
S e n d f e e d b a c k t o n x 5 0 0 0 - d o c f e e d b a c k @ c i s c o . c o m
1-8
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
OL-16597-01
Chapter 1 Configuring
Configuring
The following example shows how to configure the preshared keys:
switch#
configure terminal
switch(config)#
tacacs-server host 10.10.1.1 key 0 PlIjUhYg
switch(config)#
exit
switch#
show tacacs-server
switch#
copy running-config startup-config
Configuring Server Groups
You can specify one or more remote AAA servers to authenticate users using server groups. All members
of a group must belong to the protocol. The servers are tried in the same order in which you
configure them.
You can configure these server groups at any time but they only take effect when you apply them to an
AAA service. For information on AAA services, see the
“Remote AAA Services” section on page 1-3
.
To configure server groups, perform this task:
Step 3
switch(config)#
exit
Exits configuration mode.
Step 4
switch#
show tacacs-server
(Optional) Displays the server
configuration.
Note
The preshared keys are saved in encrypted
form in the running configuration. Use the
show running-config
command to display the
encrypted preshared keys.
Step 5
switch#
copy running-config
startup-config
(Optional) Copies the running configuration to the
startup configuration.
Command
Purpose
Command
Purpose
Step 1
switch#
configure terminal
Enters configuration mode.
Step 2
switch(config)#
aaa group server
group-name
Creates a server group and enters the
server group configuration mode for that
group.
Step 3
switch(config-)#
server
{
ipv4-address
|
ipv6-address
|
host-name
}
Configures the server as a member of the
server group.
Tip
If the specified server is not found,
configure it using the
tacacs-server host
command and retry this command.
Step 4
switch(config-)#
deadtime
minutes
(Optional) Configures the monitoring dead time. The
default is 0 minutes. The range is from 0 through 1440.
Note
If the dead-time interval for a
server group is greater than zero (0), that value
takes precedence over the global dead-time
value.