6-10
Catalyst 3550 Multilayer Switch Software Configuration Guide
78-11194-03
Chapter6 Administering the Switch
Controlling Switch Access with TACACS+

Logging into and Exiting a Privilege Level

Beginning in privileged EXEC mode, follow these steps to log in to a specified privilege level and t o exit
to a specified privilege level:
Controlling Switch Access with TACACS+
This section describes how to enable and configure Terminal Acc es s C ontroller Access Control System
Plus (TACACS+), which provides detailed accounting information and flexible administrative control
over authentication and authorization processes. TACACS+ is facilitated through authentication,
authorization, accounting (AAA) and can be enabled only through AAA commands.
Note For complete syntax and usage information for the commands used in this section, refer to the Cisco
IOS Security Command Reference for Release 12.1.
This section contains this configuration information:
Understanding TACACS+, page 6-10
TACACS+ Operation, page 6-12
Configuring TACACS+, page 6-13
Displaying the TACACS+ Configuration, page 6-17

Understanding TACACS+

TACACS+ is a security application that provides centralized validation of users attempting to gain
access to your switch. TACACS+ services are maintained in a database on a TACACS+ daemon
typically running on a UNIX or Windows NT workstation. You should have access to and should
configure a TACACS+ server before the configuring TACACS+ features on your switch.
TACACS+ provides for separate and modular authentication, authorization, and accounting facilities.
TACACS+ allows for a single access control server (the TACACS+ daemon) to provide each
service—authentication, authorization, and accounting—independently. Each servic e can be tied into its
own database to take advantage of other services available on that server or on the netw ork, dep endi ng
on the capabilities of the daemon.
Command Purpose
Step1 enable level Log in to a specified privilege level.
For level, the range is 0 to 15.
Step2 disable level Exit to a specified privilege level.
For level, the range is 0 to 15.