<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://it-arts.net/index.php?action=history&amp;feed=atom&amp;title=ARISTA_-_AAA_Commands</id>
	<title>ARISTA - AAA Commands - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://it-arts.net/index.php?action=history&amp;feed=atom&amp;title=ARISTA_-_AAA_Commands"/>
	<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=ARISTA_-_AAA_Commands&amp;action=history"/>
	<updated>2026-05-02T18:30:13Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.44.2</generator>
	<entry>
		<id>https://it-arts.net/index.php?title=ARISTA_-_AAA_Commands&amp;diff=920&amp;oldid=prev</id>
		<title>Admin: Text replacement - &quot;Category:Wiki&quot; to &quot;Category:Wiki

&#039;&#039;&#039;&#039;&#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&#039;&#039;&#039;&#039;&#039;
&quot;</title>
		<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=ARISTA_-_AAA_Commands&amp;diff=920&amp;oldid=prev"/>
		<updated>2026-01-17T07:10:01Z</updated>

		<summary type="html">&lt;p&gt;Text replacement - &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;&amp;quot; to &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;  &amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&amp;#039;&amp;#039;&amp;#039;&amp;#039;&amp;#039; &amp;quot;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 07:10, 17 January 2026&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Wiki]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Wiki]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&#039;&#039;&#039;&#039;&#039;[https://it-arts.net/index.php/Category:Wiki Return to Wiki Index]&#039;&#039;&#039;&#039;&#039;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== AAA Overview ==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;== AAA Overview ==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
	<entry>
		<id>https://it-arts.net/index.php?title=ARISTA_-_AAA_Commands&amp;diff=573&amp;oldid=prev</id>
		<title>Admin: Created page with &quot;Category:Wiki  == AAA Overview ==  AAA refers to three main components used for managing access control and monitoring on network devices: * **Authentication**: Verifies the identity of users or devices attempting to connect. * **Authorization**: Determines what authenticated users or devices are allowed to do. * **Accounting**: Tracks what actions users or devices perform during a session.  == Enabling AAA ==  To enable AAA on an Arista device, use the following com...&quot;</title>
		<link rel="alternate" type="text/html" href="https://it-arts.net/index.php?title=ARISTA_-_AAA_Commands&amp;diff=573&amp;oldid=prev"/>
		<updated>2025-12-14T16:31:42Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;&lt;a href=&quot;/index.php/Category:Wiki&quot; title=&quot;Category:Wiki&quot;&gt;Category:Wiki&lt;/a&gt;  == AAA Overview ==  AAA refers to three main components used for managing access control and monitoring on network devices: * **Authentication**: Verifies the identity of users or devices attempting to connect. * **Authorization**: Determines what authenticated users or devices are allowed to do. * **Accounting**: Tracks what actions users or devices perform during a session.  == Enabling AAA ==  To enable AAA on an Arista device, use the following com...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;[[Category:Wiki]]&lt;br /&gt;
&lt;br /&gt;
== AAA Overview ==&lt;br /&gt;
&lt;br /&gt;
AAA refers to three main components used for managing access control and monitoring on network devices:&lt;br /&gt;
* **Authentication**: Verifies the identity of users or devices attempting to connect.&lt;br /&gt;
* **Authorization**: Determines what authenticated users or devices are allowed to do.&lt;br /&gt;
* **Accounting**: Tracks what actions users or devices perform during a session.&lt;br /&gt;
&lt;br /&gt;
== Enabling AAA ==&lt;br /&gt;
&lt;br /&gt;
To enable AAA on an Arista device, use the following command:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
AAA configure&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This command activates AAA functionality on the device. After this, you can configure individual AAA services.&lt;br /&gt;
&lt;br /&gt;
== Authentication Configuration ==&lt;br /&gt;
&lt;br /&gt;
Authentication is used to verify the identity of a user or device. Arista devices support multiple authentication methods including local, RADIUS, and TACACS+.&lt;br /&gt;
&lt;br /&gt;
=== Local Authentication ===&lt;br /&gt;
&lt;br /&gt;
To configure local authentication for console access:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
username admin privilege 15 secret MySecretPassword&lt;br /&gt;
line con 0&lt;br /&gt;
 login local&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Here, the `admin` user is created with privilege level 15 and a secret password. The `line con 0` command applies local authentication for console access.&lt;br /&gt;
&lt;br /&gt;
=== RADIUS Authentication ===&lt;br /&gt;
&lt;br /&gt;
To configure RADIUS authentication:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
radius-server host 192.168.1.100 key MyRadiusSecret&lt;br /&gt;
aaa authentication login default group radius local&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In this example, RADIUS authentication is set up to authenticate users with the RADIUS server at IP address `192.168.1.100`, and if RADIUS is unavailable, it falls back to local authentication.&lt;br /&gt;
&lt;br /&gt;
=== TACACS+ Authentication ===&lt;br /&gt;
