No need for enable secret??

mikearamamikearama Member Posts: 749
And that, despite having entered (and re-entered) it.

Anyone had that happen? Got a 3825 router that, once tacacs approved, goes directly to exec... no need to enter the enable password. From the console it is still mandatory, just not via telnet.

Not a biggie... just like to get it fixed. Preciate any thoughts.

Mike
There are only 10 kinds of people... those who understand binary, and those that don't.

CCIE Studies: Written passed: Jan 21/12 Lab Prep: Hours reading: 385. Hours labbing: 110

Taking a time-out to add the CCVP. Capitalizing on a current IPT pilot project.

Comments

  • dtlokeedtlokee Member Posts: 2,378 ■■■■□□□□□□
    The TACACS server is returning a privilege level (or there is one set on the VTY lines). The console may use a different TACACS group or none at all.
    The only easy day was yesterday!
  • HumperHumper Member Posts: 647
    Take a look at your config :D
    Now working full time!
  • mikearamamikearama Member Posts: 749
    dtlokee wrote:
    (or there is one set on the VTY lines).

    That was it.

    The router came with the priv level set to 15 on the vty lines... I haven't seen that before. Once removed, secret required.

    Thanks.
    There are only 10 kinds of people... those who understand binary, and those that don't.

    CCIE Studies: Written passed: Jan 21/12 Lab Prep: Hours reading: 385. Hours labbing: 110

    Taking a time-out to add the CCVP. Capitalizing on a current IPT pilot project.
  • hectorjhrdzhectorjhrdz Member Posts: 127
    cisco says:

    Add Authorization

    Adding authorization is optional.

    By default, there are three command-levels on the router:

    privilege level 0 which includes disable, enable, exit, help, and logout

    privilege level 1 - normal level on a Telnet - prompt says router>

    #privilege level 15 - enable level - prompt says router#



    check out your aaa config
  • dtlokeedtlokee Member Posts: 2,378 ■■■■□□□□□□
    mikearama wrote:
    dtlokee wrote:
    (or there is one set on the VTY lines).

    That was it.

    The router came with the priv level set to 15 on the vty lines... I haven't seen that before. Once removed, secret required.

    Thanks.

    Somewhere along the way the documentation for SDM said oyu needed to add the "privilege level 15" command to the vty lines for SDM to work, I have seen this on a few brand new routers and I can only assume it was done so SDM would run (even though it's not needed).
    The only easy day was yesterday!
Sign In or Register to comment.