Why my firewall only use the domain user name and password for login and enable passwords, not a different password enable as do it my switches? RADIUS config looks the same...

/ * Style definitions * / table. MsoNormalTable {mso-style-name: "Table Normal" "; mso-knew-rowband-size: 0; mso-knew-colband-size: 0; mso-style - noshow:yes; mso-style-priority: 99; mso-style-parent:" ";" mso-padding-alt: 0 to 5.4pt 0 to 5.4pt; mso-para-margin: 0; mso-para-margin-bottom: .0001pt; mso-pagination: widow-orphan; do-size: 10.0pt; do-family: "Times New Roman", "serif" ;} "}

Question:

Firewalls Cisco requires that one level of password, i.e. the domain user name and password are used for logging as that to reach the global configuration mode.

Background:

We have several network devices Cisco, put in place who authenticate to our Windows using NPS (Windows 2008 R2) DC. Switches we have implemented the function exactly as we would wish that they need your domain user name and password to connect to the device. Then they require a separate password when you use the enable command, it is stored in Active Directory:

Switches:

User name:domain-username

Password:password-field

SWITCH >Activate

Password:Enable-password - to-Active Directory

SWITCH #.

Firewalls (as they are now):

User name:domain-username

Password:password-field

Firewall >enable

Password:password-field

FIREWALL #.

With the firewall, however, they require your domain user name and password first and then your domain password again when you use the enable command. I want to reuse the firewall to use the level that currently switches enable password rather than the password of domain. The appearance of the current configuration as follows:

Current configuration of the switch:

AAA new-model

AAA authentication login default local radius group

AAA authentication enable default group enable RADIUS

AAA authorization exec default local radius group

AAA - the id of the joint session

ACCT-port of 1645 auth-port host 192.168.0.1 Server RADIUS 1646

Server RADIUS ports source-1645-1646

RADIUS server key 7 1234abcd

Current configuration of the firewall:

RADIUS protocol AAA-server DC01

AAA-server DC01 (outside) host 192.168.0.1

authentication AAA ssh console LOCAL DC01

Console to enable AAA authentication LOCAL DC01

1234abcd keys

Any help would be great, thanks!

You must use GANYMEDE + instead of RADIUS for this.

Here, you can use command sets in the results section of the policy.

Tags: Cisco Security

Similar Questions

  • Why my email sign in with a user name and password is all of a sudden?

    Original title:

    E-mail

    Why my email sign in with a user name and password is all of a sudden?  When I don't put my username and password in the spaces, he says it is a mistake and I do it again and again, and it never works.  I can't send or receive e-mail on my Microsoft e-mail account.  I haven't changed anything lately, so I don't know why this is happening.  I can get my email on my COX webmail is a Microsoft problem, is not a COX problem.  Help!?

    As the account of emissions contain private information that can be shared in a public forum, please use the online form below. They are the only ones who have access to your account information, we simply don't have.


    Account of all the partners must now wonder online by using the Microsoft online form


    Select the error you must help with and fill in the information requested on the next page.  You must be connected to a Microsoft account to access the form.
    If you are unable to access your main account, you can use another account (if you have one) or create a new one https://signup.live.com/
  • My XP computer has a domain user name and password and I forgot. How can I permanently delete.

    I would like to know how to change or remove

    Hello

    As you try to edit or delete the domain user name and password, it would be better suited in the Windows Technet Forum. Please post your question in the following TechNet forum:

    http://social.technet.Microsoft.com/forums/en-us/categories

    Hope this information is useful.

  • If a Firefox window is open a 1password address open, only when I quit Firefox and use a 1Password user name and password is firefox open the necessary

    I'm keeping Firefox updated.
    However, it would be nice to use an address to 1password logon when a Firefox window is open and just opened another tab.
    See you soon
    Stan

    Hi mountfordp,
    I understand that you ask is why when you address window the 1Password Firefox does not open in another tab?

    I found that he was kidnapped and recommended update after version 40 Firefox: https://support.1password.com/v3-extension-firefox/

    However for the tab does not open I don't know if it's Firefox or the 1Password.

    In the past, a new profile has been recommended to be created with the latest version of 1Password in Firefox. Use the Profile Manager to create and delete profiles Firefox , first try a new profile and see if the new tab opens correctly.

