What to Do Next
Createan TACACS+ provider.
Creating a TACACS+ Provider
CiscoUCS Managersupports amaximum of 16 TACACS+providers.
Before You Begin
Performthe following configuration in the TACACS+ server:
• Create the cisco-av-pair attribute. Youcannot use an existing TACACS+ attribute.
Thecisco-av-pair name is the string that provides the attribute ID for the TACACS+ provider.
Thefollowing syntaxexample shows how to specify multiples user roles and locales when you create
thecisco-av-pair attribute: cisco-av-pair=shell:roles="admin aaa" shell:locales*"L1 abc".
Usingan asterisk (*) in the cisco-av-pairattribute syntax flags the locale as optional, preventing
authenticationfailures for other Cisco devices that use the same authorizationprofile. Usea space as
thedelimiter to separatemultiple values.
• For a cluster configuration, add the management port IP addresses for both fabric interconnects.This
configurationensures that remote users can continue to log in if the first fabric interconnect fails and
thesystem fails over to the second fabric interconnect. All login requests are sourced from these IP
addresses,not the virtualIP address used by Cisco UCS Manager.
Procedure
Step 1 Inthe Navigation pane, clickthe Admin tab.
Step 2 Onthe Admin tab, expand All >User Management>TACACS+.
Step 3 Inthe Actions area of the General tab, click CreateTACACS+ Provider.
Step 4 Inthe Create TACACS+ Provider dialog box:
a) Complete the fields with the information about the TACACS+ service you want to use.
DescriptionName
Thehostname or IP address on which the TACAS+ provider resides.
Ifyou use a hostname ratherthan an IP address, you must
configurea DNS server in Cisco UCS Manager.
Note
Hostnamefield
Theorder in which Cisco UCS uses this provider to authenticate
users.
Enteran integer between 1 and 16, or enter lowest-available or 0
(zero)if you want Cisco UCS to assign the next available order based
onthe other providers defined in this Cisco UCS domain.
Orderfield
TheSSL encryptionkey for the database.Keyfield
TheSSL encryptionkey repeatedfor confirmationpurposes.ConfirmKey field
Cisco UCS Manager GUI Configuration Guide, Release 2.0
OL-25712-04 145
Configuring TACACS+ Providers