Cisco nexus 5000 series Cli Configuration Manual page 254

Hide thumbs Also See for nexus 5000 series:
Table of Contents

Advertisement

Configuring TACACS+
S e n d f e e d b a c k t o n x 5 0 0 0 - d o c f e e d b a c k @ c i s c o . c o m
Configuring TACACS+ Server Hosts
To access a remote TACACS+ server, you must configure the IPv4 or IPv6 address or the hostname for
the TACACS+ server on the Nexus 5000 Series switch. All TACACS+ server hosts are added to the
default TACACS+ server group.You can configure up to 64 TACACS+ servers.
If a preshared key is not configured for a configured TACACS+ server, a warning message is issued if a
global key is not configured. If a TACACS+ server key is not configured, the global key (if configured)
is used for that server (see the
"Configuring TACACS+ Server Preshared Keys" section on page
Before you configure TACACS+ server hosts, you should do the following:
To configure TACACS+ server hosts, perform this task:
Command
Step 1
switch# configure terminal
Step 2
switch(config)# tacacs-server host
{ipv4-address | ipv6-address|host-name}
Step 3
switch(config)# exit
Step 4
switch# show tacacs-server
Step 5
switch# copy running-config
startup-config
You can delete a TACACS+ server host from a server group.
Configuring Global Preshared Keys
You can configure preshared keys at the global level for all servers used by the Nexus 5000 Series switch.
A preshared key is a shared secret text string between the Nexus 5000 Series switch and the TACACS+
server hosts.
Before you configure preshared keys, you should do the following:
To configure global preshared keys, perform this task:
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
1-6
Enable TACACS+ (see the
Obtain the IPv4 or IPv6addresses or the hostnames for the remote TACACS+ servers.
Enable TACACS+ (see the
Obtain the preshared key values for the remote TACACS+ servers.
"Configuring Global Preshared Keys" section on page 1-6
"Enabling TACACS+" section on page
Purpose
Enters configuration mode.
Specifies the IPv4 or IPv6 address or hostname for a
TACACS+ server.
Exits configuration mode.
(Optional) Displays the TACACS+ server
configuration.
(Optional) Copies the running configuration to the
startup configuration.
"Enabling TACACS+" section on page
Chapter 1
Configuring TACACS+
and the
1-7).
1-5).
1-5).
OL-16597-01

Advertisement

Table of Contents
loading

Table of Contents