02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

TACACS+ Remote Au<strong>the</strong>ntication and Authorization<br />

<strong>FTOS</strong> takes <strong>the</strong> access class from <strong>the</strong> TACACS+ server. Access class is <strong>the</strong> class of service that restricts<br />

Telnet access and packet sizes. If you have configured remote authorization, <strong>the</strong>n <strong>FTOS</strong> ignores <strong>the</strong> access<br />

class you have configured <strong>for</strong> <strong>the</strong> VTY line. <strong>FTOS</strong> instead gets this access class in<strong>for</strong>mation from <strong>the</strong><br />

TACACS+ server. <strong>FTOS</strong> needs to know <strong>the</strong> username and password of <strong>the</strong> incoming user be<strong>for</strong>e it can<br />

fetch <strong>the</strong> access class from <strong>the</strong> server. A user, <strong>the</strong>re<strong>for</strong>e, will at least see <strong>the</strong> login prompt. If <strong>the</strong> access<br />

class denies <strong>the</strong> connection, <strong>FTOS</strong> closes <strong>the</strong> Telnet session immediately.<br />

Figure 69 demonstrates how to configure <strong>the</strong> access-class from a TACACS+ server. This causes <strong>the</strong><br />

configured access-class on <strong>the</strong> VTY line to be ignored. If you have configured a deny10 ACL on <strong>the</strong><br />

TACACS+ server, <strong>FTOS</strong> downloads it and applies it. If <strong>the</strong> user is found to be coming from <strong>the</strong> 10.0.0.0<br />

subnet, <strong>FTOS</strong> also immediately closes <strong>the</strong> Telnet connection. Note, that no matter where <strong>the</strong> user is coming<br />

from, <strong>the</strong>y see <strong>the</strong> login prompt.<br />

Figure 69 Specifying a TACACS+ server host<br />

<strong>Force10</strong>#<br />

<strong>Force10</strong>(conf)#<br />

<strong>Force10</strong>(conf)#ip access-list standard deny10<br />

<strong>Force10</strong>(conf-ext-nacl)#permit 10.0.0.0/8<br />

<strong>Force10</strong>(conf-ext-nacl)#deny any<br />

<strong>Force10</strong>(conf)#<br />

<strong>Force10</strong>(conf)#aaa au<strong>the</strong>ntication login tacacsmethod tacacs+<br />

<strong>Force10</strong>(conf)#aaa au<strong>the</strong>ntication exec tacacsauthorization tacacs+<br />

<strong>Force10</strong>(conf)#tacacs-server host 25.1.1.2 key <strong>for</strong>ce10<br />

<strong>Force10</strong>(conf)#<br />

<strong>Force10</strong>(conf)#line vty 0 9<br />

<strong>Force10</strong>(config-line-vty)#login au<strong>the</strong>ntication tacacsmethod<br />

<strong>Force10</strong>(config-line-vty)#authorization exec tacauthor<br />

<strong>Force10</strong>(config-line-vty)#<br />

<strong>Force10</strong>(config-line-vty)#access-class deny10<br />

<strong>Force10</strong>(config-line-vty)#end<br />

When configuring a TACACS+ server host, you can set different communication parameters, such as <strong>the</strong><br />

<strong>the</strong> key password.<br />

<strong>FTOS</strong> <strong>Configuration</strong> <strong>Guide</strong>, version 7.7.1.0 153

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!