Skip to main content

AAA Settings

Location in GUI: Admin » AAA » Authentication » AAA

Diagram

Classes

aaa (apic.fabric_policies)

NameTypeConstraintMandatoryDefault Value
remote_user_login_policyChoiceassign-default-role, no-loginNono-login
default_fallback_checkBooleantrue, falseNofalse
default_realmChoicelocal, tacacs, ldap, radiusNolocal
default_login_domainStringRegex: ^[a-zA-Z0-9_.:-]{1,64}$No
console_realmChoicelocal, tacacs, ldap, radiusNolocal
console_login_domainStringRegex: ^[a-zA-Z0-9_.:-]{1,64}$No
management_settingsClass[management_settings]No
security_domainsList[security_domains]No

management_settings (apic.fabric_policies.aaa)

NameTypeConstraintMandatoryDefault Value
password_strength_checkBooleantrue, falseNofalse
password_strength_profileClass[password_strength_profile]No
password_change_during_intervalBooleantrue, falseNotrue
password_change_countIntegermin: 0, max: 10No2
password_change_intervalIntegermin: 0, max: 745No48
password_no_change_intervalIntegermin: 0, max: 745No24
password_history_countIntegermin: 0, max: 15No5
web_token_timeoutIntegermin: 300, max: 9600No600
web_token_max_validityIntegermin: 4, max: 24No24
web_session_idle_timeoutIntegermin: 600, max: 65525No1200
include_refresh_session_recordsBooleantrue, falseNotrue
enable_login_blockBooleantrue, falseNofalse
login_block_durationIntegermin: 1, max: 1440No60
login_max_failed_attemptsIntegermin: 1, max: 15No5
login_max_failed_attempts_windowIntegermin: 1, max: 720No5

security_domains (apic.fabric_policies.aaa)

NameTypeConstraintMandatoryDefault Value
nameStringRegex: ^[a-zA-Z0-9_.:-]{1,64}$Yes
descriptionStringRegex: ^[a-zA-Z0-9\\!#$%()*,-./:;@ _{|}~?&+]{1,128}$No
restricted_rbac_domainBooleantrue, falseNofalse

password_strength_profile (apic.fabric_policies.aaa.management_settings)

NameTypeConstraintMandatoryDefault Value
password_mininum_lengthIntegermin: 8, max: 64No8
password_maximum_lengthIntegermin: 8, max: 64No64
password_strength_test_typeChoicedefault, customNodefault
password_class_flagsListChoice[digits, lowercase, specialchars, uppercase]No

Examples

apic:
fabric_policies:
aaa:
remote_user_login_policy: no-login
default_fallback_check: true
default_realm: local
console_realm: tacacs
console_login_domain: tacacs
security_domains:
- name: SEC1
restricted_rbac_domain: true
management_settings:
password_strength_check: true
password_strength_profile:
password_mininum_length: 8
password_maximum_length: 64
password_strength_test_type: default
password_class_flags:
- digits
- lowercase
- uppercase
password_change_during_interval: true
password_change_count: 2
password_change_interval: 48
password_no_change_interval: 24
password_history_count: 5
web_token_timeout: 600
web_token_max_validity: 24
web_session_idle_timeout: 1200
include_refresh_session_records: true
enable_login_block: false
login_block_duration: 60
login_max_failed_attempts: 5
login_max_failed_attempts_window: 5