Specifying Different Servers For Individual Aaa Functions - Dell PowerConnect B-FCXs Configuration Manual

Powerconnect b-series fcx
Hide thumbs Also See for PowerConnect B-FCXs:
Table of Contents

Advertisement

Syntax: tacacs-server host <ip-addr> | <ipv6-addr> | <hostname> [auth-port <number>]
The <ip-addr>|<ipv6-addr>|<hostname> parameter specifies the IP address or host name of the
server. You can enter up to eight tacacs-server host commands to specify up to eight different
servers.
NOTE
To specify the server's host name instead of its IP address, you must first identify a DNS server using
the ip dns server-address <ip-addr> command at the global CONFIG level.
If you add multiple TACACS/TACACS+ authentication servers to the Dell PowerConnect device, the
device tries to reach them in the order you add them. For example, if you add three servers in the
following order, the software tries the servers in the same order.
1. 207.94.6.161
2. 207.94.6.191
3. 207.94.6.122
You can remove a TACACS/TACACS+ server by entering no followed by the tacacs-server command.
For example, to remove 207.94.6.161, enter the following command.
PowerConnect(config)#no tacacs-server host 207.94.6.161
NOTE
If you erase a tacacs-server command (by entering "no" followed by the command), make sure you
also erase the aaa commands that specify TACACS/TACACS+ as an authentication method. (Refer
to
"Configuring authentication-method lists for TACACS/TACACS+"
you exit from the CONFIG mode or from a Telnet session, the system continues to believe it is
TACACS/TACACS+ enabled and you will not be able to access the system.
The auth-port parameter specifies the UDP (for TACACS) or TCP (for TACACS+) port number of the
authentication port on the server. The default port number is 49.

Specifying different servers for individual AAA functions

In a TACACS+ configuration, you can designate a server to handle a specific AAA task. For example,
you can designate one TACACS+ server to handle authorization and another TACACS+ server to
handle accounting. You can set the TACACS+ key for each server.
To specify different TACACS+ servers for authentication, authorization, and accounting, enter the
command such as following.
PowerConnect(config)#tacacs-server host 1.2.3.4 auth-port 49 authentication-only
key abc
PowerConnect(config)#tacacs-server host 1.2.3.5 auth-port 49 authorization-only
key def
PowerConnect(config)#tacacs-server host 1.2.3.6 auth-port 49 accounting-only key
ghi
Syntax:
The default parameter causes the server to be used for all AAA functions.
PowerConnect B-Series FCX Configuration Guide
53-1002266-01
tacacs-server host <ip-addr> | <ipv6-addr> | <server-name> [auth-port <num>]
[authentication-only | authorization-only | accounting-only | default] [key 0 | 1 <string>]
Configuring TACACS/TACACS+ security
on page 1173.) Otherwise, when
32
1171

Advertisement

Table of Contents
loading

Table of Contents