30 CHAPTER 2: AAA COMMANDS
On the console, login succeeds without any authentication check if the
authentication method is not defined.
Command Mode
Global Configuration mode
User Guidelines
The default and optional list names created with the aaa authentication
login command are used with the login authentication command.
Create a list by entering the aaa authentication login list-name method
command for a particular protocol, where list-name is any character
string used to name this list. The method argument identifies the list of
methods that the authentication algorithm tries, in the given sequence.
The additional methods of authentication are used only if the previous
method returns an error, not if it fails. To ensure that the authentication
succeeds even if all methods return an error, specify none as the final
method in the command line.
Example
The following example configures the authentication login.
aaa authentication
enable
The aaa authentication enable Global Configuration mode command
defines authentication method lists for accessing higher privilege levels.
To restore defaults, use the no form of this command.
Syntax
aaa authentication enable {default | list-name} method1 [method2...]
no aaa authentication enable {default | list-name}
Parameters
■ default — Uses the listed authentication methods that follow this
argument as the default list of methods, when using higher privilege
levels.
Console(config)#
aaa authentication
login default radius tacacs enable line local none