1.4.3.1 Ensure 'aaa authentication enable console' is configured correctly

Information

Authenticates users trying to access the Enable mode (privileged EXEC mode) through the 'enable' command.

Rationale:

The default access to enable mode is done through a password. AAA provides a primary method for authenticating users (a username/password database stored on a TACACS+ or RADIUS server or group of servers) and then specifies backup method (a locally stored username/password database). The backup method is used if the primary method's database cannot be accessed by the networking device.

Solution

Configure the aaa authentication for enable access using the TACACS+ server-group as primary method and the local database as backup method

HOSTNAME(CONFIG)# AAA AUTHENTICATION ENABLE CONSOLE <_server-group_name_> LOCAL

See Also

https://workbench.cisecurity.org/files/1903

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2(9), CSCv7|4.3

Plugin: Cisco

Control ID: 017ca146f249270c0c6bdce6b975e8f7648d437214e17e8e4333a87ecfd0e807