Configuring Ftp And Ssh Messaging Format For Aaa Servers - Cisco MGX 8850 (PXM1E/PXM45) Configuration Manual

Multiservice switch
Table of Contents

Advertisement

Managing Remote (TACACS+) Authentication and Authorization
Replace the authorType variable with group to select group mode or with command to select command
mode. As with the cnfaaa-authen command, you can specify up to three methods (see
authorization, and the switch will use these methods in the configured order. As with authentication, the
local method is not a practical substitute for AAA server authorization because it requires data entry in
the AAA server and every supported switch.
The following example configures the switch to use group mode for authorization:
M8830_SF.2.PXM.a > cnfaaa-author group tacacs+
AAA CONFIGURATION:
Authentication Methods
Authorization Methods
Authorization Type
Default Privilege Level :
Prompt Display
SSH/FTP Message Type
IOS Exclusion List
WARNING: The newly configured authentication/authorization methods will
apply to new session.

Configuring FTP and SSH Messaging Format for AAA Servers

When the switch configuration uses an AAA server for authentication and authorization, FTP and SSH
requests are directed to the remote server. The TACACS+ message format for these requests can be either
ASCII or PAP.
One special application of the FTP and SSH messaging format applies when the AAA server is
configured to issue challenges, which are not supported by FTP and SSH. In this application, the PAP
message format should be configured.
To select the messaging format, log in using a username with SERVICE_GP privileges or higher and
enter the cnfaaa-ftpssh command in the following format:
M8850_LA.7.PXM.a >
Enter the ascii keyword to select TACACS+ ASCII login messages. Enter the pap keyword to select
TACACS+ PAP login messages. The default keyword selects TACACS+ ASCII login messages.
The following example selects the PAP message format:
M8830_SF.2.PXM.a > cnfaaa-ftpssh pap
AAA CONFIGURATION:
Authentication Methods
Authorization Methods
Authorization Type
Default Privilege Level :
Prompt Display
SSH/FTP Message Type
IOS Exclusion List
Cisco MGX 8850 (PXM1E/PXM45), Cisco MGX 8950, Cisco MGX 8830, and Cisco MGX 8880 Configuration Guide
9-70
:
tacacs+ cisco
: tacacs+ cisco
:
group
NOUSER_GP
:
acs
:
Inbound ASCII Login
:
This configuration has no impact on existing sessions.
cnfaaa-ftpssh <ascii|pap|default>
:
tacacs+ cisco
:
local cisco
:
group
NOUSER_GP
:
acs
:
Inbound PAP Login
:
Chapter 9
Switch Operating Procedures
Table
Release 5.0.10, OL-3845-01 Rev. B0, August 16, 2004
9-30) for

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mgx 8950Mgx 8830Mgx 8880

Table of Contents