Staros User Account Requirements; Configuring Tacacs+ Aaa Services - Cisco ASR 5000 Administration Manual

Staros release 21.1
Hide thumbs Also See for ASR 5000:
Table of Contents

Advertisement

Configuring TACACS+ AAA Services

Important
To display the default mapping of TACACS+ privilege levels to CLI administrative roles, run the Exec mode
show tacacs priv-lvl command. The default mapping varies based on the StarOS release and build type.
TACACS+ priv-levels can be reconfigured from their default StarOS authorization values via the TACACS+
Configuration mode priv-lvl and user-id commands. For additional information, see the TACACS+
Configuration Mode Commands chapter of the Command Line Interface Reference.
Important

StarOS User Account Requirements

TACACS+ users who are allowed administrative access to the system must have the following user account
information defined in StarOS:
• username
• password
• administrative role and privileges
Important
Configuring TACACS+ AAA Services
This section provides an example of how to configure TACACS+ AAA services for administrative users on
the system.
When configuring TACACS+ AAA services for the first time, the administrative user must use
Caution
non-TACACS+ services to log into the ASR 5x00. Failure to do so will result in the TACACS+ user being
denied access to the system.
Log in to the system using non-TACACS+ services.
Use the example below to configure TACACS+ AAA services on the system:
configure
tacacs mode
server priority priority_number ip-address tacacs+srvr_ip_address
end
ASR 5000 System Administration Guide, StarOS Release 21.1
56
TACACS+ privilege levels are stored as Attribute Value Pairs (AVPs) in the network's TACACS+ server
database. Users are restricted to the set of commands associated with their privilege level. A mapping of
TACACS+ privilege levels to ASR 5x00 CLI administrative roles and responsibilities is provided in the
table below.
In release 20.0 and higher Trusted StarOS builds, FTP is not supported.
For instructions on defining users and administrative privileges on the system, refer to Configuring System
Administrative Users.
System Settings

Advertisement

Table of Contents
loading

Table of Contents