39-43
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
OL-8978-04
Chapter 39 Configuring the Switch Access Using AAA
Configuring Authentication on the Switch
To clear all the Kerberos credentials, perform this task in privileged mode:
This example shows how to clear all the Kerberos credentials from the switch:
Console> (enable)
clear kerberos creds
Console> (enable)
Authentication Example
Figure 39-3
shows a simple network topology using .
In this example, authentication is enabled and local authentication is disabled for both the
login and enable access to the switch for all Telnet connections. When Workstation A attempts to
connect to the switch, the user is challenged for a username and password.
However, only local authentication is enabled for both the login and enable access on the console port.
Any user with access to the directly connected terminal can access the switch using the login and enable
passwords.
Figure 39-3
Example Network Topology
This example shows how to configure the switch so that authentication is enabled for Telnet
connections, local authentication is enabled for the console connections, and a encryption key
is specified:
Console> (enable)
show tacacs
Tacacs key:
Tacacs login attempts: 3
Tacacs timeout: 5 seconds
Tacacs direct request: disabled
Tacacs-Server Status
---------------------------------------- -------
Task
Command
Clear all the credentials.
clear kerberos creds
Workstation A
server
172.20.52.10
Switch
Terminal
Console port
connection
18927