Merge Guidelines For Radius And Tacacs+ Configurations - Cisco AP776A - Nexus Converged Network Switch 5020 Configuration Manual

Cisco mds 9000 family cli configuration guide - release 4.x (ol-18084-01, february 2009)
Hide thumbs Also See for AP776A - Nexus Converged Network Switch 5020:
Table of Contents

Advertisement

Chapter 34
Configuring RADIUS and TACACS+
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
To discard the RADIUS sessionin-progress distribution, follow these steps:
Command
Step 1
switch# config t
Step 2
switch(config)# radius abort
To discard the TACACS+ sessionin-progress distribution, follow these steps:
Command
Step 1
switch# config t
Step 2
switch(config)# tacacs+ abort
To clear the ongoing CFS distribution session (if any) and to unlock the fabric for the RADIUS feature,
enter the clear radius session command from any switch in the fabric.
switch# clear radius session
To clear the ongoing CFS distribution session (if any) and to unlock the fabric for the TACACS+ feature,
enter the clear tacacs+ session command from any switch in the fabric.
switch# clear tacacs+ session

Merge Guidelines for RADIUS and TACACS+ Configurations

.
The RADIUS and TACACS+ server and global configuration are merged when two fabrics merge. The
merged configuration is applied to CFS distribution-enabled switches.
When merging the fabric, be aware of the following conditions:
If there is a conflict between two switches in the server ports configured, the merge fails.
Caution
Use the show radius distribution status command to view the status of the RADIUS fabric merge as
shown in
Example 34-11 Displays the RADIUS Fabric Merge Status
switch# show radius distribution status
distribution : enabled
session ongoing: no
session db: does not exist
merge protocol status: merge response received
merge error: conflict: server dmtest2 has auth-port 1812 on this switch and 1999
on remote
OL-18084-01, Cisco MDS NX-OS Release 4.x
The server groups are not merged.
The server and global keys are not changed during the merge.
The merged configuration contains all servers found on all CFS enabled switches.
The timeout and retransmit parameters of the merged configuration are the largest values found per
server and global configuration.
Example
34-11.
Purpose
Enters configuration mode.
Discards the RADIUS configuration changes to the running
configuration.
Purpose
Enters configuration mode.
Discards the TACACS+ configuration changes to the running
configuration.
Cisco MDS 9000 Family CLI Configuration Guide
AAA Server Distribution
34-33

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents