Cisco AP776A - Nexus Converged Network Switch 5020 Configuration Manual page 845

Cisco mds 9000 family cli configuration guide - release 4.x (ol-18084-01, february 2009)
Hide thumbs Also See for AP776A - Nexus Converged Network Switch 5020:
Table of Contents

Advertisement

Chapter 34
Configuring RADIUS and TACACS+
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
Command
Step 8
switch(config-radius)# server ServerB
Step 9
switch(config-radius)# deadtime 30
switch(config-radius)# no deadtime 30
To verify the configured server group order, use the show radius-server groups command:
switch# show radius-server groups
total number of groups:2
following RAIDUS server groups are configured:
To configure a TACACS+ server group, follow these steps:
Command
Step 1
switch# config t
Step 2
switch(config)# aaa group server tacacs+
TacacsServer1
switch(config-tacacs+)#
switch(config)# no aaa group server
tacacs+ TacacsServer1
Step 3
switch(config-tacacs+)# server ServerA
OL-18084-01, Cisco MDS NX-OS Release 4.x
group RadServer:
server 10.71.58.91 on port 2
group RadiusServer1:
server ServerA on port 49
server ServerB on port 49:
Purpose
Configures ServerB to be tried second within the
server group RadiusServer1.
Configures the monitoring dead time to 30 minutes.
The range is 0 through 1440.
If the dead-time interval for an individual
Note
RADIUS server is greater than 0, that value
takes precedence over the value set for the
server group.
Reverts to the default value (0 minutes).
If the dead-time interval for both the RADIUS
Note
server group and an individual TACACS+
server in the RADIUS server group is set to 0,
the switch does not mark the RADIUS server
as dead when it is found to be unresponsive by
periodic monitoring. Also, the switch does
not perform dead server monitoring for that
RADIUS server. (See the
RADIUS Server Monitoring Parameters"
section on page
34-12.)
Purpose
Enters configuration mode.
Creates a server group named TacacsServer1 and
enters the submode for that group.
Deletes the server group called TacacsServer1 from
the authentication list.
Configures ServerA to be tried first within the server
group called the TacacsServer1.
Tip
If the specified TACACS+ server is not found,
configure it using the tacacs-server host
command and retry this command.
Cisco MDS 9000 Family CLI Configuration Guide
Configuring Server Groups
"Configuring
34-29

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents