
30-18
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2948G-GE-TX, and Catalyst 2980G Switches Software Configuration Guide—Release 8.2GLX
78-15908-01
Chapter 30 Configuring Switch Access Using AAA
Configuring Authentication
Console> (enable) set tacacs server 172.20.52.10
172.20.52.10 added to TACACS server table as backup server.
Console> (enable) show tacacs
Login Authentication: Console Session Telnet Session
--------------------- ---------------- ----------------
tacacs disabled disabled
radius disabled disabled
local enabled(primary) enabled(primary)
Enable Authentication: Console Session Telnet Session
---------------------- ----------------- ----------------
tacacs disabled disabled
radius disabled disabled
local enabled(primary) enabled(primary)
Tacacs key:
Tacacs login attempts: 3
Tacacs timeout: 5 seconds
Tacacs direct request: disabled
Tacacs-Server Status
---------------------------------------- -------
172.20.52.3
172.20.52.2 primary
172.20.52.10
Console> (enable)
Enabling Authentication
Note
Specify at least one server before enabling authentication on the switch. For more
information on specifying servers, see the
“Specifying Servers” section on
page 30-17
.
You can enable authentication for login and enable access to the switch. If desired, you can
enter the console and telnet keywords to specify that authentication is used only on console
or Telnet connections. If you are using both RADIUS and , you can enter the primary
keyword to force the switch to try authentication first.
To enable authentication, perform this task in privileged mode:
Task
Command
Step 1
Enable authentication for normal login
mode. Enter the console or telnet keywords if you
want to enable only for the console
port or for the Telnet connection attempts.
set authentication login tacacs enable [all |
console | http | telnet] [primary]
Step 2
Enable authentication for enable
mode. Enter the console or telnet keywords if you
want to enable only for the console
port or for the Telnet connection attempts.
set authentication enable tacacs enable [all |
console | http | telnet] [primary]
Step 3
Verify the configuration.
show authentication