02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

To specify a TACACS+ server host and configure its communication parameters, use <strong>the</strong> following<br />

command in <strong>the</strong> CONFIGURATION mode:<br />

Command Syntax Command Mode Purpose<br />

tacacs-server host {hostname |<br />

ip-address} [port port-number]<br />

[timeout seconds] [key key]<br />

To specify multiple TACACS+ server hosts, configure <strong>the</strong> tacacs-server host command multiple times. If<br />

multiple TACACS+ server hosts are configured, <strong>FTOS</strong> attempts to connect with <strong>the</strong>m in <strong>the</strong> order in which<br />

<strong>the</strong>y were configured.<br />

To view <strong>the</strong> TACACS+ configuration, use <strong>the</strong> show running-config tacacs+ command in <strong>the</strong> EXEC<br />

privilege mode.<br />

To delete a TACACS+ server host, use <strong>the</strong> no tacacs-server host {hostname | ip-address} command.<br />

Command Authorization<br />

CONFIGURATION Enter <strong>the</strong> host name or IP address of <strong>the</strong> TACACS+<br />

server host. Configure <strong>the</strong> optional communication<br />

parameters <strong>for</strong> <strong>the</strong> specific host:<br />

• port port-number range: 0 to 65335. Enter a<br />

TCP port number. The default is 49.<br />

• timeout seconds range: 0 to 1000. Default is 10<br />

seconds.<br />

• key key: Enter a string <strong>for</strong> <strong>the</strong> key. The key can<br />

be up to 42 characters long. This key must<br />

match a key configured on <strong>the</strong> TACACS+ server<br />

host. This parameter should be <strong>the</strong> last<br />

parameter configured.<br />

If <strong>the</strong>se optional parameters are not configured, <strong>the</strong><br />

default global values are applied.<br />

freebsd2# telnet 2200:2200:2200:2200:2200::2202<br />

Trying 2200:2200:2200:2200:2200::2202...<br />

Connected to 2200:2200:2200:2200:2200::2202.<br />

Escape character is '^]'.<br />

Login: admin<br />

Password:<br />

<strong>Force10</strong>#<br />

<strong>Force10</strong>#<br />

!-The prompt is returned as <strong>the</strong> connection is au<strong>the</strong>nticated.<br />

The AAA command authorization feature configures <strong>FTOS</strong> to send each configuration command to a<br />

TACACS server <strong>for</strong> authorization be<strong>for</strong>e it is added to <strong>the</strong> running configuration.<br />

By default, <strong>the</strong> AAA authorization commands configure <strong>the</strong> system to check both EXEC mode and<br />

CONFIGURATION mode commands. Use <strong>the</strong> command no aaa authorization config-commands to<br />

enable only EXEC mode command checking.<br />

154 Security

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!