TACACS+ Authentication
Overview
A3 or
B3
Primary
TACACS+
Server
The switch passes the login
requests from terminals A and B
to the TACACS+ server for
authentication. The TACACS+
server determines whether to
allow access to the switch and
what privilege level to allow for
a given access request.
Figure 2-1. Example of TACACS+ Operation
2-2
Overview
Feature
view the switch's authentication configuration
view the switch's TACACS+ server contact
configuration
configure the switch's authentication methods
configure the switch to contact TACACS+ server(s) disabled
TACACS+ authentication enables you to use a central server to allow or deny
access to the Switch 2650 and 6108 (and other TACACS-aware devices) in your
network. This means that you can use a central database to create multiple
unique username/password sets with associated privilege levels for use by
individuals who have reason to access the switch from either the switch's
console port (local access) or Telnet (remote access).
Switch 2650 or 6108
Configured for
A2 or
TACACS+ Operation
B2
B4
B1
Access Request
TACACS Server
Response
TACACS+ in the Switch 2650 and 6108 manages authentication of logon
attempts through either the Console port or Telnet. TACACS+ uses an authen-
tication hierarchy consisting of (1) remote passwords assigned in a TACACS+
Default
n/a
n/a
disabled
A4
A1
A
B
Terminal "B" Remotely Accessing The Switch Via Telnet
Menu
CLI
Web
—
page
2-10
—
page
2-10
—
page
2-11
—
page
2-15
Terminal "A" Directly
Accessing the Switch
Via Switch's Console
Port
A1 - A4 : Path for Request from
Terminal A (Through Console Port)
B1 - B4: Path for Request from
Terminal B (Through Telnet)
—
—
—
—