  • 'The specified network folder is currently mapped using a different user name and password'.

    "The specified network folder is currently mapped using a.
    another user name and password.
    Connect using a different user name and password
    First, disconnect any existing mappings to this network
    share '.
    I got this message when trying to access a laptop on my home network. It's a laptop which came for years. The only change that occurred was the removal of a few videos to Windows Media Player. In fact, I was sitting near the laptop (laptop 1) that stores the video & audio files that I share on my network for years and an additional (cell 2) laptop computer on my network. I was simply remove a playlist via WMP and I witnessed portable 2 lose access to files I had shared for years with my home network. I don't even use WMP, I had just open trying to access the laptop 1 video/audio files to my PS3 system. I was clear an old list of video of WMP so I could add the extra avi files to the list that I had collected over the years. I wanted to not double many videos so I removed the videos in WMP list. Since then, I'm not able to share anything of my laptop 1 to the rest of my network. I did not like WMP before, now I really despise WMP. When I try to share a folder, right click, share with & click on homegroup (read/write), the option is not selected. Any solution would be greatly appreciated. Thank you

    Hello

    The link below talking about a similar problem that should help you to solve the problem.

    http://answers.Microsoft.com/en-us/Windows/Forum/windows_vista-networking/the-network-folder-specified-is-currently-mapped/928f6313-fe2c-4d2D-A247-152ec022e062

  • why there are four drives in the Fable: The Lost Chapters pack but we can only use the first to play?

    original title: fable: the lost chapters
    Hello! I wonder why there are four drives in the Fable: The Lost Chapters pack but we can only use the first to play?

    My guess would be that the other 3 drives are required for installation, because they contain the installation files, but actually the game startup files are only on the 1st disk.

  • I teach online and all my classes have the same user name and password. Now that I clicked "remember me next time", I can connect only in one class. How to unlock my password. Carol in English

    I teach online and all my classes have the same user name and password. Now that I clicked "remember me next time", I can connect only in ONE class. How to unlock my login and my password, so that I can use it for all classes. Carol in English

    "Remember Me" for the site connections automatically when you return to the Web site is done with a Cookie the site in Firefox.

    Try to clear your Cookies for this Web site.

    Tools > Options-> life privacy - Cookies = the button show Cookies.

    You must use the custom settings for history at the top of this tab to see the View the Cookies button.

    Enter the domain name in the top search bar and all Cookies for this URL will be displayed. Unless you can figure out which is Cookie to "remember me", you will need to delete them all.

    Hold the {Ctrl} key while you click each Cookie in the small window. When this list is all highlighted, click the Cookie delete button at the bottom left.
    When you are finished click Close.

  • Windows Virtual PC integrated with components lock me out of my WinXP - error of OEM comments - "the system could not log. Make sure that your user name and domain are correct... »

    With my new desktop Windows 7 hardware configuration, I decided (before you consider VMware Player) to retry Windows Virtual PC; but instead of using Windows XP Mode (which is useless because the disk is inaccessible), I decided to use my own Windows XP Pro OEM. [I use it for games that won't play on Win7.  Security issues are also irrelevant, because for these games, I'm not likely to use the Web.  Of course, I always Windows Security Essentials in my OEM customers.]

    The problem here is, whenever I have to Activate my integration, features VPC opens as if the Windows XP Mode have been installed (it is not); and when the screen is turned on, it asks my user name and password.  I tried to use the name and the password that I entered when installing my XP OEM; but I get this message:

    "The system could not log.  Make sure that your user name and domain are correct.  Type your password again.  Letters in passwords must be entered using the proper case. »

    How is it that I can't access my Windows XP OEM guest when the integration features are enabled?  Only when they are disabled can I activate my OS; invited but it's counterproductive, because I won't be able to move items from my host in my comments.  Once more, if I should decide to use VPC as my host VM for Linux Ubuntu/Kubuntu, what chance is there that the activation of the integration features will lock out me my Linux guest?

    Another thing: in the Start Menu under Windows Virtual PC folder I have shortcuts for ' Windows Virtual PC ' or 'Virtual Machines' (according to the Win7 version I use, 32-bit or 64-bit); but I also have "Windows XP Mode", I have not installed.  How is that possible?  I checked the shortcut, and point it to rundll32.exe.  Should I just get rid of the shortcut, or I will incur damage to my VPC if I do?

