64 | Management
www.dell.com | support.dell.com
Figure 4-5.  Applying an Access List to a VTY Line
Configure Login Authentication for Terminal Lines
You can use any combination of up to six authentication methods to authenticate a user on a terminal line. 
A combination of authentication methods is called a “method list”. If the user fails the first authentication 
method, FTOS prompts the next method until all methods are exhausted, at which point the connection is 
terminated. The available authentication methods are: 
•
enable—Prompt for the enable password.
•
line—Prompt for the password you assigned to the terminal line. You must configure a password for 
the terminal line to which you assign a method list that contains the 
line authentication method. 
Configure a password using the 
password command from LINE mode.
•
local—Prompt for the system username and password.
•
none—Do not authenticate the user.
•
radius—Prompt for a username and password and use a RADIUS server to authenticate.
•
tacacs+—Prompt for a username and password and use a TACACS+ server to authenticate.
To configure authentication for a terminal line, follow these steps:
FTOS Behavior: Prior to FTOS version 7.4.2.0, in order to deny access on a VTY line, you must apply 
an ACL and AAA authentication to the line. Then users are denied access only after they enter a 
username and password. Beginning in FTOS version 7.4.2.0, only an ACL is required, and users are 
denied access before they are prompted for a username and password.
Step Task Command Syntax Command Mode
1 Create an authentication method list. 
You may use a mnemonic name or 
use the keyword default. The default 
authentication method for terminal 
lines is local, and the default method 
list is empty.
aaa authentication login {method-list-name | 
default} [method-1] [method-2] [method-3] 
[method-4] [method-5] [method-6]
CONFIGURATION
2 Apply the method list from Step 1 to 
a terminal line.
login authentication {method-list-name | default}
CONFIGURATION
FTOS(conf-std-nacl)#show config
!
ip access-list standard myvtyacl
 seq 5 permit host 10.11.0.1
FTOS(conf-std-nacl)#line vty 0
FTOS(conf-line-vty)#show config
line vty 0
 access-class myvtyacl