IntermediatePublished 2026-07-04
AAA Authentication with a Local User Database
Bundle lab · $29.99
Harden R1’s management plane by moving SSH login authentication and exec authorization under the IOS AAA framework using the local user database. You will start from a secure SSH-only baseline that still uses login local, enable aaa new-model, define default AAA methods that point at local, and bind VTY lines to AAA. Success is proven by authenticating from the ADMIN host over SSH and landing at the user’s privilege level.
Learning objectives
- Enable AAA on IOS and migrate VTY login from login local to a default AAA method list that uses the local database
- Assign user privilege via the user account and enforce it with AAA exec authorization
- Harden remote access with SSH-only transport and safe local admin retention to prevent lockout
- Verify AAA operation from the router and via SSH from a Linux host
Troubleshooting focus
- AAA not enabled (no aaa new-model) so AAA method lists never take effect
- VTY lines still use login local instead of login authentication default
- Missing local username or wrong privilege assignment
- SSH service not ready (no RSA key pair, missing hostname or ip domain-name)
- Transport not restricted to SSH (Telnet allowed) or SSHv2 not enforced
Topology
Own this lab's topology — and every lab — in Device Hardening: SSH, AAA & Secure Access.
Unlock with Device Hardening: SSH, AAA & Secure AccessFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.
Grade your work
Create a free account to submit your completed lab for grading.
Create a free account