TACACS Commands 327
TACACS Commands

tacacs-server host

The
tacacs-server host
Global Configuration mode command specifies a TACACS+ host. To
delete the specified name or address, use the
no
form of this command.
Syntax
tacacs-server host {
ip-address
|
hostname
}
[
single-connection
] [
port
port-number
] [
timeout
timeout
] [
key
key-string
] [
source
source
] [
priority
priority
]
no tacacs-server host {
ip-address
|
hostname
}
ip-address
—Name or IP address of the host.
hostname
—Hostname of the tacacs server. (Range: 1 - 158 characters)
single-connection
—Specify single-connection. Rather than have the device open and
close a TCP connection to the daemon each time it must communicate, the single-
connection option maintains a single open connection between the device and the
daemon.
port-number—
Specify a server port number. If unspecified, the port number defaults to
49. (Range: 0 - 65535)
timeout—
Specifies the timeout value in seconds. If no timeout value is specified, the
global value is used. (Range: 1 - 30)
key-string—
Specifies the authentication and encryption key for all TACACS
communications between the device and the TACACS server. This key must match the
encryption used on the TACACS daemon. If no key string value is specified, the global
value is used. (Range: 0 - 128 characters)
source—
Specifies the source IP address to use for the communication. If no source value
is specified, the global value is used.
priority—
Determines the order in which the servers will be used, when 0 is the highest
priority. If unspecified defaults to 0. (Range: 0 - 65535)
Default Configuration
No TACACS host is specified
Command Mode
Global Configuration mode
User Guidelines
Multiple
tacacs-server host
commands can be used to specify multiple hosts.