Dell Force10 MXL Blade Configuration Manual page 494

Configuration guide for the mxl 10/40gbe switch io module
Hide thumbs Also See for Force10 MXL Blade:
Table of Contents

Advertisement

Figure 28-7
access-class on the VTY line to be ignored. If you have configured a
FTOS downloads it and applies it. If the user is found to be coming from the 10.0.0.0 subnet, FTOS also
immediately closes the Telnet connection. Note that no matter where the user is coming from, they see the
login prompt.
Figure 28-7. Specify a TACACS+ Server Host
FTOS#
FTOS(conf)#
FTOS(conf)#ip access-list standard deny10
FTOS(conf-std-nacl)#permit 10.0.0.0/8
FTOS(conf-std-nacl)#deny any
FTOS(conf)#
FTOS(conf)#aaa authentication login tacacsmethod tacacs+
FTOS(conf)#aaa authentication exec tacacsauthorization tacacs+
FTOS(conf)#tacacs-server host 25.1.1.2 key FTOS
FTOS(conf)#
FTOS(conf)#line vty 0 9
FTOS(conf-line-vty)#login authentication tacacsmethod
FTOS(conf-line-vty)#authorization exec tacauthor
FTOS(conf-line-vty)#
FTOS(conf-line-vty)#access-class deny10
FTOS(conf-line-vty)#end
When configuring a TACACS+ server host, you can set different communication parameters, such as the
key password.
To specify a TACACS+ server host and configure its communication parameters, use the following
command in CONFIGURATION mode:
Command Syntax
tacacs-server host {hostname
ip-address} [port port-number] [timeout
seconds] [key key]
To specify multiple TACACS+ server hosts, configure the
you configure multiple TACACS+ server hosts, FTOS attempts to connect with them in the order in which
they were configured.
To view the TACACS+ configuration, use the
mode.
492
|
Security
shows how to configure
access-class
Command Mode
|
CONFIGURATION
from a TACACS+ server. This causes the configured
deny10
Purpose
Enter the host name or IP address of the TACACS+
server host. Configure the optional communication
parameters for the specific host:
port port-number
number. The default is 49.
timeout seconds
seconds.
key key:
Enter a string for the key. The key can be up
to 42 characters long. This key must match a key
configured on the TACACS+ server host. This
parameter should be the last parameter configured.
If these optional parameters are not configured, the
default global values are applied.
tacacs-server host
show running-config tacacs+
ACL on the TACACS+ server,
range: 0 to 65335. Enter a TCP port
range: 0 to 1000. Default is 10
command multiple times. If
command in EXEC Privilege

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents