Firewall Wizards mailing list archives

Login straight to priv mode in PIX with TACACS server


From: Michel Ferreira <michelf () gmail com>
Date: Sat, 6 Feb 2010 13:32:44 -0200

Hi,

I've successfully configured my PIX 506E (6.3) to authenticate with my
TACACS+ Server (ACS 4.1), however I want to know if there's any way to
put the user straight in priv mode (enable) just after login, without
the need to input the 'enable' command.

I'm questioning this because I don't want to include the "aaa
authentication enable console tacacs+ LOCAL" command, since with this
command if I need console access I still will be authenticating
against the TACACS+ server, which, in a emergency situation (like one
that i need to physically connect a console cable to the firewall)
I'll be using the remote authentication, and I don't want that.

Thanks for your considerations,

Michel
_______________________________________________
firewall-wizards mailing list
firewall-wizards () listserv icsalabs com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: