[c-nsp] Freeware tacacs and PIX enable authentication

Oliver Boehmer (oboehmer) oboehmer at cisco.com
Wed Jun 8 04:38:55 EDT 2005


Lora Ganeva <> wrote on Wednesday, June 08, 2005 10:08 AM:

> I have a serious problem with making my PIX firewall authenticate its
> enable password with a freeware tac-plus server.
> 
> I have made some tests and all I can see is that the enable
> authentication is rejected from the TACACS+.
> 
> The following is my tacacs configuration:
> 
> 
> 
> user = enable_15 {
> 
>         default service = permit
> 
>         login = cleartext cisco
> 
> }

not 100% sure, but have you  tried

user = $enab15$ {
        default service = permit
        login = cleartext cisco
}

At least this is what IOS sends as username for enable authentication..

	oli




More information about the cisco-nsp mailing list