Enterasys Networks CSX7000, CSX5500, CSX6000 manual Tacacs Authentication Server

Models: CSX7000 CSX6000 CSX5500

1 729
Download 729 pages 41.51 Kb
Page 218
Image 218

USER’S GUIDE

If a specific set of parameters is required for a particular device, configure the specific device independently, either locally (through the on-node device list) or in CSM. The CyberSWITCH will look at the configured device table first before proceeding to the dynamic device default configuration. Since the configured device table overrides the default configuration, leave the dynamic device option enabled, and configure specific devices for exceptional cases only.

TACACS AUTHENTICATION SERVER

CONFIGURING A TACACS AUTHENTICATION SERVER

Note: In order for the CyberSWITCH to reference the TACACS server, basic IP information must be configured. If the IP Host mode is not in use, you must also configure the following:

a LAN Network interface must be configured appropriately for the IP network connected to each LAN port on the system

at least one WAN Network Interface must be configured for TACACS to be operable

USING CFGEDIT

1.Select option (3), TACACS from the Off-node Server Information menu. If you need guidance to find this menu, refer to the instructions provided in the CSM Authentication Server configuration section. The following screen will be displayed:

TACACS Authentication Server Menu:

 

Primary Server

 

IP Address

is 001.002.003.004

UDP Port Number

is 49

Secondary Server

 

IP Address

is 001.002.003.008

UDP Port Number

is 49

Access Request Retry

 

Number of Access Retries

is 3

Time between Retries

is 1 second

TACACS Packet Format

is (ID CODE,PIN)

TACACS Server Configuration Options:

1) Primary Server

2) Secondary Server

3) Access Request Retry

Select function from above or <RET> for previous menu:

2.Select (1) Primary Server to enter the following information:

a.IP address of the Authentication Server

b.UDP port number used by the Authentication Server

3.Optional: configure a secondary TACACS Server with selection (2). In the event that the primary server does not respond to system requests, the secondary server will be queried for device authentication information. The address of the Secondary Server must not be the same as the Primary Server.

4.Select (3) Access Request Retry to finish configuration. Specify the number of access request retries that the system will send to the Authentication Server, as well as the time between retries. You may also specify order of the TACACS authentication prompts for access request.

218 CyberSWITCH

Page 218
Image 218
Enterasys Networks CSX7000, CSX5500, CSX6000 manual Configuring a Tacacs Authentication Server