Aaa Server Groups; Aaa Service Configuration Options - Cisco Nexus 9000 Series Configuration Manual

Nx-os security configuration guide, release 9.x
Hide thumbs Also See for Nexus 9000 Series:
Table of Contents

Advertisement

Configuring AAA

AAA Server Groups

You can specify remote AAA servers for authentication, authorization, and accounting using server groups.
A server group is a set of remote AAA servers that implement the same AAA protocol. The purpose of a
server group is to provide for failover servers in case a remote AAA server fails to respond. If the first remote
server in the group fails to respond, the next remote server in the group is tried until one of the servers sends
a response. If all the AAA servers in the server group fail to respond, then that server group option is considered
a failure. If required, you can specify multiple server groups. If the Cisco NX-OS device encounters errors
from the servers in the first group, it tries the servers in the next server group.

AAA Service Configuration Options

The AAA configuration in Cisco NX-OS devices is service based, which means that you can have separate
AAA configurations for the following services:
• User Telnet or Secure Shell (SSH) login authentication
• Console login authentication
• User management session accounting
This table provides the related CLI command for each AAA service configuration option.
Table 2: AAA Service Configuration Commands
AAA Service Configuration Option
Telnet or SSH login
Console login
User session accounting
You can specify the following authentication methods for the AAA services:
All RADIUS servers
Specified server groups
Local
None
Note
If you specify the all RADIUS servers method, rather than a specified server group method, the Cisco NX-OS
device chooses the RADIUS server from the global pool of configured RADIUS servers, in the order of
configuration. Servers from this global pool are the servers that can be selectively configured in a RADIUS
server group on the Cisco NX-OS device.
Uses the global pool of RADIUS servers for authentication.
Uses specified RADIUS, TACACS+, or LDAP server groups you have configured for authentication.
Uses the local username or password database for authentication.
Specifies that no AAA authentication be used.
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
Related Command
aaa authentication login default
aaa authentication login console
aaa accounting default
AAA Server Groups
11

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents