User's Manual

Table Of Contents
112
Users Manual of CS-6306R
6.1.2.1 Overview of the AAA Configuration Process
Configuring AAA is relatively simple after you understand the basic process involved. To configure security on
a Cisco router or access server using AAA, follow this process:
If you decide to use a separate security server, configure security protocol parameters, such as RADIUS,
TACACS+, or Kerberos.
Define the method lists for authentication by using an AAA authentication command.
Apply the method lists to a particular interface or line, if required.
(Optional) Configure authorization using the AAA authorization command.
(Optional) Configure accounting using the AAA accounting command.
6.1.3 AAA Authentication Configuration Task List
Configuring Login Authentication Using AAA
Configuring PPP Authentication Using AAA
Enabling Password Protection at the Privileged Level
Configuring Message Banners for AAA Authentication
AAA authentication username-prompt
AAA authentication password-prompt
Establishing Username Authentication
Enabling Password
6.1.4 AAA Authentication Configuration Task
To configure AAA authentication, perform the following configuration processes:
1. If you decide to use a separate security server, configure security protocol parameters, such as RADIUS,
TACACS+, or Kerberos.
2. Define the method lists for authentication by using an AAA authentication command.
3. Apply the method lists to a particular interface or line, if required.
6.1.4.1 Configuring Login Authentication Using AAA
The AAA security services facilitate a variety of login authentication methods. Use the aaa authentication login
command to enable AAA authentication no matter which of the supported login authentication methods you
decide to use. With the aaa authentication login command, you create one or more lists of authentication
methods that are tried at login. These lists are applied using the login authentication line configuration
command.
To configure login authentication by using AAA, use the following commands beginning in global configuration
mode: