3Com Switch 8800 Configuration Guide Chapter 40 AAA and RADIUS/TACACS+ Protocol Con
figuration
40-23
Configuring TACACS+ Authentication Servers
z Configuring TACACS+ Authorization Servers
z Configuring TACACS+ Accounting Servers and the Related Attributes
z Configuring the Source Address for TACACS+ Packets Sent by NAS
z Setting a Key for Securing the Communication with TACACS Server
z Setting the Username Format Acceptable to the TACACS Server
z Setting the Unit of Data Flows Destined for the TACACS Server
z Setting Timers Regarding TACACS Server
Note:
Pay attention to the following when configuring a TACACS server:
z TACACS+ server does not check whether a scheme is being used by users when
changing most of HWTACS attributes, unless you delete the scheme.
z By default, the TACACS server has no key.
In the above configuration tasks, creating TACACS+ scheme and configuring TACACS
authentication/authorization server are required; all other tasks are optional and you
can determine whether to perform these configurations as needed.
40.4.1 Creating a HWTACAS Scheme
As aforementioned, TACACS+ protocol is configured scheme by scheme. Therefore,
you must create a TACACS+ scheme and enter TACACS+ view before you perform
other configuration tasks.
Perform the following configuration in system view.
Table 40-26 Create a TACACS+ scheme
Operation Command
Create a TACACS+ scheme and
enter TACACS+ view TACACS+ scheme
TACACS+-scheme-name
Delete a TACACS+ scheme undo TACACS+ scheme
TACACS+-scheme-name
By default, no TACACS+ scheme exists.
If the TACACS+ scheme you specify does not exist, the system creates it and enters
TACACS+ view. In TACACS+ view, you can configure the TACACS+ scheme
specifically.
The system supports up to 16 TACACS+ schemes. You can only delete the schemes
that are not being used.