Installation and Getting Started Guide
Specifying a Single Source Interface for Telnet, TACACS/TACACS+, or RADIUS Packets
When the routing switch originates a Telnet, TACACS/TACACS+, or RADIUS packet, the source address of the packet is the
Identifying a single source IP address for Telnet, TACACS/TACACS+, or RADIUS packets provides the following benefits:
•If your Telnet, TACACS/TACACS+, or RADIUS server is configured to accept packets only from specific IP addresses, you can use this feature to simplify configuration of the server by configuring the device to always send the packets from the same link or source address.
•If you specify a loopback interface as the single source for Telnet, TACACS/TACACS+, or RADIUS packets, servers can receive the packets regardless of the states of individual links. Thus, if a link to the server becomes unavailable but the client or server can be reached through another link, the client or server still receives the packets, and the packets still have the source IP address of the loopback interface.
The software contains separate CLI commands for specifying the source interface for Telnet, TACACS/TACACS+, or RADIUS packets. You can configure a source interface for one or more of these types of packets separately.
To specify an Ethernet port or a loopback or virtual interface as the source for all TACACS/TACACS+ packets from the device, use the following CLI method. The software uses the
USING THE CLI
The following sections show the syntax for specifying a single source IP address for Telnet, TACACS/TACACS+, and RADIUS packets.
Telnet Packets
To specify the
HP9300(config)# int loopback 2
HP9300(config)# ip telnet
The commands in this example configure loopback interface 2, assign IP address 10.0.0.2/24 to the interface, then designate the interface as the source for all Telnet packets from the routing switch.
Syntax: ip telnet
The <num> parameter is a loopback interface or virtual interface number. If you specify an Ethernet port, the <portnum> is the port’s number (including the slot number, if you are configuring a chassis device).
The following commands configure an IP interface on an Ethernet port and designate the address port as the source for all Telnet packets from the routing switch.
HP9300(config)# interface ethernet 1/4
HP9300(config)# ip telnet
TACACS/TACACS+ Packets
To specify the
HP9300(config)# int ve 1
6 - 26