Extreme Networks Summit Summit24 Installation And User Manual page 61

Extreme summit summit24: user guide
Hide thumbs Also See for Summit Summit24:
Table of Contents

Advertisement

attempting to administer the switch. TACACS+ is used to communicate between the switch and an
authentication database.
NOTE
You cannot use RADIUS and TACACS+ at the same time.
You can configure two TACACS+ servers, specifying the primary server address, secondary server
address, and UDP port number to be used for TACACS+ sessions.
Table 16 describes the commands that are used to configure TACACS+.
Table 16: TACACS+ Commands
Command
config tacacs [primary | secondary] server
[<ipaddress> | <hostname>] {<udp_port>} client-ip
<ipaddress>
config tacacs [primary | secondary] shared-secret
{encrypted} <string>
config tacacs-accounting [primary | secondary]
server [<ipaddress> | <hostname>] {<udp_port>}
client-ip <ipaddress>
config tacacs-accounting [primary | secondary]
shared-secret {encrypted} <string>
disable tacacs
disable tacacs-accounting
disable tacacs-authorization
enable tacacs
enable tacacs-accounting
enable tacacs-authorization
Summit24e3 Switch Installation and User Guide
Description
Configure the server information for a
TACACS+ server. Specify the following:
primary | secondary — Specifies
primary or secondary server
configuration. To remove a server, use
the address 0.0.0.0.
<ipaddress> | <hostname> —
Specifies the TACACS+ server.
• <udp_port> — Optionally specifies
the UDP port to be used.
• client-ip — Specifies the IP
address used by the switch to identify
itself when communicating with the
TACACS+ server.
Configures the shared secret string used
to communicate with the TACACS+ server.
Configures the TACACS+ accounting
server. You can use the same server for
accounting and authentication.
Configures the shared secret string used
to communicate with the TACACS+
accounting server.
Disables TACACS+.
Disables TACACS+ accounting.
Disables CLI command authorization.
Enables TACACS+. Once enabled, all CLI
logins are sent to one of the two
TACACS+ server for login name
authentication and accounting.
Enables TACACS+ accounting. If
accounting is use, the TACACS+ client
must also be enabled.
Enables CLI command authorization.
When enabled, each command is
transmitted to the remote TACACS+
server for authorization before the
command is executed.
Authenticating Users
61

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Summit24e3

Table of Contents