Aaa Server Groups; Aaa Service Configuration Options - Cisco AP775A - Nexus Converged Network Switch 5010 Configuration Manual

Cli software configuration guide
Hide thumbs Also See for AP775A - Nexus Converged Network Switch 5010:
Table of Contents

Advertisement

Information About AAA

AAA Server Groups

You can specify remote AAA servers for authentication, authorization, and accounting using server groups.
A server group is a set of remote AAA servers that implement the same AAA protocol. The purpose of a
server group is to provide for failover servers in case a remote AAA server fails to respond. If the first remote
server in the group fails to respond, the next remote server in the group is tried until one of the servers sends
a response. If all the AAA servers in the server group fail to respond, then that server group option is considered
a failure. If required, you can specify multiple server groups. If a Cisco Nexus 5000 Series switch encounters
errors from the servers in the first group, it tries the servers in the next server group.

AAA Service Configuration Options

On Cisco Nexus 5000 Series switches, you can have separate AAA configurations for the following services:
• User Telnet or Secure Shell (SSH) login authentication
• Console login authentication
• User management session accounting
The following table lists the CLI commands for each AAA service configuration option.
Table 21: AAA Service Configuration Commands
AAA Service Configuration Option
Telnet or SSH login
Console login
User session accounting
You can specify the following authentication methods for the AAA services:
• RADIUS server groups—Uses the global pool of RADIUS servers for authentication.
• Specified server groups—Uses specified RADIUS or TACACS+ server groups for authentication.
• Local—Uses the local username or password database for authentication.
• None—Uses only the user name.
Note
If the method is for all RADIUS servers, instead of a specific server group, the Nexus 5000 Series switches
choose the RADIUS server from the global pool of configured RADIUS servers in the order of
configuration. Servers from this global pool are the servers that can be selectively configured in a RADIUS
server group on the Nexus 5000 Series switches.
The following table describes the AAA authentication methods that you can configure for the AAA services.
OL-16597-01
Related Command
aaa authentication login default
aaa authentication login console
aaa accounting default
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
AAA Server Groups
229

Advertisement

Table of Contents
loading

Table of Contents