Administering the WMIC
Controlling WMIC Access with
35
Cisco 3200 Series Wireless MIC Software Configuration Guide
To remove the specified server name or address, use the
no tacacs-server host
hostname
command in global configuration mode. To remove a server group from the configuration list, use the
no aaa group server
group-name
command in global configuration mode. To remove the IP
address of a server, use the
no server ip-address
server group subconfiguration command.
Configuring Login Authentication
To configure AAA authentication, define a named list of authentication methods, and then apply that list
to various interfaces. The method list defines the types of authentication to be performed and the
sequence in which they are performed; the method must be applied to a specific interface before any of
the defined authentication methods can be performed. The only exception is the default method list
(which is named
default
). The default method list is automatically applied to all interfaces except those
for which a named method list is explicitly defined. A defined method list overrides the default method
list.
A method list describes the sequence and authentication methods to be queried to authenticate an
administrator. You can designate one or more security protocols to be used for authentication, to ensure
a backup system for authentication if the initial method fails. The software uses the first method listed
to authenticate users; if that method fails to respond, the software selects the next authentication method
in the method list. This process continues until there is successful communication with a listed
authentication method or until all defined methods are exhausted. If authentication fails at any point in
this cycle—that is, if the security server or local username database responds by denying the
administrator access—the authentication process stops, and no further authentication methods are
attempted.
To configure login authentication
, follow these required steps, beginning in privileged EXEC mode:
Step 5
server
ip-address
(Optional) Associate a particular server with the defined server
group. Repeat this step for each server in the AAA server
group.
Each server in the group must be previously defined in Step 2.
Step 6
end
Returns to privileged EXEC mode.
Step 7
show tacacs
Verifies your entries.
Step 8
copy running-config startup-config
(Optional) Saves your entries in the configuration file.
Command
Purpose
Command
Purpose
Step 1
configure terminal
Enters global configuration mode.
Step 2
aaa new-model
Enables AAA.