data:image/s3,"s3://crabby-images/fab5e/fab5e9011d936d8c54bfcb45c51a04d39da380ba" alt="Cisco 4006 - Catalyst Switch Configuration Manual Download Page 463"
30-17
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2948G-GE-TX, and Catalyst 2980G Switches Software Configuration Guide—Release 8.2GLX
78-15908-01
Chapter 30 Configuring Switch Access Using AAA
Configuring Authentication
Enable Authentication: Console Session Telnet Session Http Session
---------------------- ----------------- ---------------- ----------------
tacacs disabled disabled disabled
radius disabled disabled disabled
kerberos disabled disabled disabled
local *
enabled(primary) enabled(primary) enabled(primary)
attempt limit 3 3 -
lockout timeout (sec) disabled disabled -
* Local User Authentication disabled.
Console> (enable)
Deleting a Local User Account
To delete a local user account on the switch, perform this task in privileged mode:
This example shows how to disable local user authentication for the switch and verify the configuration:
Console> (enable) clear localuser number1
Console> (enable) show localusers
Username Privilege Level
--------- -------------
picard
15
Console> (enable)
Configuring Authentication
The following sections describe how to configure authentication on the switch.
Specifying Servers
Specify one or more servers before you enable authentication on the switch. The
first server that you specify is the primary server, unless you explicitly make one server the primary
server by using the primary keyword.
To specify one or more servers, perform this task in privileged mode:
This example shows how to specify servers and verify the configuration:
Console> (enable) set tacacs server 172.20.52.3
172.20.52.3 added to TACACS server table as primary server.
Console> (enable) set tacacs server 172.20.52.2 primary
172.20.52.2 added to TACACS server table as primary server.
Task
Command
Step 1
Delete a local user account.
clear localuser picard
Step 2
Verify that the local user account has been deleted.
show localusers
Task
Command
Step 1
Specify the IP address of one or more servers. set tacacs server ip_addr [primary]
Step 2
Verify the configuration.
show tacacs