EX2500 Ethernet Switch Configuration Guide
NOTE: When you are using the EX2500 Web Device Manager, the TACACS+ Accounting Stop records are sent only if the Logout button on the browser is clicked.
Command Authorization and Logging
When TACACS+ Command Authorization is enabled, EX2500 configuration commands are sent to the TACACS+ server for authorization. Use the following command to enable TACACS+ Command Authorization:
ex2500(config)#
When TACACS+ Command Logging is enabled, EX2500 configuration commands are logged on the TACACS+ server. Use the following command to enable TACACS+ Command Logging:
ex2500(config)#
The following examples illustrate the format of EX2500 commands sent to the
TACACS+ server:
authorization request, cmd=shell,
Configuring TACACS+ Authentication on the Switch
1.Configure the Primary and Secondary TACACS+ servers, and enable TACACS authentication.
ex2500(config)#
2.Configure the TACACS+ secret and second secret.
ex2500(config)#
ex2500(config)#
3.If desired, you may change the default TCP port number used to listen to TACACS+. The
ex2500(config)#
4.Configure the number of retry attempts and the timeout period.
ex2500(config)#
16 Securing Access to the Switch