← CCNP Security: SCOR core and operations
22 / 25 · 55 MIN

Network management: AAA and recovery

Diagnose administrative access by stage and prepare a change preserving control, auditing and recovery.

1. Protect the administrative path

An APS team loses SSH to a device during a change. Data service still works, but that does not establish management-plane availability. Map administrative origin, bastion, routing, ACL, interface and destination service. An out-of-band path helps only if its dependencies survive the incident considered; validate power, network, identity and operator access. Restrict sources and protocols, use protected transport and confirm destination identity. A configured loopback can supply a stable address but needs usable routing. Do not copy an entire checklist without checking support, required services and the risk of blocking the only recovery path.

2. Separate the three AAA decisions

Authentication addresses identity; authorization determines services or commands; accounting records actions and sessions. In the fictional worksheet, login succeeds but a command authorized by the change request is denied. Investigate authorization policy and effective profile before changing the password. In another case, commands work but destination records are missing: access success does not establish accounting. Retain user, device, origin, time, session and the command needed for diagnosis without passwords. Explicitly test an allowed command, a denied command, record arrival and failure recovery. An account able to log in is not automatically authorized to do everything.

3. Distinguish rejection from unavailability

In the studied IOS XE list, TACACS+ precedes local authentication. Explicit rejection should not be treated as a transport error to try local credentials until access succeeds. The next method is attempted on error or no response according to the configured list and service. Test ACCEPT, REJECT and server unavailability separately, including authorization after login. Two AAA entries depending on the same route or identity service can fail together. Emergency accounts need scope, protection, ownership and review after use. The none authorization method can permit access when used; it is not equivalent to a least-privilege local account.

4. Validate transport and related controls

The hardening guide recommends TACACS+ over TLS 1.3 on supporting releases and identifies the old obfuscation mechanism as obsolete. The consulted example uses IOS XE 17.18.1 and ISE 3.4 Patch 2; confirm models, releases, certificates and both-end configuration. “Reachable port” does not establish successful TLS authentication. For SNMP, review authentication, content protection, views and write access rather than accepting only the v3 label. In CoPP, an ACL used for classification does not necessarily have the effect of an interface ACL: permit can select the class whose policy map drops traffic. Read classification and action together before changing them.

5. Demonstrate access after the change

Keep an authorized recovery path during the window and open a new session to test policy; an old session may continue without exercising new authentication. Define rollback criteria for errors, lost access and service impact. Collect classification counters, drops, CPU and required traffic when interpreting a CoPP change; increased drops alone establish neither attack nor control success. Synchronize time and confirm RUN can search destination accounting records. The worksheet contains eight planned tests not executed on Cisco. Summary: validate path, transport, authentication, authorization, recording and recovery as separate stages with evidence and ownership.

IN PRACTICE

Login ACCEPT and command REJECT refer to different stages; changing the password does not demonstrate repaired authorization.

Common pitfalls

REJECT as timeout; old session as a new test; none as least privilege; permit in a classification ACL as final authorization.

Related topics: AAA and TACACS+ · Management plane and CoPP · Change and continuity

Take this idea with you

Administrative access is accepted only when identity, action, auditing and recovery work within intended scope.

Create account

Reference: Cisco IOS XE Software Hardening Guide · 350-701 SCOR v2.0, effective 2026-08-27; core component of CCNP Security

CCNP® and Cisco® are registered trademarks of Cisco Systems, Inc. and/or its affiliates. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by Cisco. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.