enable secret cisco
line con 0 password cisco login
line vty 0 15 password cisco login ! по умолчанию
server# telnet router
aaa new-model aaa authentication login CONSOLE none aaa authorization exec CONSOLE none enable secret cisco aaa authorization console line con 0 login authentication CONSOLE authorization exec CONSOLE privilege level 15
aaa authentication login default local username user1 password cpassword1
Уровни привилегий:
aaa authorization exec default local username user1 privilege 7 privilege exec level 7 show running-config view full
server# ssh user1@switch1 ... switch# show privilege switch# show running-config view full ...
radius-server host server auth-port 1812 acct-port 1813 radius-server key testing123
aaa authentication login default group radius enable
aaa authorization exec default group radius none
http://open1x.sourceforge.net/
aaa authentication dot1x default group radius aaa accounting dot1x default start-stop group radius
tacacs-server host server tacacs-server key tackey123
aaa authentication login default group tacacs+ enable aaa authorization exec default group tacacs+ none aaa accounting commands 15 default start-stop group tacacs+