Tacacs+ Client Configuration - Avaya ERS 1600 Technical Configuration Manual

Authentication, authorization and accounting (aaa) for ers and es
Hide thumbs Also See for ERS 1600:
Table of Contents

Advertisement

avaya.com

3.5 TACACS+ Client Configuration

Two different product lines, ERS 5500 (and 2500, 4500 in the future) use a specific logic for configuration
whereas ERS 1600, 8300 (and 8600 in the future) each uses a different logic for configuration.
Network diagram with TACAC+ client and server can be simplified and summarized as shown below:
Telnet/SSH/CLI
Administrative User
10.10.50.40
10.10.50.5
ERS 5510
ERS 8300
10.10.55.6
Tac_plus
Server
Key = Dda
3.5.1 ERS 5500
ACLI or JDM (Java Device Manager) can be used to configure the switch. For simplicity and readability,
we will document command line interface (CLI) commands assuming the TACACS+ server IP address is
10.10.50.40, and the client key is ―Dda‖ for telnet access authentication.
To configure TACACS+
5510# conf t
Enter configuration commands, one per line.
End with CNTL/Z.
5510(config)# tacacs server host 10.10.50.40
5510(config)# tacacs server key
Dda
5510(config)# tacacs authorization enable
5510(config)# tacacs authorization level all
5510(config)# tacacs accounting enable
5510(config)# cli password switch telnet tacacs
To display TACACS configuration
5510# show tacacs
Primary Host:
10.10.50.40
Secondary Host:
0.0.0.0
Authentication, Authorization and Accounting (AAA) for ERS and ES
November 2010
47
Technical Configuration Guide

Advertisement

Table of Contents
loading

Table of Contents