Dell Force10 S4810P Configuration Manual page 896

High-density, 1ru 48-port 10gbe switch
Hide thumbs Also See for Force10 S4810P:
Table of Contents

Advertisement

Figure 43-5
configured access-class on the VTY line to be ignored. If you have configured a
TACACS+ server, FTOS downloads it and applies it. If the user is found to be coming from the 10.0.0.0
subnet, FTOS also immediately closes the T elnet connection. Note, that no matter where the user is coming
from, they see the login prompt.
Figure 43-5. Specify a TACACS+ server host
FTOS#
FTOS(conf)#
FTOS(conf)#ip access-list standard deny10
FTOS(conf-std-nacl)#permit 10.0.0.0/8
FTOS(conf-std-nacl)#deny any
FTOS(conf)#
FTOS(conf)#aaa authentication login tacacsmethod tacacs+
FTOS(conf)#aaa authentication exec tacacsauthorization tacacs+
FTOS(conf)#tacacs-server host 25.1.1.2 key Force10
FTOS(conf)#
FTOS(conf)#line vty 0 9
FTOS(config-line-vty)#login authentication tacacsmethod
FTOS(config-line-vty)#authorization exec tacauthor
FTOS(config-line-vty)#
FTOS(config-line-vty)#access-class deny10
FTOS(config-line-vty)#end
When configuring a TACACS+ server host, you can set different communication parameters, such as the
key password.
To specify a TACACS+ server host and configure its communication parameters, use the following
command in the CONFIGURATION mode:
Command Syntax
tacacs-server host
} [
port port-number
ip-address
[
] [
timeout seconds
To specify multiple TACACS+ server hosts, configure the
multiple TACACS+ server hosts are configured, FTOS attempts to connect with them in the order in which
they were configured.
To view the TACACS+ configuration, use the
mode.
896
|
Security
demonstrates how to configure the
Command Mode
{
|
CONFIGURATION
hostname
]
]
key key
from a TACACS+ server. This causes the
access-class
Purpose
Enter the host name or IP address of the TACACS+
server host. Configure the optional communication
parameters for the specific host:
port port-number
number. The default is 49.
timeout seconds
seconds.
Enter a string for the key. The key can be up
key key:
to 42 characters long. This key must match a key
configured on the TACACS+ server host. This
parameter should be the last parameter configured.
If these optional parameters are not configured, the
default global values are applied.
tacacs-server host
show running-config tacacs+
ACL on the
deny10
range: 0 to 65335. Enter a TCP port
range: 0 to 1000. Default is 10
command multiple times. If
command in the EXEC Privilege

Advertisement

Table of Contents
loading

Table of Contents