Section 3, Common Provisioning - Provision Authentication, Authorization, and Accounting (AAA)
65K510DEP08-1A 3-21
Configure Authentication Method
TheTotalAccess5000usesthefollowingpriorityofauthenticationmethods:
1. Ifenabled,theTotalAccess5000attemptstoauthenticatetheuserviaEmergencyEntry
Port(EEP).IfEEPisnotenabledortheusernamesuppliedisnotasupportedEEPuser‐
name,theTotalAccess5000proceedstothenext
step.
TheEEPisalocalauthenticationmethodthatcanbeemployedinscenarioswhereall
otherauthenticationmethodsareunsuccessful.WhenEEPisenabled,theusercanenter
apredeterminedusernameCHALLENGEtogainaccesstothesystem.Theuseristhen
presentedachallengekey.Thecorrectresponseto
thischallengekeycanbeacquired
fromADTRANTechnicalSupport.Ifthecorrectresponseisissued,thentheuseris
loggedinwithlocalAdminprivileges.
WhenEEPisenabledandtheCHALLENGEusernameisenteredattheloginprompt,the
networkelementpresentsthechallengekeyimmediately,anddoesnot
requesta
password.Thisistrueregardlessofhowtheauthenticationloginmethodlistis
configured.
UsecautionwhendisablingEEP.PriortodisablingEEP,considerationsmust
be given to options for recovery during conditions when all other
authenticationmethodsdenyaccess.
2. Ifenabled,theTotalAccess5000attemptstoauthenticatetheuserusingtheconfigured
TA CACS+server(s).IfTACACS+isnotenabledortheTotalAccess5000 isunableto
connecttoaTACACS+server,theTotalAccess5 000proceedstothenextstep.
3. Ifenabled,theTotalAccess
5000attemptstoauthenticatetheuserusingtheconfigured
RADIUSserver(s).IfRADIUSisnotenabledortheTotalAccess5000isunabletoconnect
toaRADIUSserver,theTotalAccess5000proceedstothenextstep.
4. Ifenabled,theTotalAccess5000authenticatestheuserusingthelocallyprogrammed
useraccounts.Iflocalauthenticationisnotenabled,theTotalAccess5000rejectsthe
loginattempt.
IftheTotalAccess5000connectsto aTACACS+serveror,then,aRADIUS
server,andtheserverrejectstheloginattempt,theTotalAccess5000doesnot
proceedtothe nextauthenticationmethod.Itrejectstheloginat tempt.A
fallbacktothenextmethodoccursonlyifa timeoutoccurson
allserversofa
givenprotocol(TACACS+orRADIUS).
Toconfiguretheauthenticationmethod(s)tobeused,completethefollowingprocedure:
1. FromtheEnableprompt,type
configure terminal,andpressENTERtoaccesstheGlo‐
balConfigurationprompt.
2. FromtheGlobalConfigurationprompt,type
aaa authentication login default
group tacacs+ [group radius|local]
,andpressENTER.