    Hello Cooky,

    Please provide a detailed description of the issue.

    I understand the inconvenience you encountered. However, I appreciate your efforts.

    To get more information about it, we have a dedicated forum where these issues are dealt with and would be better suited to the TechNet community.

    Please visit the link below to find a community that will provide the best support.

    https://social.technet.Microsoft.com/forums/Windows/en-us/home?category=w7itpro

    I hope this information is useful.

    Please let us know if you need more help, we will be happy to help you.

    Thank you.

  • Multimedia file sharing only works if the two devices are connected using the same protocol

    So I'm frustrated!

    I spent an hour trying to get my Windows 7 computer to share my music with my XBox 360. I have two machines on my network, one connected by Ethernet to the router and the other connected by WiFi. I tried everything I could find online to get the WiFi connected machine appears in the "Music Player" on my XBox system - follow all sharing, make sure that my router has UPnP, restarted a bouquet of services, etc..
    Nothing! During this time, my machine connected to Ethernet was watching me in the face. He has appeared on the XBox without problem. I started to compare the settings on both machines and found no difference.
    Then I remembered, boredom, I had setting up WiFi sync for Windows Phone my wife. In fact, it was this session of troubleshooting that lead me to put this machine on the WiFi in the first place! Seems to set up WiFi sync, Windows Phone and the target of the machine must be, not only connected to the same network (obviously), but for some reason any the $ @$ crazy, both connected by WiFi. I just connected this computer by WiFi - not happy, a faster speed with my wired connection - and immediately fixed the problem itself.
    Then, remembering that, I moved my XBox WiFi network and - presto - my second machine appears without a problem.
    My question is... WTF! ???
    This is ridiculous - this is the same network! Why things must be connected using the same protocol?

    Hi, Edward Petersen,.

    Please contact the Microsoft community. I'll help you solve the problem with sharing music using media sharing.

    Some routers isolate the cable connections and wireless, you can check if you have the option in the configuration of the router to share media

    If the problem occurs, you can contact the router manufacturer for assistance.

    Hope this information helps. If you need help with Windows, simply reply that we will be happy

    to help you.

  • Why I can't use the nested aggregate function?

    Hello Experts,

    Why I can't use the nested aggregate function? There is not an ora-00979 group by error of expression.

    Oracle Database 11 g Release 11.2.0.4.0 - 64 bit Production

    Select

       SUM (BOX WHEN (KSD_CREATEDATE BETWEEN TRUNC((KSD_CREATEDATE)) AND TRUNC(MIN(KSD_CREATEDATE)) +60) THEN 1  ELSE 0 END) AS col

    DE TABLE_3_4

    GROUP BY STC_FIRMANO

    Thank you

    GROUP BY will manage the SUM function, but the MIN is used incorrectly - use another SELECTION to get it, or work with only with a single line. Otherwise, you could do WITH... get the SUM of SELECT MIN...

  • Don't want new tiff files saved in my catalog if I'm only using the image of a composite.

    During the edition of Photoshop CS4 of LR3, the new fit will not appear in the catalog unless I have save in PS. In the LR4, it saves a new tiff in my catalog without worrying if I save the image edited in PS or not. I have a library of clouds, I use often and don't want new files saved in my LR catalog if I'm only using the image open for compositing. Can someone help me understand how to change the workflow to resemble LR3?

    The behavior of LR, create and save a TIFF file is automatically used when LR and ACR do not run a version of equal. In order for Lightroom to be able to place an image without creating a TIFF file saved the LR and ACR version must match. This will be possible until CS6 and cab 7 fate PS. Then when LR RTAs versions and match, Lightroom image from Camera Raw to make in Photoshop using a thing called 'bridge Scriot"LR tracks to open the file in Photoshop. If you don't save it, LR knows and no file is added to the catlog. If you save or you save as in Photoshop, Lightroom knows and adds this file that you saved, regardless of where it was saved.

