515
Commands
C
OMMANDS
provides access control for networked devices via one or more centralized servers. Similar to RADIUS, this
protocol simplifies authentication by making use of a single database that can be shared by many clients on a large network.
is based on the TACACS protocol (described in RFC1492) but additionally provides for separate authentication,
authorization, and accounting services. The original protocol was UDP based with messages passed in clear text over the
network; uses TCP to ensure reliable delivery and a shared key configured on the client and daemon server to
encrypt all messages.
tacacs-server host
Use the
tacacs-server host
command in Global Configuration mode to configure a server. This command
enters into the configuration mode. The
<ip-address|hostname>
parameter is the IP address or hostname of
the server. To specify multiple hosts, multiple
tacacs-server host
commands can be used.
no tacacs-server host
Use the
no tacacs-server host
command to delete the specified hostname or IP address. The
<ip-
address|hostname>
parameter is the IP address of the server.
tacacs-server key
Use the
tacacs-server key
command to set the authentication and encryption key for all communications
between the switch and the daemon. The
<key-string>
parameter has a range of 0 - 128 characters and
specifies the authentication and encryption key for all TACACS communications between the switch and the
server. This key must match the key used on the daemon.
Text-based configuration supports TACACS server’s secrets in encrypted and non-encrypted format. When you save the
configuration, these secret keys are stored in encrypted format only. If you want to enter the key in encrypted format, enter
the key along with the encrypted keyword. In the show running config command’s display, these secret keys are displayed
in encrypted format. You cannot show these keys in plain text format.
no tacacs-server key
Use the
no tacacs-server key
command to disable the authentication and encryption key for all
communications between the switch and the daemon. The
<key-string>
parameter has a range of 0 - 128
characters This key must match the key used on the daemon.
Format
tacacs-server host
<ip-address|hostname>
Mode
Global Config
Format
no tacacs-server host
<ip-address|hostname>
Mode
Global Config
Format
tacacs-server key
[
<key-string> | encrypted <key-string>]
Mode
Global Config
Format
no tacacs-server key
<key-string>
Mode
Global Config
Summary of Contents for DWS-4000 Series
Page 20: ...D Link Unified Switch CLI Command Reference 12 2009 D Link Corporation All Rights Reserved ...
Page 170: ...D Link Unified Switch CLI Command Reference 162 2009 D Link Corporation All Rights Reserved ...
Page 369: ...361 Captive Portal Status Commands Locale Link The names of the languages Field Description ...
Page 416: ...D Link Unified Switch CLI Command Reference 408 2009 D Link Corporation All Rights Reserved ...
Page 528: ...D Link Unified Switch CLI Command Reference 520 2009 D Link Corporation All Rights Reserved ...
Page 545: ...537 O SSupport ...
Page 546: ...D Link Unified Switch CLI Command Reference 538 2009 D Link Corporation All Rights Reserved ...
Page 566: ...D Link Unified Switch CLI Command Reference 558 2009 D Link Corporation All Rights Reserved ...