Switch of AAA and password Enable question

I have a switch with a config to base thereon and created some 15 local user privilege.  I was copying the config of another switch and unfortunately did NOT know the secret to activate it but still added to the (stupid I know) configuration.  Opening a session on the switch after being in production was working fine, until I tried to configure AAA.  As the enable password I've referenced another similar switch for configuration of the AAA and I did this several times in the past and it works normally.

However, this time AAA would work not for a reason any but everything was fine because the local user account.  Then I made a few other changes trying to solve the AAA and now when I login, it invited me to this password to enable a reason any?  The local user works get me in but for the non-privilege mode.   Can anyone shed some light on why this is happening?

It would be difficult to provide information on why your config didn't work as expected without seeing the actual config :)

So, it looks like you will need to perform a password recovery. You can follow the instructions in this link:

http://www.Cisco.com/c/en/us/support/docs/switches/catalyst-2950-series-switches/12040-pswdrec-2900xl.html

I hope this helps!

Thank you for evaluating useful messages!

Tags: Cisco Security

Similar Questions

  • Why my firewall only use the domain user name and password for login and enable passwords, not a different password enable as do it my switches? RADIUS config looks the same...

    / * Style definitions * / table. MsoNormalTable {mso-style-name: "Table Normal" "; mso-knew-rowband-size: 0; mso-knew-colband-size: 0; mso-style - noshow:yes; mso-style-priority: 99; mso-style-parent:" ";" mso-padding-alt: 0 to 5.4pt 0 to 5.4pt; mso-para-margin: 0; mso-para-margin-bottom: .0001pt; mso-pagination: widow-orphan; do-size: 10.0pt; do-family: "Times New Roman", "serif" ;} "}

    Question:

    Firewalls Cisco requires that one level of password, i.e. the domain user name and password are used for logging as that to reach the global configuration mode.

    Background:

    We have several network devices Cisco, put in place who authenticate to our Windows using NPS (Windows 2008 R2) DC. Switches we have implemented the function exactly as we would wish that they need your domain user name and password to connect to the device. Then they require a separate password when you use the enable command, it is stored in Active Directory:

    Switches:

    User name:domain-username

    Password:password-field

    SWITCH >Activate

    Password:Enable-password - to-Active Directory

    SWITCH #.

    Firewalls (as they are now):

    User name:domain-username

    Password:password-field

    Firewall >enable

    Password:password-field

    FIREWALL #.

    With the firewall, however, they require your domain user name and password first and then your domain password again when you use the enable command. I want to reuse the firewall to use the level that currently switches enable password rather than the password of domain. The appearance of the current configuration as follows:

    Current configuration of the switch:

    AAA new-model

    AAA authentication login default local radius group

    AAA authentication enable default group enable RADIUS

    AAA authorization exec default local radius group

    AAA - the id of the joint session

    ACCT-port of 1645 auth-port host 192.168.0.1 Server RADIUS 1646

    Server RADIUS ports source-1645-1646

    RADIUS server key 7 1234abcd

    Current configuration of the firewall:

    RADIUS protocol AAA-server DC01

    AAA-server DC01 (outside) host 192.168.0.1

    authentication AAA ssh console LOCAL DC01

    Console to enable AAA authentication LOCAL DC01

    1234abcd keys

    Any help would be great, thanks!

    You must use GANYMEDE + instead of RADIUS for this.

    Here, you can use command sets in the results section of the policy.

  • 38.0.1 updated to does not allow me to log into G-mail. I know that my user name and password, cookies are enabled and clear history information. I am able to Safari.

    38.0.1 updated to does not allow me to log into G-mail. I know that my user name and password, cookies are enabled and clear history information. I am able to Safari.

    Thank you. I could sign G-mail in Mode safe, so I "refreshed" Firefox and that took care of him. Appreciate your quick response and helpful instructions.

  • Hi all, I have icloud email and password of the last iphone user, but iphone is blocked and he don't remember security questions. Send the same as apple ID. I have all chansements to unlock in the appstore?

    Hi all, I have icloud email and password of the last iphone user, but iphone is blocked and he don't remember security questions. Send the same as apple ID. I have all chansements to unlock in the appstore?

    You can not unlock with the AppStore. Request a refund or ask the previous owner to retrieve his password:

    Check these items and follow the instructions.

