Authentication, Authorization and Accounting (AAA) for ERS and ES
Technical Configuration Guide
48
November 2010
avaya.com
Port: 49
Key: ***************
authorization is enabled
Authorization is enabled on levels : 0-15
accounting is enabled
3.5.2 ERS 1600, 8300
ACLI or JDM (Java Device Manager) can be used to configure the switch, for simplicity and readability,
we will document command line interface commands:
To configure
8300:5#
config tacacs enable true
8300:5#
config tacacs server create 10.10.50.40 key Dda
To display configuration
8300:5#
show tacacs info
Sub-Context: clear config monitor show test trace
Current Context:
enable : true
8300:5#
show tacacs server config
Sub-Context: clear config monitor show test trace
Current Context:
create :
IP address Status Key Port Prio Timeout Single Source
SourceEnabled
10.10.50.40 NotConn Dda 49 1 10 false 0.0.0.0
The source IP address sent by the switch (Layer 2 operation) is always the Management IP
address configured on the switch when sending a client message.
There is no way to change the source IP address. When the switch is configured in
routed mode, it uses interface IP address where frame is sent.
Hence, if you have multiple IP interfaces facing the core network where a message
could be sent, you will have to configure the server with each IP address.
With the ERS 5500 switch, you can configure two servers, a primary server and a
secondary server. If all servers are not reachable (no answers) then local authentication is
done. You get the following message at console:
no response from servers