1. Protect the administrative path
An APS team loses SSH to a device during a change. Data service still works, but that does not establish management-plane availability. Map administrative origin, bastion, routing, ACL, interface and destination service. An out-of-band path helps only if its dependencies survive the incident considered; validate power, network, identity and operator access. Restrict sources and protocols, use protected transport and confirm destination identity. A configured loopback can supply a stable address but needs usable routing. Do not copy an entire checklist without checking support, required services and the risk of blocking the only recovery path.
2. Separate the three AAA decisions
Authentication addresses identity; authorization determines services or commands; accounting records actions and sessions. In the fictional worksheet, login succeeds but a command authorized by the change request is denied. Investigate authorization policy and effective profile before changing the password. In another case, commands work but destination records are missing: access success does not establish accounting. Retain user, device, origin, time, session and the command needed for diagnosis without passwords. Explicitly test an allowed command, a denied command, record arrival and failure recovery. An account able to log in is not automatically authorized to do everything.
3. Distinguish rejection from unavailability
In the studied IOS XE list, TACACS+ precedes local authentication. Explicit rejection should not be treated as a transport error to try local credentials until access succeeds. The next method is attempted on error or no response according to the configured list and service. Test ACCEPT, REJECT and server unavailability separately, including authorization after login. Two AAA entries depending on the same route or identity service can fail together. Emergency accounts need scope, protection, ownership and review after use. The none authorization method can permit access when used; it is not equivalent to a least-privilege local account.
4. Validate transport and related controls
The hardening guide recommends TACACS+ over TLS 1.3 on supporting releases and identifies the old obfuscation mechanism as obsolete. The consulted example uses IOS XE 17.18.1 and ISE 3.4 Patch 2; confirm models, releases, certificates and both-end configuration. “Reachable port” does not establish successful TLS authentication. For SNMP, review authentication, content protection, views and write access rather than accepting only the v3 label. In CoPP, an ACL used for classification does not necessarily have the effect of an interface ACL: permit can select the class whose policy map drops traffic. Read classification and action together before changing them.
5. Demonstrate access after the change
Keep an authorized recovery path during the window and open a new session to test policy; an old session may continue without exercising new authentication. Define rollback criteria for errors, lost access and service impact. Collect classification counters, drops, CPU and required traffic when interpreting a CoPP change; increased drops alone establish neither attack nor control success. Synchronize time and confirm RUN can search destination accounting records. The worksheet contains eight planned tests not executed on Cisco. Summary: validate path, transport, authentication, authorization, recording and recovery as separate stages with evidence and ownership.
Login ACCEPT and command REJECT refer to different stages; changing the password does not demonstrate repaired authorization.
Common pitfalls
REJECT as timeout; old session as a new test; none as least privilege; permit in a classification ACL as final authorization.
Related topics: AAA and TACACS+ · Management plane and CoPP · Change and continuity
Administrative access is accepted only when identity, action, auditing and recovery work within intended scope.
Reference: Cisco IOS XE Software Hardening Guide · 350-701 SCOR v2.0, effective 2026-08-27; core component of CCNP Security