Aaa Server Distribution; Enabling Aaa Server Distribution - HP Cisco MDS 9020 - Fabric Switch Configuration Manual

Cisco mds 9000 family cli configuration guide, release 3.x (ol-16184-01, april 2008)
Hide thumbs Also See for Cisco MDS 9020 - Fabric Switch:
Table of Contents

Advertisement

AAA Server Distribution

S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
Command
Step 4
switch(config-tacacs+)# server ServerB
switch(config-tacacs+)# no server ServerB
Step 5
switch(config-tacacs+)# deadtime 30
switch(config-tacacs+)# no deadtime 30
AAA Server Distribution
Configuration for RADIUS and TACACS+ AAA on an MDS switch can be distributed using the Cisco
Fabric Services (CFS). The distribution is disabled by default (see
Infrastructure").
After enabling the distribution, the
server configuration commands entered thereafter are stored in a temporary database and applied to all
switches in the fabric (including the originating one) when you explicitly commit the database. The
various server and global parameters are distributed, except the server and global keys. These keys are
unique secrets to a switch and should not be shared with other switches.
Server group configurations are not distributed.
Note
For an MDS switch to participate in AAA server configuration distribution, it must be running Cisco
Note
MDS SAN-OS Release 2.0(1b) or later.

Enabling AAA Server Distribution

Only switches where distribution is enabled can participate in the distribution activity.
Cisco MDS 9000 Family CLI Configuration Guide
32-30
Purpose
Configures ServerB to be tried second within the
server group TacacsServer1.
Deletes ServerB within the TacacsServer1 list of
servers.
Configures the monitoring dead time to 30 minutes.
The range is 0 through 1440.
Note
If the dead-time interval for an individual
TACACS+ server is greater than 0, that value
takes precedence over the value set for the
server group.
Reverts to the default value (0 minutes).
If the dead-time interval for both the
Note
TACACS+ server group and an individual
TACACS+ server in the TACACS+ server
group is set to 0, the switch does not mark the
TACACS+ server as dead when it is found to
be unresponsive by periodic monitoring.
Also, the switch does not perform dead server
monitoring for that TACACS+ server. (See
the
"Configuring TACACS+ Server
Monitoring Parameters" section on
page
f
irst server or global configuration starts an implicit session. All
Chapter 32
Configuring RADIUS and TACACS+
32-21.)
Chapter 6, "Using the CFS
OL-16184-01, Cisco MDS SAN-OS Release 3.x

Advertisement

Table of Contents
loading

Table of Contents