CONFIGURING OFF-NODE SERVER INFORMATION

TACACS Authentication Server

information from the secondary server if one is configured. The connection will be released if neither server responds to the access requests.

The section titled On-node Device Table Security Requirements describes the device authentication information required for each type of remote device. The information you need to configure depends upon what you have configured for the CyberSWITCH operating mode (bridging and/or routing), and the security options you select.

To configure the RADIUS Server itself, refer to the RADIUS Authentication Server User’s Guide. If you have Internet access, you may obtain this guide by following the steps outlined below:

Use your Web browser to get to the following address: http:// service.nei.com

From the resulting screen, click on Public.

Click on the Radius directory.

Click on the Docs directory. The guide will be under this directory.

TACACS AUTHENTICATION SERVER

CONFIGURING A TACACS AUTHENTICATION SERVER

Note: In order for the CyberSWITCH to reference the TACACS server, basic IP information must be configured. If the IP Host mode is not in use, you must also configure the following:

a LAN Network interface must be configured appropriately for the IP network connected to each LAN port on the system

at least one WAN Network Interface must be configured for TACACS to be operable

USING CFGEDIT

1.Select option (3), TACACS from the Off-node Server Information menu. If you need guidance to find this menu, refer to the instructions provided in the VRA Manager Authentication Server configuration section. The following screen will be displayed:

TACACS Authentication Server Menu:

 

Primary Server

 

IP Address

is 001.002.003.004

UDP Port Number

is 49

Secondary Server

 

IP Address

is 001.002.003.008

UDP Port Number

is 49

Access Request Retry

 

Number of Access Retries

is 3

Time between Retries

is 1 second

TACACS Packet Format

is (ID CODE,PIN)

TACACS Server Configuration Options:

1) Primary Server

2) Secondary Server

3) Access Request Retry

Select function from above or <RET> for previous menu:

2.Select (1) Primary Server to enter the following information:

a.IP address of the Authentication Server

b.UDP port number used by the Authentication Server

Workgroup Remote Access Switch 183

Page 183
Image 183
Cabletron Systems CSX1200, CSX1000 manual Configuring a Tacacs Authentication Server