
Configuration
446
tacacs-server
authentication
host
<
ip-address
> [port <
port-number
>]
[timeout
<seconds>
] [key {0 | 7}
<string>
] [primary]
no tacacs-server authentication host
<
ip-address
>
Configure the IP address, listening port
number, the value of timeout timer and
the key string of the server;
the no form of this command deletes the
authentication server.
3. Configure the authentication timeout time
Command
Explanation
Global Mode
tacacs-server timeout
<seconds>
no tacacs-server timeout
Configure the authentication timeout for
the
server,
the
―
no
tacacs-server
timeout
‖
command
restores the default configuration.
4. Configure the IP address of the NAS
Command
Explanation
Global Mode
tacacs-server nas-ipv4
<ip-address>
no tacacs-server nas-ipv4
To configure the source IP address for
the packets for the switch.
50.3
Scenarios Typical Examples
Fig 50-1 TACACS Configuration
A computer connects to a switch, of which the IP address is 10.1.1.2 and connected
with a authentication server; IP address of the server is 10.1.1.3 and the
authentication port is defaulted at 49, set telnet log on authentication of the switch as
tacacs local, via using authentication server to achieve telnet user
10.1.1.1
10.1.1.2
Tacacs Server
10.1.1.3