Page
27
Select 6,
TACACS
Encryption
Enable
sets the
encryption to off or on. Sending
unencrypted TACACS packets is useful for
troubleshooting but should not be used under
normal operations.
TACACS Server IP Address is: 0.0.0.0
Enter TACACS server address in dotted decimal form :
TACACS Backup IP Address is: 0.0.0.0
Enter TACACS server address in dotted decimal form :
DS62 usernames as backup login is Disabled
Enable ? (Y/N), CR for no change) :
TACACS encryption is..............Enabled
Enable ? (Y/N), CR for no change) :
TACACS response timeout is 10 seconds
Enter timeout, in seconds ( >=0 and <=30 )
0 = no timeout :
TACACS server port is: 49
Enter port number (>= 1024, D for default 49): 12
TACACS Privilege Level is.........Disabled
Enable ? (Y/N), CR for no change) :
Select 1,
TACACS
Enable
sends the login information to the TACACS server for authentication. If
enabled, the primary TACACS server
address’ must be specified.
Select 2,
TACACS
Server
Address
assigns
a specific TACACS server IP addresses.
Select 3,
TACACS
Backup
Server
Address
assigns a specific Backup
Server IP addresses.
Select 4,
TACACS
Secret
assigns a secret word shared
between the TACACS server and this unit. A secret
can be up to 16 characters and must be exactly the same
as the secret stored on the server.
Select 5
,
EnableDS62
usernames
as
backup
allows an unsecured access in case all
specified radius servers are unavailable.
Select 7,
TACACS
Login
Timeout
sets the amount of time the unit will
wait for a response from the TACACS
server.
Select 8,
TACACS
Server
Port
assigns a
more secure port,
default is TCP 49
. If
you type a port number less than 1024 the
Host Module responds with the same
screen until a valid entry is typed.
Select 9
,
DS62
Privilege
Level
Enable
enables the unit to send a
privilege level to the TACACS server.
Default is Disabled
TACACS User Privilege Feature
Important:
The TACACS admin user must perform the following before the TACACS Privilege level to
operate: Open the tacacs.conf file and add the following entry for each user: (service = exec {priv-lvl =
n}). Where “n” is a number from 1 to 15, inclusive. 15 is root privilege level, 1 is lowest level user.
“priv-lvl” must be spelled exactly as shown, including case. Restart the daemon after making changes.
TACACS login is...................Disabled
Enable ? (Y/N), CR for no change) :
TACACS secret is: HardlyASecret
Enter TACACS secret (16 chars max).
: