About The Default Tacacs+ Server Encryption Type And Preshared Key; Enabling Tacacs+; Setting The Tacacs+ Server Address - HP Cisco MDS 9020 - Fabric Switch Configuration Manual

Cisco mds 9000 family cli configuration guide, release 3.x (ol-16184-01, april 2008)
Hide thumbs Also See for Cisco MDS 9020 - Fabric Switch:
Table of Contents

Advertisement

Configuring TACACS+
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m

About the Default TACACS+ Server Encryption Type and Preshared Key

You need to configure the TACACS+ preshared key to authenticate the switch to the TACACS+ server.
The length of the key is restricted to 64 characters and can include any printable ASCII characters (white
spaces are not allowed). You can configure a global key to be used for all TACACS+ server
configurations on the switch.
You can override this global key assignment by explicitly using the key option when configuring and
individual TACACS+ server.

Enabling TACACS+

By default, the TACACS+ feature is disabled in all switches in the Cisco MDS 9000 Family. You must
explicitly enable the TACACS+ feature to access the configuration and verification commands for fabric
authentication. When you disable this feature, all related configurations are automatically discarded.
To enable TACACS+ for a Cisco MDS switch, follow these steps:
Command
Step 1
switch# config t
Step 2
switch(config)# tacacs+ enable
switch(config)# no tacacs+ enable

Setting the TACACS+ Server Address

If a secret key is not configured for a configured server, a warning message is issued if a global key is
not configured. If a server key is not configured, the global key (if configured) is used for that server (see
the
You can use the dollar sign ($) and the percent sign (%) in global secret keys.
Note
To configure the TACACS+ server IPv4 address and other options, follow these steps:
Command
Step 1
switch# config t
Step 2
switch(config)# tacacs-server host
171.71.58.91
switch(config)# no tacacs-server host
171.71.58.91
Cisco MDS 9000 Family CLI Configuration Guide
32-18
Allowing the user to specify a TACACS+ server at login
"Setting the Timeout Value" section on page
Chapter 32
Purpose
Enters configuration mode.
Enables the TACACS+ in this switch.
Disables (default) the TACACS+ in this switch.
32-20).
Purpose
Enters configuration mode.
Configures the TACACS+ server identified by the
specified IPv4 address.
Deletes the specified TACACS+ server identified by the
IPv4 address. By default, no server is configured.
OL-16184-01, Cisco MDS SAN-OS Release 3.x
Configuring RADIUS and TACACS+

Advertisement

Table of Contents
loading

Table of Contents