9-29
Using Passwords and TACACS+ To Protect Against Una uthorized Access
TACACS+ Authentication for Cent ral Control of Switch Access S ecurity
Using Passwords and
TACACS+
Operating Notes
If you configure Authorized IP Managers on the switch, it is not
necessary to include any devices used as TACACS+ servers in the
authorized manager list. That is, au thentication traffic between a
TACACS+ server and the switch is not subject to Authorized IP
Manager controls configured on the switch. Also, the switch does not
attempt TACACS+ authentication for a management station that the
Authorized IP Manager list excludes because, independent of
TACACS+, the switch already denies access to such stations.
When TACACS+ is not enabled on the switchor when the switchs
only designated TACACS+ servers are not accessible setting a local
Operator password without also setting a local Manager password
does not protect the switch from manager-level access by unautho-
rized persons.)
Troubleshooting TACACS+ Operation
Event Log. When troubleshooting TACACS+ operation, check the switchs
Event Log for indications of problem areas.
For specific troubleshooting help, see TACACS-Related Problems on page
18-9.