19.10.2013 Views

7.6.1.0 - Force10 Networks

7.6.1.0 - Force10 Networks

7.6.1.0 - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

To delete a TACACS+ server host, use the no tacacs-server host {hostname | ip-address} command.<br />

freebsd2# telnet 2200:2200:2200:2200:2200::2202<br />

Trying 2200:2200:2200:2200:2200::2202...<br />

Connected to 2200:2200:2200:2200:2200::2202.<br />

Escape character is '^]'.<br />

Login: admin<br />

Password:<br />

<strong>Force10</strong>#<br />

<strong>Force10</strong>#<br />

!-The prompt is returned as the connection is authenticated.<br />

Command Authorization<br />

The AAA command authorization feature configures FTOS to send each configuration command to a<br />

TACACS server for authorization before it is added to the running configuration.<br />

By default, the command AAA authorization commands configures the system to check both EXEC level<br />

and CONFIGURATION level commands. Use the command no aaa authorization config-commands to<br />

enable only EXEC-level command checking.<br />

If rejected by the AAA server, the command is not added ot the running configuration, and messages<br />

similar to Message 4 are displayed.<br />

Message 4 Configuration Command Rejection<br />

04:07:48: %RPM0-P:CP %SEC-3-SEC_AUTHORIZATION_FAIL: Authorization failure Command<br />

authorization failed for user (denyall) on vty0 ( 10.11.9.209 )<br />

VTY Line and Access-Class Configuration<br />

The <strong>Force10</strong> Operating System provides several ways to configure access classes for VTY lines,<br />

including:<br />

• VTY Line Local Authentication and Authorization on page 124<br />

• VTY Line Remote Authentication and Authorization on page 125<br />

VTY Line Local Authentication and Authorization<br />

FTOS retrieves the access class from the local database. To use this feature:<br />

1. Create a username<br />

2. Enter a password<br />

3. Assign an access class<br />

4. Enter a privilege level<br />

124 Security

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!