934
|
Security
www.dell.com | support.dell.com
Figure 45-5
demonstrates how to configure the
access-class
from a server. This causes the
configured access-class on the VTY line to be ignored. If you have configured a
deny10
ACL on the
server, FTOS downloads it and applies it. If the user is found to be coming from the 10.0.0.0
subnet, FTOS also immediately closes the Telnet connection. Note, that no matter where the user is coming
from, they see the login prompt.
Figure 45-5. Specify a server host
When configuring a server host, you can set different communication parameters, such as the
the key password.
To specify a server host and configure its communication parameters, use the following
command in the CONFIGURATION mode:
To specify multiple server hosts, configure the
tacacs-server host
command multiple times. If
multiple server hosts are configured, FTOS attempts to connect with them in the order in which
they were configured.
To view the configuration, use the
show running-config
command in the EXEC
Privilege mode.
Command Syntax
Command Mode
Purpose
tacacs-server host
{
hostname
|
ipv4-address
|
ipv6-address
} [
port
port-number
] [
timeout
seconds
] [
key
key
]
CONFIGURATION
Enter the host name or IP address of the
server host. Configure the optional communication
parameters for the specific host:
•
port
port-number
range: 0 to 65335. Enter a TCP
port number. The default is 49.
•
timeout
seconds
range: 0 to 1000. Default is 10
seconds.
•
key
key:
Enter a string for the key. The key can be up
to 42 characters long. This key must match a key
configured on the server host. This
parameter should be the last parameter configured.
If these optional parameters are not configured, the
default global values are applied.
FTOS#
FTOS(conf)#
FTOS(conf)#ip access-list standard deny10
FTOS(conf-ext-nacl)#permit 10.0.0.0/8
FTOS(conf-ext-nacl)#deny any
FTOS(conf)#
FTOS(conf)#aaa authentication login tacacsmethod
FTOS(conf)#aaa authentication exec tacacsauthorization
FTOS(conf)#tacacs-server host 25.1.1.2 key force10
FTOS(conf)#
FTOS(conf)#line vty 0 9
FTOS(config-line-vty)#login authentication tacacsmethod
FTOS(config-line-vty)#authorization exec tacauthor
FTOS(config-line-vty)#
FTOS(config-line-vty)#access-class deny10
FTOS(config-line-vty)#end
Summary of Contents for Force10 E300
Page 1: ...FTOS Configuration Guide FTOS 8 4 2 7 E Series TeraScale C Series S Series S50 S25 ...
Page 32: ...32 w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 132: ...132 802 1X w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 310: ...310 Configuration Replace and Rollback w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 330: ...330 Dynamic Host Configuration Protocol w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 402: ...402 High Availability w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 462: ...462 Interfaces w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 482: ...482 IPv4 Addressing w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 506: ...506 IPv6 Addressing w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 582: ...582 Layer 2 w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 642: ...642 Multicast Source Discovery Protocol w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 662: ...662 Multiple Spanning Tree Protocol w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 690: ...690 Object Tracking w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 754: ...754 PIM Dense Mode w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 784: ...784 PIM Source Specific Mode w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 800: ...800 Power over Ethernet w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 876: ...876 Quality of Service w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 892: ...892 Routing Information Protocol w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 1006: ...1006 Simple Network Management Protocol w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 1018: ...1018 SONET SDH w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 1048: ...1048 Broadcast Storm Control w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 1096: ...1096 Uplink Failure Detection UFD w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 1098: ...1098 Upgrade Procedures w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 1196: ...1196 C Series Debugging and Diagnostics w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 1252: ...1252 Standards Compliance w w w d e l l c o m s u p p o r t d e l l c o m ...
Page 1262: ...1262 Index w w w d e l l c o m s u p p o r t d e l l c o m ...