    If you have forgotten your Apple - Apple Support ID

    If you forgot your Apple ID - Apple Support password

    https://iforgot.Apple.com/appleid

  • my hotmail account has been blocked and I don't remember my secret question and password

    WHT I'm doing as I dnt remember my secret question and password I did tht account years ago and hotmail has blocked he sent unwanted emails on its own... I dnt know how

    pls help

    Hello

    Answers is a peer group supported and unfortunately has no real influence on Hotmail.

    HotMail has its own Forums, so you can ask your questions there.

    Windows Live Solution Center - HotMail - HotMail Forums Solutions
    http://windowslivehelp.com/

    Hotmail - Forums
    http://windowslivehelp.com/forums.aspx?ProductID=1

    Hotmail - Solutions
    http://windowslivehelp.com/solutions.aspx?ProductID=1

    How to contact Windows Live Hotmail Support
    http://email.about.com/od/hotmailtips/Qt/et_hotmail_supp.htm

    Windows Live Hotmail Top issues and Support information
    http://support.Microsoft.com/kb/316659/en-us

    Compromised account - access unauthorized account - how to recover your account
    http://windowslivehelp.com/solution.aspx?SolutionID=6ea0c7b3-1473-4176-b03f-145b951dcb41

    Hotmail hacked? Take these steps
    http://blogs.msdn.com/b/securitytipstalk/archive/2010/07/07/Hotmail-hacked-take-these-steps.aspx

    I hope this helps.

  • BlackBerry Smartphones after switch of the device to the same model, BB missing Apps (like cards and password keeper)

    I had problems for a long time with my keyboard on my BB Bold 9900, so finally I was given a used to toggle Bold 9900. I have used the functionality of the switch device of BlackBerry Desktop (v7.1) software and was off and running on my 'new' "BOLD". Finally, I noticed that the cards and password keeper are missing on my new phone. I did a lot of digging through our corporate HelpDesk, phone call from mobile provider support, and if Google search (incl. various BlackBerry support forums). Nowhere is that I found a solution that worked.

    A number of sources did the download card www.blackberry.com/ but that results in a message of "Opinion sorry, your device does not meet the system requirements that are needed to support BlackBerry Maps."

    When I look in the Applications tab of BB Desktop Software, BlackBerry Maps is not listed (is not password keeper).

    Two of my phones are running OS 7.1 Bundle 2840. Carrier SaskTel (part of the network of Bell Mobility).

    Any ideas?

    From what you describe, something is not right when you installed/updated / switched devices. Thus, a clean reload of the OS would be the right thing to do. The easiest way is, on a PC (you can not do on MAC):

    (1) make sure that you have a current backup and your BB complete... you can find the instructions at the link in my auto-sig below.

    2) uninstall all the BB OS packages from your PC,

    (3) make sure you have the BB Desktop Software already installed

    (4) download and install on your computer, the BB OS package you want:

    • http://us.BlackBerry.com/support/downloads/download_sites.jsp
    • If all you want are the levels of BONE, it is first sorted by carrier - the carrier supports, your search will be fast. However, some carriers are much slower than others to release updates. To really get the package up-to-date OS for your BB, you need to dig through and find all businesses that support your specific model BB and then compare the BONE levels they support.

    5) remove all copies of the SELLER on your PC. XML... There will be at least one and maybe 2, and they will be located in the same way or to (it changes based on your version of Windows) these files:

    • C:\Program Files (x 86) \Common Files\Research In Motion\AppLoader
    • C:\Users\(your Windows username) \AppData\Roaming\Research In Motion\BlackBerry\Loader XML

    6 (a) to change your level of BB OS installed (at level or lower), you can run the Desktop software and connect your BB... the software should offer the operating system package you have installed on your PC.

    6 (b) or, for recharging your BB OS level installed as well to change, work around the Desktop software and use the CHARGER. EXE directly, through step 2 in this process:

    If, during the process of 6a or 6 b, your BB has an error '507', simply unplug the USB of the BB cord and reinsert it. do nothing else... This should allow the installation to continue.

    If you are on a MAC, you are limited to only your sanctioned carriers OS packages... but can still use any level they currently have to sanction. See this procedure:

    • KB19915 How to perform a clean reload of the smartphone BlackBerry using BlackBerry Desktop Software application software

    Good luck and let us know!

  • With Firefox 24, authentication ID and password are automatically filled in. With Firefox 26.0, this happens is more although the memory of password is enabled. What should do?

    The ID or the password appears on a site, but the two do not seem to with Firefox 24. I have an iMac with OS X version 10.9 (Mavericks, who is also newly installed).

    Note that you are currently using a beta version of Firefox 26.0 and not the current version of Firefox 25.0.

    You can find the full version of the latest version of Firefox 25.0 in all languages and for all systems operating here:

    You always see the names and passwords in the password manager?

    • Tools > Options > Security: passwords: "saved passwords" > "show passwords".

    Make sure that you run not Firefox in private browsing mode (permanent) (don't forget the story never).

    • Firefox > Preferences > privacy > Firefox will be: "use the custom settings for history".
    • Uncheck the box: [] "always use the navigation mode private.
  • How to enable save username and password to login

    Hello

    I have problem!

    Please help me!

    and:

    I used the program Advanced.System.Optimizer.3.5.1000.15559!

    and go to the program of Fixer of problems > system and security adviser

    and start Security Scan into the system and security adviser!

    and don't know select Disable Save username and password!

    No setting of restoration in the program!

    Hi Javad,

    Since the parameters you are talking about is in the "Advanced.System.Optimizer" program, I suggest contact you the program support team for help with this problem.

    Please refer to this link:

    http://www.systweak.com/ASO/features/secure-encryptor/

    Also refer to:

    http://Windows.Microsoft.com/en-us/Windows7/are-registry-cleaners-necessary

    It will be useful.

    Please let us know in case you need assistance on issues related to Windows.

  • Adding a printer - question is I keep are asked and ID and password

    I have Windows 7 and I'm trying to add a printer.  The printer looks like it is added, but I can't access it because he keeps asking and ID and password and then a different password.  How can I disable this request because I don't have a password on my laptop.  Thank you!

    What make and model printer?

    It's connected usb or wi - fi?

    When exact is any required password and what is the exact message?

  • question about rest api. user name and password is not valid for rest api.

    I installed the vCloud director v1.5.1 trival version, and I can browse the version by https://127.0.0.1/api/versions information.

    When I use the https://127.0.0.1/api/login, IE needs me at the entrance of username and password. I did, but it was not valid.

    Can I use the user name and password to log into vCloud Director web page, it is the system administrator.

    Using the wrong username and password? What should I do?

    concerning

    Hello

    The user name must be in the form of "username@organization" instead of the name of the user.

    If you are using a system administrator, then the name of the Organization should be 'system '.

    Kind regards

    Todor Todorov

  • local user name and password if the ACS server fails

    Hello

    I have every router and switch configuration for authentication of the connection via the ACS server.  I used these 12 lines below and it works very well.  Each engineer has their own account.

    AAA new-model
    AAA of default login authentication group Ganymede + activate
    the AAA authentication enable default group Ganymede + activate
    AAA authorization exec default authenticated if
    AAA authorization commands 15 default group Ganymede + authenticated if
    AAA accounting exec default start-stop Ganymede group.
    orders accounting AAA 15 by default start-stop Ganymede group.
    Default connection accounting AAA power Ganymede group.
    AAA - the id of the joint session

    RADIUS-server host x.x.x.x
    RADIUS-server application made
    radius-server key, regardless of

    ----------------------------------------------

    I would add to this a local username and password so that if the ACS server was offline engineers have yet to connect with a knowledge of username and default password

    username privilege 15 secret mypassword MYUSERNAME

    line vty 0 4
    local connection

    Q. How do I make ACS a first preference and connection server only local users username and password if the ACS server is down?

    Kind regards

    Kevin

    Now you have the password to enable as the fall back method:

    AAA of default login authentication group Ganymede + activate

    Change 'enable' for 'local' and the local (to the router) database of user names and passwords is used.

    The same works to activate authentication (the second line "authentication, aaa... ("in the config that you posted).

  • I have the two Master Sync activated WITHOUT be asked for master password said at the start of the session and password?

    The basic question is that whenever I start Firefox, I am invited, a few seconds later, my master password, regardless of if I will actually connect a site for which I saved my credentials.
    This same number as well as a replica of his original poster chosen as the best answer has been published on the following link: https://support.mozilla.org/en-US/questions/1039575

    I'm in the same situation as this poster, but I don't want to turn off sync. I need the master password set to protect my passwords stored, and I need the Sync feature enabled to share my profile between different computers that I use.
    If I close the master password prompt at the start of the session and then I go to a page that I recorded the password, I should I get prompted again, and that's all I need. Also, I've installed Sync do NOT share my passwords stored, where the master password invite so that the effect is useless in my case.

    So the question is simply how can I turn off the prompt for password at startup, have it pop up when you access a site that needs a password stored (or ask if I want to save a) and keep the clock running without sharing passwords.

    Thanks in advance.

    No, this is not possible.
    Sync must retrieve the journal of authentication data in password manager and which requires to enter the password to unlock the password.

    The synchronization used in Firefox 34 version then use password manager to store the name (e-mail) and password to use to connect to the synchronization server.
    The chrome://FirefoxAccounts entry in the Password Manager stores (kA and kB) credentials in JSON format.
    Earlier versions of Firefox used to store these data in the signedInUser.json file in the profile folder, but the current version only stores the sessionToken in this file and must the Manager password for the credentials of the synchronization.

  • gmail login page always opens with my username and password already filled

    I go to the login page for gmail - little matter how I'm here via a bookmark or not - the page is always displayed with my username and password already filled. Questions (a) is not sure, anyone could sign as me simply by pressing 'back' (b) other users in the House need to back my details away in order to enter their own.

    I tried to reinstall Firefox - no use. How to make a gmail login page to open with empty boxes for username and password?

    Thanks in advance for any advice!

    It seems that your username and passoword are saved in your browser. You cannot remove from tools > Options > Security > saved passwords Panel. Also you can enable/disable this password box do not forget in the same pane.

  • Today, I put my user name and password in Windows Mail, and it will not accept it.

    Today, I tried to get on my Windows Mail and the logon to windows mail window popped up. I put in my username and password and it accepts it. Anyone know what is happening? Or how

    Original title: windows mail

    Hi Samantha,

    For you help I would be grateful if you could answer the following questions:

    (1) what accounts you set up on the Mail App?

    (2) you get an error message / code?

    Check out the links and follow the troubleshooting steps;

    Method 1:

    Solve problems with Windows Mail

    http://Windows.Microsoft.com/en-in/Windows-Vista/troubleshoot-problems-with-Windows-Mail

    Working with Windows Mail in Windows Vista

    http://Windows.Microsoft.com/en-in/Windows-Vista/working-with-Windows-Mail

    Method 2: Temporary deactivation of the antivirus/firewall software

    Enable or disable Windows Firewall

    http://Windows.Microsoft.com/en-in/Windows-Vista/turn-Windows-Firewall-on-or-off

    Important note: Antivirus software can help protect your computer against viruses and other security threats. In most cases, you should not disable your antivirus software. If you need to disable temporarily to install other software, you must reactivate as soon as you are finished. If you are connected to the Internet or a network, while your antivirus software is disabled, your computer is vulnerable to attacks.

    You should contact the provider of messaging and see there are problems.  See also if you can connect via webmail and if it works.

    If you need help with Windows, please do not hesitate to post. We will be happy to help you.

  • Unable to connect to a dial-up connection does not require a user id and password.

    It's kind of a weird question.  I have a new vista machine, and a user must always connect to a Government to start the connection via modem.  In XP, we used hyperterminal and everything worked well.  As hyperterminal is not available under Vista, we spent some time trying to get the vista switched from work.  He composed, negotiates, but when it comes to 'verification of the user name and password' connection failed after that right.  He has not set password to connect, the password entered only after you connect and you select the option to connect.

    Now, I copied Hyperterminal from a XP machine and was able to connect.  But using hyperterminal, none of the shortcuts that I do can be used.  They all come with "could not read session file: c:\. "c:\session.ht".ht."  I changed the location of the shortcut, the location of the hypertrm.exe, departure to the target location, etc...  The only way to get a recorded session to run is to open hyperterminal, and then click file, open and point to the location of the session.ht file.  It works, I suppose, but its not just a lot more, especially since this is not until the last the default location that you opened a file from.

    Ideally, I would like to use the connection to start menu.  Is it possible to force the connection does not send a user name and password?  He always says "verifying username and password" even though I left the empty boxes.  Or is this another problem with Vista and dial upward?  Any help would be greatly appreciated.

    Thank you.

    I thought about it... a bit, I've found a workaround.

    You can call hyperterminal for the prompt, using:
    Hypertrm c:\myfile.ht

    You open hyperterminal as we are used to having open when you click the .ht file in XP.

    Knowing this, you can create a shortcut to hyperterminal which calls the hypertrm.exe AND the .ht file

    Mine is:
    C:\Windows\System32\hypertrm.exe c:\Windows\System32\ohip.ht

    Bloody Government and their former systems eh?

    I hope this helps!

    Dave

Maybe you are looking for