Hi Richard,

The aaa-new model command, once enabled always asks you for a 
username/password combination for any login type. Looking at your config I 
expect you to get a username/password prompt and failed logins for both con 
and vty unless if authenticated by tacacs and am surprised you are able to 
login by console.

To get around it,
a. Creat a local username/password on the AS ie
      username anything password anyotherthing
b. Add the command
      aaa authentication login no_tacacs local
c. Add the command:
      login authentication no_tacacs
   to your con and vty lines to reference b. above

I once experienced a similar thing and resolved it as above, except you want 
to authenticate all logins by tacacs.

I am open to corrections.

Tunji




_________________________________________________________________
Get your FREE download of MSN Explorer at http://explorer.msn.com/intl.asp




Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=27663&t=27648
--------------------------------------------------
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]

Reply via email to