    So, again, there are two fundamental behaviours of Lightroom. If LR and ACR match, LR titles the image where (if) you save. If LR and ACR are out of phase of pf, Lightroom renders a file TIFF is saved before sending it to Photoshop. And no, ACR 6.7 does not count as in sync with LR4... 6.7 the cab is a stop gap measure to allow users of LR4 open images with parameters of PV 2012... It will not be until you get 7 ACR in CS6 you will get optimal integration between LR, ACR and Photoshop.

    BTW, this behavior is consistent across all versions of LR/ACR for LR2.

  • Have not used my email in a long time and I forgot the user name and password

    Hello. I don't use my thunderbird email in a long time and can't remember my user name or password if I remember my email address. How can I connect?

    Your user name is all or part of your e-mail address.
    The user name and the password is given with your email provider. You need to communicate with them.
    Most providers have a password reset link on their page for help by e-mail.

  • I can't scroll my podcasts more since the update to iTunes 12.4. I can only use the arrow keys to go through my podcasts, and then take it all down.

    I have a MacBook Pro and update to the latest iOS and iTunes. I can't scroll in my podcasts to choose which episodes to synchronize. I can only use the arrow keys to navigate, but then while he list of podcasts on the left, it moves also down from the bar on the list of episodes, so by the time I spend the first 7 or 8 I can't see the episodes more to choose which to add/remove.

    Same here, very frustrating.

    I found if you go in your library > Podcast, then control click on the podcast, you can select Add to the device, which works, but is in no way acceptable.

  • Why the temperature shows on my watch always different temperature on the watch of my husband when they use the same application?

    Why the temperature still showing on my watch shows a different temperature than on my husband watch when they both use the same weather app?

    Hi Jodie

    If you are each using the weather app (which is included in the framework of the iOS and watchOS), the following steps can help (followed by each of you):

    • On your iPhone, in the weather app:
      • If using anything other than the current location (which is included by default), make sure you have each added to a common location / city.
      • To add another location, select the icon «+»
    • On your iPhone, in the application of the watch, go to: My Watch (tab) > weather > default City > make sure you have each selected at the same location (for example: place of current residence or Mount Laurel).
    • On your iPhone, go to: settings > privacy > location Services:
      • Ensure that the location service is enabled;
      • Make sure Apple Watch is face value while it helps;
      • Check that the weather is set to always;
    • On your iPhone, go to: settings > general > background App update:
      • Check that the bottom App Refresh is enabled.
      • It can also help to activate the setting for the weather.
    • For optimal performance of your watch, keep the Bluetooth and Wi - Fi enabled at all times on your iPhone:
      • iPhone: settings > Bluetooth - on.
      • iPhone: settings > Wi - Fi - on.
  • I forgot my icloud user name and the password, my ID apple won't do me in my phone how to lay or clear everyhing so that I can use my phone again?

    I forgot my icloud user name and the password, my ID apple won't do me in my phone how to lay or clear everyhing so that I can use my phone again?

    https://iforgot.Apple.com/password/verify/appleid#! & section = password

Maybe you are looking for

  • Satellite M70-147 - rpm and the graphics card.

    What is the number of turns of the M70 - 147? HTTP://BE.COMPUTERS.TOSHIBA-EUROPE.COM/CGI-BIN/TOSHIBACSG/SELECTED_PRODUCT_OPTION.JSP?LNG=10&SERVICE=BE&PROD UCT_ID = 109802 & DISC_MODEL = 0 It is also not clear what graphics card is inside. In the head

  • How can I remove a duplicate 'Add or remove programs"icon in the control panel?

    Whenever I open the Control Panel on my computer, I see two icons "Add or Remove Programs". How can I fix this problem?

  • How to recover a deleted folder photos.

    Original title: delete errorfolder deleted photos by mistake when you work in the lexmark productivity studio, not in the trash folder, is the salvageable. If so, how?

  • System Restore missing on the list of system tools

    Original title: System Restore lost I have the detector of max secure spyware on my system, he pointed out that my system restore is false and deleted the shortcut of this program. I restored the research program and found. Research says the program

  • Charger UK for us hp pro book 4545 s

    I have a hp pro book 4545 American s. I move to the United Kingdom. I was wondering if I could buy a charger uk for my computer and use it instead to use a converter. Will be that FRY even though my computer?