Chapter 18
Configuring TACACS+
S e n d f e e d b a c k t o n x 5 0 0 0 - d o c f e e d b a c k @ c i s c o . c o m
Configure the preshared secret keys for the TACACS+ servers.
Step 3
See the
Server Preshared Keys" section on page
If needed, configure TACACS+ server groups with subsets of the TACACS+ servers for AAA
Step 4
authentication methods.
See the
section on page
Step 5
If needed, configure any of the following optional parameters:
•
•
•
•
If needed, configure periodic TACACS+ server monitoring.
Step 6
See the
Enabling TACACS+
By default, the TACACS+ feature is disabled on the Nexus 5000 Series switch. To explicitly enable the
TACACS+ feature to access the configuration and verification commands for authentication, perform
this task:
Command
Step 1
switch# configure terminal
Step 2
switch(config)# feature tacacs+
Step 3
switch(config)# exit
Step 4
switch# copy running-config
startup-config
Configuring TACACS+ Server Hosts
To access a remote TACACS+ server, you must configure the IPv4 or IPv6 address or the hostname for
the TACACS+ server on the Nexus 5000 Series switch. All TACACS+ server hosts are added to the
default TACACS+ server group.You can configure up to 64 TACACS+ servers.
If a preshared key is not configured for a configured TACACS+ server, a warning message is issued if a
global key is not configured. If a TACACS+ server key is not configured, the global key (if configured)
is used for that server (see the
"Configuring TACACS+ Server Preshared Keys" section on page
Before you configure TACACS+ server hosts, you should do the following:
OL-16597-01
"Configuring Global Preshared Keys" section on page 18-6
"Configuring TACACS+ Server Groups" section on page 18-7
16-6.
Dead-time interval
Allow TACACS+ server specification at login
Timeout interval
See the
"Configuring the Global TACACS+ Timeout Interval" section on page
TCP port
See the
"Configuring TCP Ports" section on page
"Configuring Periodic TACACS+ Server Monitoring" section on page
18-7.
18-10.
Purpose
Enters configuration mode.
Enables TACACS+.
Exits configuration mode.
(Optional) