Installation and Getting Started Guide
HP9300(config)# aaa accounting system default start-stop tacacs+
Syntax: aaa accounting system default start-stop radius | tacacs+ | none
Configuring an Interface as the Source for All TACACS/TACACS+ Packets
You can designate the lowest-numbered IP address configured an Ethernet port, loopback interface, or virtual
interface as the source IP address for all TACACS/TACACS+ packets from the routing switch. Identifying a single
source IP address for TACACS/TACACS+ packets provides the following benefits:
If your TACACS/TACACS+ server is configured to accept packets only from specific links or IP addresses,
you can use this feature to simplify configuration of the TACACS/TACACS+ server by configuring the HP
device to always send the TACACS/TACACS+ packets from the same link or source address.
If you specify a loopback interface as the single source for TACACS/TACACS+ packets, TACACS/TACACS+
servers can receive the packets regardless of the states of individual links. Thus, if a link to the TACACS/
TACACS+ server becomes unavailable but the client or server can be reached through another link, the client
or server still receives the packets, and the packets still have the source IP address of the loopback interface.
The software contains separate CLI commands for specifying the source interface for Telnet, TACACS/TACACS+,
and RADIUS packets. You can configure a source interface for one or more of these types of packets.
To specify an Ethernet port or a loopback or virtual interface as the source for all TACACS/TACACS+ packets from
the device, use the following CLI method. The software uses the lowest-numbered IP address configured on the
port or interface as the source IP address for TACACS/TACACS+ packets originated by the device.
To specify the lowest-numbered IP address configured on a virtual interface as the device's source for all
TACACS/TACACS+ packets, enter commands such as the following:
HP9300(config)# int ve 1
HP9300(config-vif-1)# ip address 10.0.0.3/24
HP9300(config)# ip tacacs source-interface ve 1
The commands in this example configure virtual interface 1, assign IP address 10.0.0.3/24 to the interface, then
designate the interface as the source for all TACACS/TACACS+ packets from the routing switch.
Syntax: ip tacacs source-interface ethernet <portnum> | loopback <num> | ve <num>
The <num> parameter is a loopback interface or virtual interface number. If you specify an Ethernet port, the
<portnum> is the port's number (including the slot number, if you are configuring a chassis device).
Displaying TACACS/TACACS+ Statistics and Configuration Information
The show aaa command displays information about all TACACS+ and RADIUS servers identified on the device.
HP9300# show aaa
Tacacs+ key: whistle
Tacacs+ retries: 1
Tacacs+ timeout: 15 seconds
Tacacs+ dead-time: 3 minutes
Tacacs+ Server: 220.127.116.11 Port:49:
Radius key: networks
Radius retries: 3
Radius timeout: 3 seconds
Radius dead-time: 3 minutes
3 - 26
opens=6 closes=3 timeouts=3 errors=0
packets in=4 packets out=4
18.104.22.168 Auth Port=1645 Acct Port=1646:
opens=2 closes=1 timeouts=1 errors=0
packets in=1 packets out=4