Verifying Tacacs+ Configuration Using Fabric Manager; Verifying Tacacs+ Configuration Using The Cli - Cisco 9134 - MDS Multilayer Fabric Switch Troubleshooting Manual

Mds 9000 family
Hide thumbs Also See for 9134 - MDS Multilayer Fabric Switch:
Table of Contents

Advertisement

Chapter 17
Troubleshooting RADIUS and TACACS+
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m

Verifying TACACS+ Configuration Using Fabric Manager

To verify or change the TACACS+ configuration using Fabric Manager, follow these steps:
Step 1
Choose Switches > Security > AAA > TACACS+ and select the Servers tab. You see the TACACS+
configuration in the Information panel.
Step 2
Highlight the server that you need to change and click Delete Row to delete this server configuration.
Step 3
Click Create Row to add a new TACACS+ server.
Set the KeyType and Key fields to the preshared key configured on the TACACS+ server.
Step 4
Set the AuthPort and AcctPort fields to the authentication and accounting ports configured on the
Step 5
TACACS+ server.
Set the TimeOut value and click Apply to save these changes.
Step 6
Select the CFS tab and select commit from the Config Action drop-down menu and click Apply
Step 7
Changes to distribute these changes to all switches in the fabric.

Verifying TACACS+ Configuration Using the CLI

To verify or change the TACACS+ configuration using the CLI, follow these steps:
Use the show tacacs-server command to display configured TACACS+ parameters.
Step 1
switch# show tacacs-server
Global TACACS+ shared secret:***********
timeout value:30
total number of servers:3
following TACACS+ servers are configured:
Step 2
Use the tacacs-server host ip-address key command to set the preshared key to match what is
configured on your TACACS+ server.
Use the tacacs-server host ip-address port command to set the communications port to match what is
Step 3
configured on your TACACS+ server.
Use the tacacs-server timeout command to set the period in seconds for the switch to wait for a response
Step 4
from all TACACS+ servers before the switch declares a timeout failure.
Use the tacacs commit command to commit any changes and distribute to all switches in the fabric.
Step 5
OL-9285-05
11.5.4.3:
available on port:2
cisco.com:
available on port:49
11.6.5.4:
available on port:49
TACACS+ shared secret:*****
Cisco MDS 9000 Family Troubleshooting Guide, Release 3.x
AAA Issues
17-5

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents