Page
42
TACACS
Configuration
Menu 6: Network TACACS Configuration
TACACS Server IP Address is: 0.0.0.0
Enter TACACS server address in dotted decimal form :
TACACS Backup IP Address is: 0.0.0.0
Enter TACACS server address in dotted decimal form :
URPC usernames as backup login is Disabled
Enable ? (Y/N), CR for no change) :
Select 1),
TACACS
Enable
sends the login information to the TACACS server for authentication. If
enabled, the primary TACACS server
addresses must be specified.
Select 2),
TACACS
Server
Address
assigns a specific TACACS server IP
addresses.
Select 3),
TACACS
Backup
Server
Address
assigns a specific Backup
Server IP addresses.
Select 4),
TACACS
Secret
assigns a secret word shared
between the TACACS server and this unit. A secret
can be up to 16 characters and must be exactly the same
as the secret stored on the server.
Select 5)
,
Enable
URPC
usernames
as
backup
allows an unsecured access in case all
specified TACACS servers are unavailable.
TACACS Enable....................1
Enable/Disable TACACS
TACACS Server Address............2
TACACS server IP address 0.0.0.0
TACACS Backup Server Address.....3
Backup TACACS server IP address
TACACS Secret....................4
TACACS secret key (16 char max)
Enable URPC usernames as backup..5
As written
TACACS Encryption Enable.........6
Enable/Disable encryption
TACACS login Timeout.............7
Sets Time units waits for response
TACACS Server Port...............8
Assign secure TCP port
URPC Privilege Level Enable......9
Enable/Disable TACACS privilege
URPC Privilege Level.............10
Set Privilege Level 1-15
Exit.............................X, CR
Select 4) from the Login
Setup Menu
displays the
TACACS Configuration
menu
Setting up TACACS
To enable TACACS for logins do the following:
Enable TACACS from the TACACS configuration menu.
Enter the IP address of the TACACS server
Enter the IP address of the backup TACACS server if any.
Enable local logins as a backup to the TACACS server if needed.
Secret word must match the secret word in the TACACS server configuration.
Enable URPC Privilege Level and set levels.
Enable usernames and passwords for the network and serial port via the logins setup access control
menu.
TACACS can be used to authenticate logins for the serial port, the network port, modem or all three. When
a telnet / SSH session (or RS232 session) is started the Host module will prompt for the username then a
password. The Host will send the username and password to the TACACS server. If the server verifies
the username and password, the Host will display the menus. If the server rejects the username and
password or does not respond the Host will display the reason the login failed.
TACACS login is...................Disabled
Enable ? (Y/N), CR for no change) :
TACACS secret is: HardlyASecret
Enter TACACS secret (16 chars max).
: