Reference Guide

Security | 815
aaa authentication enable
z
Configure AAA Authentication method lists for user access to the EXEC Privilege mode (the “Enable”
access).
Syntax
aaa authentication enable {default | method-list-name} method [... method2]
To return to the default setting, use the no aaa authentication enable {default | method-list-name}
method [... method2] command.
Parameters
Defaults
Use the enable password.
Command Modes
CONFIGURATION
Command History
Usage Information
By default, the Enable password is used. If aaa authentication enable default is configured, FTOS will
use the methods defined for Enable access instead.
Methods configured with the aaa authentication enable command are evaluated in the order they are
configured. If authentication fails using the primary method, FTOS employs the second method (or
third method, if necessary) automatically. For example, if the TACACS+ server is reachable, but the
server key is invalid, FTOS proceeds to the next authentication method. The TACACS+ is incorrect,
but the user is still authenticated by the secondary method.
Related
Commands
S6000
default Enter the keyword default followed by the authentication methods to use as
the default sequence of methods to be used for the Enable log-in.
Default:
default enable
method-list-name
Enter a text string (up to 16 characters long) to name the list of enabled
authentication methods activated at log in.
method
Enter one of the following methods:
enable - use the password defined by the enable password command in the
CONFIGURATION mode.
line - use the password defined by the password command in the LINE
mode.
none - no authentication.
radius - use the RADIUS server(s) configured with the radius-server host
command.
tacacs+ - use the TACACS+ server(s) configured with the tacacs-server
host command.
... method2
(OPTIONAL) In the event of a “no response” from the first method, FTOS
applies the next configured method.
Version 9.0.2.0 Introduced on the S6000.
Version 8.3.11.1 Introduced on Z9000
enable password Change the password for the enable command.
login authentication Enable AAA login authentication on terminal lines.
password Create a password.
radius-server host Specify a RADIUS server host.
tacacs-server host Specify a TACACS+ server host.