1.4.3.1 Ensure 'aaa authentication enable console' is configured correctly

Information

Authenticates users trying to access the Enable mode (privileged EXEC mode) through the 'enable' command.

Rationale:

The default access to enable mode is done through a password. AAA provides a primary method for authenticating users (a username/password database stored on a TACACS+ or RADIUS server or group of servers) and then specifies backup method (a locally stored username/password database). The backup method is used if the primary method's database cannot be accessed by the networking device.

Solution

Configure the aaa authentication for enable access using the TACACS+ server-group as primary method and the local database as backup method

hostname(config)# aaa authentication enable console <server-group_name> local

Default Value:

The aaa authentication is disabled by default for the enable mode

See Also

https://workbench.cisecurity.org/files/3246

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2(9), CSCv7|4.3

Plugin: Cisco

Control ID: e68e7cac6851bb0f60df82a5b9a20d22f4b6d1de52667a6b9e7987c31589ae72