Example: TACACS Authentication
The following example shows how to configure as the security protocol for PPP authentication:
aaa new-model
aaa authentication ppp test group local
tacacs-server host 10.1.2.3
tacacs-server key goaway
interface serial 0
ppp authentication chap pap test
The lines in the preceding sample configuration are defined as follows:
•
The
aaa new-model
command enables the AAA security services.
•
The
aaa authentication
command defines a method list,
“
test,
”
to be used on serial interfaces running
PPP. The keyword
group
means that authentication will be done through . If
returns an ERROR of some sort during authentication, the keyword
local
indicates that
authentication will be attempted using the local database on the network access server.
•
The
tacacs-server host
command identifies the daemon as having an IP address of 10.1.2.3.
The
tacacs-server key
command defines the shared encryption key to be
“
goaway.
”
•
The
interface
command selects the line, and the
ppp authentication
command applies the test method
list to this line.
The following example shows how to configure as the security protocol for PPP authentication,
but instead of the
“
test
”
method list, the
“
default
”
method list is used.
aaa new-model
aaa authentication ppp default if-needed group local
tacacs-server host 10.1.2.3
tacacs-server key goaway
interface serial 0
ppp authentication chap default
The lines in the preceding sample configuration are defined as follows:
•
The
aaa new-model
command enables the AAA security services.
•
The
aaa authentication
command defines a method list,
“
default,
”
to be used on serial interfaces running
PPP. The keyword
default
means that PPP authentication is applied by default to all interfaces. The
if-needed
keyword means that if the user has already authenticated by going through the ASCII login
procedure, then PPP authentication is not necessary and can be skipped. If authentication is needed, the
keyword
group
means that authentication will be done through . If
returns an ERROR of some sort during authentication, the keyword
local
indicates that authentication
will be attempted using the local database on the network access server.
•
The
tacacs-server host
command identifies the daemon as having an IP address of 10.1.2.3.
The
tacacs-server key
command defines the shared encryption key to be
“
goaway.
”
•
The
interface
command selects the line, and the
ppp authentication
command applies the default
method list to this line.
The following example shows how to create the same authentication algorithm for PAP, but it calls the method
list
“
MIS-access
”
instead of
“
default
”
:
aaa new-model
Consolidated Platform Configuration Guide, Cisco IOS Release 15.2(4)E (Catalyst 2960-X Switches)
897
Configuration Examples for
Содержание Catalyst 2960 Series
Страница 78: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches lxxviii Contents ...
Страница 96: ......
Страница 184: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 102 Additional References ...
Страница 195: ...P A R T II IP Multicast Routing Configuring IGMP Snooping and Multicast VLAN Registration page 115 ...
Страница 196: ......
Страница 250: ......
Страница 292: ......
Страница 488: ......
Страница 589: ...P A R T VI Cisco Flexible NetFlow Configuring NetFlow Lite page 509 ...
Страница 590: ......
Страница 619: ...P A R T VII QoS Configuring QoS page 539 Configuring Auto QoS page 645 ...
Страница 620: ......
Страница 749: ...P A R T VIII Routing Configuring IP Unicast Routing page 669 Configuring IPv6 First Hop Security page 677 ...
Страница 750: ......
Страница 796: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 714 Additional References ...
Страница 856: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 774 Additional References ...
Страница 1400: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1318 Additional References ...
Страница 1546: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1464 Auto Identity ...
Страница 1596: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1514 Additional References ...
Страница 1604: ......
Страница 1740: ......
Страница 1764: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1682 Additional References ...
Страница 1942: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1860 cli_write ...
Страница 1950: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1868 context_save ...
Страница 2058: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1976 event_register_wdsysmon ...
Страница 2076: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 1994 smtp_subst ...
Страница 2090: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 2008 sys_reqinfo_syslog_history ...
Страница 2104: ...Consolidated Platform Configuration Guide Cisco IOS Release 15 2 4 E Catalyst 2960 X Switches 2022 unregister_counter ...
Страница 2105: ...P A R T XII Configuring Cisco IOS IP SLAs Configuring Cisco IP SLAs page 2025 ...
Страница 2106: ......
Страница 2118: ......
Страница 2164: ......