TACACS+ Authentication
Configuring TACACS+ on the Switch
other access type (console, in this case) open in case the Telnet access fails due to a configuration problem. The following procedure outlines a general setup procedure.
Note | If a complete access lockout occurs on the switch as a result of a TACACS+ | |
| configuration, see “Troubleshooting TACACS+ Operation” in the Trouble- | |
| shooting chapter of the Management and Configuration Guide for your | |
| switch. |
|
| 1. Familiarize yourself with the requirements for configuring your | |
| ||
| TACACS+ server application to respond to requests from a switch. (Refer | |
| to the documentation provided with the TACACS+ server software.) This | |
| includes knowing whether you need to configure an encryption key. (See | |
| ||
| 2. Determine the following: |
|
| • The IP address(es) of the TACACS+ | • The period you want the switch to |
| server(s) you want the switch to use | wait for a reply to an authentication |
| for authentication. If you will use | request before trying another |
| more than one server, determine | server. |
| which server is your | • The username/password pairs you |
| authentication services. | want the TACACS+ server to use for |
| • The encryption key, if any, for | controlling access to the switch. |
| allowing the switch to communicate | • The privilege level you want for |
| with the server. You can use either a | each username/password pair |
| global key or a | administered by the TACACS+ |
| depending on the encryption | server for controlling access to the |
| configuration in the TACACS+ | switch. |
| server(s). | • The username/password pairs you |
| • The number of | |
| want to use for local authentication | |
| will allow before closing a | (one pair each for Operator and |
| session. (Default: 3) | Manager levels). |
3. Plan and enter the TACACS+ server configuration needed to support TACACS+ operation for Telnet access (login and enable) to the switch. This includes the username/password sets for logging in at the Operator