We upgraded our 3810M from KB.16.10.0011 to KB.16.11.0002
prior to that, when we'd SSH into the switch, we'd authenticate via AAA server, then type in 'enable' and authenticate again (same creds).
After the upgrade, I can SSH & authenticate fine, but when I go do 'enable', and enter in creds, I get the "Access denied; maximum session limit for the user is reached." message
Even if I use a different identity for the enable than from the login, same message (in case there was some secret limit of 1)
On the Radius side, it shows it is authenticating / granting access each time.
I didn't see anything in the release notes around anything impacting aaa or radius.
I can get in by stopping the radius servers and using local accounts, but would be nice to have the AAA working properly again.
No changes to the commands done, still looks like:
aaa server-group radius "Auth1" host 192.168.5.10
aaa server-group radius "Auth1" host 192.168.5.11
aaa authentication ssh login radius server-group "Auth1" local
aaa authentication ssh enable radius server-group "Auth1" local
Wasn't finding much in the way of hits on the error message.
------------------------------
John Fedor
------------------------------