7-11
Catalyst 2950 Desktop Switch Software Configuration Guide
78-14982-01
Chapter 7 Adminis tering the Switch Controlling Switch Access with TACACS+
Figure 7-1 Typical TACACS+ Network Configuration
TACACS+, administered through the AAA security services, can provide these services:
AuthenticationProvides complete control of au then ticatio n through logi n and password dialog,
challe nge and response , and messa ging suppor t.
The authentication facility can conduct a dialog with the user (for example, after a username and
password are provided, to challenge a user with several questions, such as home address, mothers
maiden name, service type, and social security number). The TACACS+ authentication service can
also send messages to user screens. For example, a message could notify users that their passwords
must be changed because of the companys password aging po licy.
AuthorizationProvides fine-grained control over user capabilities for the duration of the users
session, including but not limited to setting autocommands, access control, session duration, or
protoc ol su ppo rt. You c an al so e nfo rce re stri ctio ns o n wh at co mmand s a u ser ca n execu te wi th t he
TACACS+ authorization feature.
AccountingCollects and sends information used for billing, auditing, and reporting to the
TACACS+ daemon. N etwork mana gers can use the accounti ng facility t o track user ac tivity for a
security au dit o r to pro vide inf orma tio n f or u ser bil lin g. A cco u nting records i nc lude u ser iden tities,
start and stop times, executed commands (such as PPP), number of packets, and number of bytes.
The TACAC S+ pr otoc ol pr ovides a uthe nti cati on b etwe en th e swi tc h and t he TACACS+ daemon, and it
ensures confidentiality because all protocol exchanges between the switch and the TACACS+ daemon
are en cryp ted.
You need a system ru nning the TACAC S+ daem on software to us e TACACS+ on your switch .
UNIX workstation
(TACACS+
server 2)
UNIX workstation
(TACACS+
server 1)
Catalyst 2950 or
3550 switches
Configure the switches with the
TACACS+ server addresses.
Set an authentication key
(also configure the same key on
the TA CACS+ servers).
Enable AAA.
Create a login authentication method list.
Apply the list to the terminal lines.
Create an authorization and accounting
method list as required.
Catalyst 6500
series switch
Workstations
171.20.10.8
171.20.10.7
74720
Workstations