Cisco Catalyst 2960-X Security Configuration Manual page 64

Cisco ios release 15.0(2)ex
Hide thumbs Also See for Catalyst 2960-X:
Table of Contents

Advertisement

Prerequisites for TACACS+
6 Apply the list to the terminal lines.
7 Create an authorization and accounting method list.
The following are the prerequisites for controlling switch access with TACACS+:
• You must have access to a configured TACACS+ server to configure TACACS+ features on your switch.
Also, you must have access to TACACS+ services maintained in a database on a TACACS+ daemon
typically running on a LINUX or Windows workstation.
• We recommend a redundant connection between a switch stack and the TACACS+ server. This is to
help ensure that the TACACS+ server remains accessible in case one of the connected stack members
is removed from the switch stack.
• You need a system running the TACACS+ daemon software to use TACACS+ on your switch.
• To use TACACS+, it must be enabled.
• Authorization must be enabled on the switch to be used.
• Users must first successfully complete TACACS+ authentication before proceeding to TACACS+
authorization.
• To use any of the AAA commands listed in this section or elsewhere, you must first enable AAA with
the aaa new-model command.
• At a minimum, you must identify the host or hosts maintaining the TACACS+ daemon and define the
method lists for TACACS+ authentication. You can optionally define method lists for TACACS+
authorization and accounting.
• The method list defines the types of authentication to be performed and the sequence in which they are
performed; it must be applied to a specific port before any of the defined authentication methods are
performed. The only exception is the default method list (which, by coincidence, is named default). The
default method list is automatically applied to all ports except those that have a named method list
explicitly defined. A defined method list overrides the default method list.
• Use TACACS+ for privileged EXEC access authorization if authentication was performed by using
TACACS+.
• Use the local database if authentication was not performed by using TACACS+.
Related Topics
TACACS+ Overview, on page 41
TACACS+ Operation, on page 43
How to Configure TACACS+, on page 45
Method List, on page 44
Configuring TACACS+ Login Authentication, on page 47
TACACS+ Login Authentication, on page 44
Configuring TACACS+ Authorization for Privileged EXEC Access and Network Services, on page 50
TACACS+ Authorization for Privileged EXEC Access and Network Services, on page 44
Catalyst 2960-X Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX
40
Configuring TACACS+
OL-29048-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents