TACACS and TACACS+ security

4 – Records commands available at the Port Configuration level (port-config and read-only commands)

5 – Records commands available at the Read Only level (read-only commands)

Configuring TACACS+ accounting for system events

You can configure TACACS+ accounting to record when system events occur on the Brocade device. System events include rebooting and when changes to the active configuration are made.

The following command causes an Accounting Start packet to be sent to the TACACS+ accounting server when a system event occurs, and a Accounting Stop packet to be sent when the system event is completed.

Brocade(config)# aaa accounting system default start-stop tacacs+

Syntax: aaa accounting system default start-stop radius tacacs+ none

Configuring an interface as the source for all

TACACS and TACACS+ packets

You can designate the lowest-numbered IP address configured an Ethernet port, loopback interface, or virtual interface as the source IP address for all TACACS/TACACS+ packets from the Layer 3 switch. For configuration details, refer to Brocade ICX 6650 Layer 3 Routing Configuration Guide.

Displaying TACACS/TACACS+ statistics and configuration information

The show aaa command displays information about all TACACS+ and RADIUS servers identified on the device.

Brocade# show aaa Tacacs+ key: foundry Tacacs+ retries: 1 Tacacs+ timeout: 15 seconds Tacacs+ dead-time: 3 minutes

Tacacs+ Server: 10.95.6.90 Port:49:

opens=6 closes=3 timeouts=3 errors=0 packets in=4 packets out=4

no connection

Radius key: networks

Radius retries: 3

Radius timeout: 3 seconds

Radius dead-time: 3 minutes

Radius Server: 10.95.6.90 Auth Port=1645 Acct Port=1646: opens=2 closes=1 timeouts=1 errors=0 packets in=1 packets out=4

no connection

The following table describes the TACACS/TACACS+ information displayed by the show aaa command.

40

Brocade ICX 6650 Security Configuration Guide

 

53-1002601-01

Page 60
Image 60
Brocade Communications Systems 6650 manual Configuring TACACS+ accounting for system events