Prerequisites For Remote Aaa; Aaa Guidelines And Limitations - Cisco nexus 5000 series Cli Configuration Manual

Hide thumbs Also See for nexus 5000 series:
Table of Contents

Advertisement

Prerequisites for Remote AAA

S e n d f e e d b a c k t o n x 5 0 0 0 - d o c f e e d b a c k @ c i s c o . c o m
Prerequisites for Remote AAA
Remote AAA servers have the following prerequisites:

AAA Guidelines and Limitations

The Nexus 5000 Series switches do not support all numeric usernames, whether created with TACACS+
or RADIUS, or created locally, and do not create local users with all numeric names. If an all numeric
username exists on an AAA server and is entered during login, the Nexus 5000 Series switch will log in
the user.
Configuring AAA
To configure AAA authentication and accounting, perform this task:
If you want to use remote RADIUS or TACACS+ servers for authentication, configure the hosts on your
Step 1
Nexus 5000 Series switch. See
TACACS+."
Step 2
Configure console login authentication methods. See the
Methods" section on page
Step 3
Configure default login authentication methods for user logins. See the
Authentication Methods" section on page 1-8
Configure default AAA accounting default methods. See the
Step 4
Methods" section on page
The following topics describe the AAA configuration procedure in more details:
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
1-6
At least one RADIUS or TACACS+ server must be IP reachable (see the
Server Hosts" section on page 1-5
page
1-6)
The Nexus 5000 Series switch is configured as a client of the AAA servers.
The preshared secret key is configured on the Nexus 5000 Series switch and on the remote AAA
servers.
The remote server responds to AAA requests from the Nexus 5000 Series switch (see the
Monitoring RADIUS Servers or Groups" section on page 1-14
TACACS+ Servers or Groups" section on page
1-7.
1-10.
Configuring Console Login Authentication Methods, page 1-7
Configuring Default Login Authentication Methods, page 1-8
Enabling Login Authentication Failure Messages, page 1-9
Enabling MSCHAP Authentication, page 1-9
Configuring AAA Accounting Default Methods, page 1-10
Using AAA Server VSAs with Nexus 5000 Series Switches, page 1-11
and the
"Configuring TACACS+ Server Hosts" section on
1-13).
Chapter 1, "Configuring RADIUS"
"Configuring Console Login Authentication
Chapter 1
"Configuring RADIUS
and the
"Manually Monitoring
and
Chapter 1, "Configuring
"Configuring Default Login
"Configuring AAA Accounting Default
Configuring AAA
"Manually
OL-16597-01

Advertisement

Table of Contents
loading

Table of Contents