user account to connect automatically by clicking on the account you want to highlight and press OK. Enter the password for this user account (when it exists) when you are prompted. Leave blank if there is no password (null). MS - MVP - Elephant Boy computers - don't panic!

  • How can I change a password for the local account of a pc that can not be connected remotely?

    Hi all

    I am currently based in London. I have a problem with the laptop of a staff based in Africa. We built the laptop and it shipped to them. As part of the construction, we put on our account standard administrator and then made a local account that they are not connected to our area.

    The user in this Africa Office has changed the local password of its account and now don't remember making it so the unable to connect to PC. I don't want to tell him our administrator password, because it is the same for all our PC in the world. I have studied a lot of things to try to connect to the computer, but it is now possible.

    I tried:

    1 navigation to the machine from another pc on the network using explroer and I see the C drive.

    2. I tried to run this command, but I get just error 1219: net use \\pcname\ipc$ / user: pcname\administrator *.

    3 RDP will not work, it will not just connect.

    4. the PC that I use is 8 Windows Home Edition and none of the business I've noticed is a problem of computer management doesn't have users and groups it seems. The remote pc is Windows 7 Enterprise.

    So for now I just a laptop that is stuck on the login screen.

    I guess I'm doomed then?

    No, you are not condemned. I gave you a recipe to solve your problem. Give the person a password for admin for a few minutes does not compromise the integrity of the machine, as long as you then reset the password in a few minutes.

    If this person can burn a CD repair system on another machine of Windows 7 then it can use to start the machine in Windows Repair Mode. From there it can use system restore to set up Windows to a point before he changed the password. You need to exercise on your own machine to guide him through the process.

  • Authentication Radius 4.2 ACS and RADIUS Accounting

    Is it possible to configure 4.2 ACS to authenticate users of a wireless network (with autonomous APs) through RADIUS while I use the same ACS to provide the command represent the points of access via GANYMEDE +? This issue came out because when I configure the APs 'AAA Clients' under 'Network Configuration' of the ACS server (necessary config for authentication APs and end users), the authentication method used is the RADIUS (Cisco Aironet) and it prevents the generation GANYMEDE server command accounting reports under "reports and activities > GANYMEDE + Administration.

    Any idea on how to solve this problem?

    Thank you

    Antonio

    Hello

    Need to add a different hostname for the AP... IE, RPOS and APt, where you can use the same IP n but use radius for Ganymede and the other.

    Thank you

    Tarik Admani
    * Please note the useful messages *.

  • Need to change password on the first login to the local account in Windows 8/8.1/10

    I need to create an about a dozen local accounts on a MS Surface Pro 3 running Windows 8.1 which is shared in a working environment.

    I would create each account with a fake password and force the user to change the password immediately to the first connection.

    How do I do that? Is the technique for Windows 10 the same?

    Hello

    Thanks for posting your query in Microsoft Community.

    Your question is beyond the scope of what is generally answered in this forum of consumer and would be better suited for the IT Pro TechNet public.

    Please post your question in the TechNet Forums.

Maybe you are looking for

  • MacPrO _ randomly typing in capital letters...

    Help! My keyboard randomly generates capital letters. The keys are all move freely, no friction. Ideas?

  • NB500 - 12 c - HDD is blocked by password

    Well, I have a toshiba nb500 - 12 c that I na not use for a long time because the screen was broken, recently my other laptop (toshiba nb250 - 10 h) has started to receive some big gal, the processor overheats and gets to 60-70 degrees in 15 minutes

  • HP Envy: start

    At startup, I have to choose the operating systems 7 or 8.1. I don't have windows 7 on the copmputer (has two systems installed at the same time). I was told to get rid of the unwanted system erase the sisk is on what I did. The system is gone, but I

  • LVOOP

    Hello, I started re writing a parallel of my current project. This time using lvoop (new to me) something that is not clear for the sake of the moment communication interface: I have several devices with rs232, gpib or nothing. I have to considerate

  • WRT1900AC: Cannot access the router remotely

    This can be a simple, but I'm scratching my head on it. I just took a 1900 for my personal use at home. I did a basic auto config (Nothing fancy, just Plain Jane). As part of the configuration process, I associated the router to a Smart Access accoun