618
C
HAPTER
33: HWTACACS C
ONFIGURATION
Configuring Source
Address for HWTACACS
Packets Sent by NAS
Perform the following configuration in the corresponding view.
The HWTACACS view takes precedence over the system view when configuring the
source address for HWTACACS packets sent from the NAS.
By default, the source address is not specified, and the interface address for packet
sending is used as the source address.
Setting a Key for
Securing the
Communication with
TACACS Server
When using a TACACS server as an AAA server, you can set a key to improve the
communication security between the switch and the TACACS server.
Perform the following configuration in HWTACACS view.
No key is configured by default.
Setting the Username
Format Acceptable to
the TACACS Server
Username is usually in the “userid@isp-name” format, with the domain name
following “@”.
If a TACACS server does not accept the username with domain name, you can
remove the domain name and resend it to the TACACS server.
Perform the following configuration in HWTACACS view.
By default, each username sent to a TACACS server contains a domain name.
Table 676
Configuring source address for HWTACACS packets sent by the NAS
Operation
Command
Configure the source address for HWTACACS packets sent
from the NAS (HWTACACS view).
nas-ip
ip-address
Delete the configured source address for HWTACACS
packets sent from the NAS (HWTACACS view).
undo nas-ip
Configure the source address for HWTACACS packets sent
from the NAS (System view).
hwtacacs nas-ip
ip-address
Cancel the configured source address for HWTACACS
packets sent from the NAS (System view).
undo hwtacacs nas-ip
Table 677
Setting a key for securing the communication with the HWTACACS server
Operation
Command
Configure a key for securing the communication
with the accounting, authorization or
authentication server
key
{
accounting
|
authorization
|
authentication
}
string
Delete the configuration
undo key
{
accounting
|
authorization
|
authentication
}
Table 678
Setting the username format acceptable to the TACACS server
Operation
Command
Send username with domain name.
user-name-format
with-domain
Send username without domain name.
user-name-format
without-domain
Summary of Contents for 5500 SI - Switch - Stackable
Page 24: ...24 ABOUT THIS GUIDE...
Page 50: ...50 CHAPTER 1 GETTING STARTED...
Page 54: ...54 CHAPTER 2 ADDRESS MANAGEMENT CONFIGURATION...
Page 78: ...78 CHAPTER 3 PORT OPERATION...
Page 88: ...88 CHAPTER 4 XRN CONFIGURATION...
Page 122: ...122 CHAPTER 8 VLAN VPN CONFIGURATION...
Page 216: ...216 CHAPTER 15 SSH TERMINAL SERVICES...
Page 268: ...268 CHAPTER 16 IP ROUTING PROTOCOL OPERATION...
Page 308: ...308 CHAPTER 17 NETWORK PROTOCOL OPERATION...
Page 349: ...349...
Page 350: ...350 CHAPTER 18 MULTICAST PROTOCOL...
Page 522: ...522 CHAPTER 22 FILE SYSTEM MANAGEMENT...
Page 584: ...584 CHAPTER 30 PASSWORD CONTROL CONFIGURATION OPERATIONS...
Page 600: ...600 CHAPTER 31 MSDP CONFIGURATION...
Page 614: ...614 CHAPTER 32 CLUSTERING...
Page 670: ...670 CHAPTER C AUTHENTICATING THE SWITCH 5500 WITH CISCO SECURE ACS...