&lt;br /&gt;
For TACACS+ authentication, the following configuration is used:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
tacacs-server host 192.168.1.200 key MyTACACSSecret&lt;br /&gt;
aaa authentication login default group tacacs+ local&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This sets up TACACS+ authentication, where the server is at IP address `192.168.1.200`.&lt;br /&gt;
&lt;br /&gt;
== Authorization Configuration ==&lt;br /&gt;
&lt;br /&gt;
Authorization defines what authenticated users are permitted to do. You can configure authorization for command execution or for network services.&lt;br /&gt;
&lt;br /&gt;
=== Command Authorization ===&lt;br /&gt;
&lt;br /&gt;
To configure command authorization, use the following:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
aaa authorization exec default group radius local&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This command sets up authorization for exec commands, using RADIUS as the primary source and falling back to local authorization if RADIUS is unavailable.&lt;br /&gt;
&lt;br /&gt;
=== Network Authorization ===&lt;br /&gt;
&lt;br /&gt;
To configure network access authorization:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
aaa authorization network default group radius local&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This command ensures that the device uses RADIUS for network access authorization, and falls back to local authorization if the RADIUS server is unreachable.&lt;br /&gt;
&lt;br /&gt;
== Accounting Configuration ==&lt;br /&gt;
&lt;br /&gt;
Accounting is used to log information about user sessions, which can include login times, commands executed, and bytes transferred.&lt;br /&gt;
&lt;br /&gt;
=== Enabling Accounting ===&lt;br /&gt;
&lt;br /&gt;
To enable accounting for user logins and exec sessions:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
aaa accounting exec default start-stop group radius&lt;br /&gt;
aaa accounting commands 15 default start-stop group radius&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These commands configure accounting for exec sessions and commands executed with privilege level 15. Accounting data will be sent to the configured RADIUS server.&lt;br /&gt;
&lt;br /&gt;
=== Accounting for Network Sessions ===&lt;br /&gt;
&lt;br /&gt;
To enable accounting for network sessions, use:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
aaa accounting network default start-stop group radius&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This command sends accounting information related to network access sessions to the RADIUS server.&lt;br /&gt;
&lt;br /&gt;
== Advanced AAA Commands ==&lt;br /&gt;
&lt;br /&gt;
In addition to the basic AAA configurations, Arista provides commands for more advanced management of AAA services.&lt;br /&gt;
&lt;br /&gt;
=== Defining AAA Server Groups ===&lt;br /&gt;
&lt;br /&gt;
You can define multiple AAA servers and assign them to specific groups. For example:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
radius-server host 192.168.1.100 key MyRadiusSecret group radius_group&lt;br /&gt;
tacacs-server host 192.168.1.200 key MyTACACSSecret group tacacs_group&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This configuration defines two AAA servers: one for RADIUS and one for TACACS+, each in its own group.&lt;br /&gt;
&lt;br /&gt;
=== AAA Command Timeout Configuration ===&lt;br /&gt;
&lt;br /&gt;
To configure the timeout for AAA authentication, authorization, and accounting requests, use the following command:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
aaa authentication login default timeout 30&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This command sets a 30-second timeout for login authentication requests. Similar commands can be used for authorization and accounting timeouts.&lt;br /&gt;
&lt;br /&gt;
=== AAA Server Deadtime Configuration ===&lt;br /&gt;
&lt;br /&gt;
In case of a failed AAA server response, you can configure the deadtime for that server:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
aaa server radius deadtime 60&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This sets the deadtime to 60 seconds, during which the server will not be queried if it fails.&lt;br /&gt;
&lt;br /&gt;
== AAA Debugging ==&lt;br /&gt;
&lt;br /&gt;
To troubleshoot AAA configurations, use the following debugging commands:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;&lt;br /&gt;
debug aaa authentication&lt;br /&gt;
debug aaa authorization&lt;br /&gt;
debug aaa accounting&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
These commands enable debugging for each AAA service, allowing you to track and troubleshoot issues related to authentication, authorization, and accounting.&lt;br /&gt;
&lt;br /&gt;
== Useful Links ==&lt;br /&gt;
&lt;br /&gt;
* [Arista Networks Official Documentation](https://www.arista.com/en/support)&lt;br /&gt;
* [AAA Overview on Cisco Docs](https://www.cisco.com/c/en/us/td/docs/iosxr/ncs5500/security/71x/b-71x-security-cg/b-71x-security-cg_chapter_010.html)&lt;br /&gt;
* [AAA Configuration Guide - Cisco](https://www.cisco.com/c/en/us/td/docs/iosxr/ncs5500/security/71x/b-71x-security-cg/b-71x-security-cg_chapter_010.html)&lt;br /&gt;
* [RADIUS and TACACS+ Protocols Overview](https://www.techopedia.com/definition/22747/radius-remote-authentication-dial-in-user-service)&lt;/div&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
</feed>