A
S
NA-X | M
DMINISTERING
MART
• Server port: Specifies the communication port, usually 1812 for authentication servers.
• Shared secret: Specify the password/shared-secret required to access the authentication server. Passwords are
case-sensitive.
For TACACS+ servers, specify the following configuration option:
• Server address: Specify the network address of the authentication server.
To edit an existing server, click the
Click Add server to finish setting up the server.
6.
If your network has more than one authentication server running, you can add them as backup/failover servers
7.
and the system will attempt to contact the second server in order to validate a user (the system will not switch
between RADIUS and TACACS+ servers though if both are defined). Note that a RADIUS server will outright
reject a validation request when secrets mismatch and will not attempt to validate the secret on a second
RADIUS server. However, RADIUS will attempt to validate the user on a second server if the user account is
not present on the first server. TACACS+ servers behave differently, and will attempt to contact a backup server
if either the user account is not present or if secrets mismatch.
If necessary, use the
8.
being used.
Click Review/apply, review the changes you have made, and then click Apply to implement the new settings.
9.
Using the CLI to add authentication servers
Enable the authentication protocol used by the authentication server. The system supports RADIUS and
1.
TACACS+ authentication servers:
CONTROLLER>set authentication {radius | tacacs}
Add a master authentication server and any backups employed by your network.
2.
• To add a RADIUS server:
CONTROLLER>create radius authserver <ip-address> <port-num> <password>
• To add a TACACS+ server:
CONTROLLER>create tacacs authserver <ip-address> <password>
Exit to apply your updates:
3.
CONTROLLER>exit
See the
commands.
ANAGING USER ACCOUNTS AND AUTHENTICATION
button to move servers into the desired contact order when several backup servers are
Commands for managing authentication and accounting, page 100
S
NA™ 10G N
MART
button.
DRAFT
A
(S
ETWORK
CCESS
MART
for information on the authentication
NA-X)
28
Need help?
Do you have a question about the SmartNA-X and is the answer not in the manual?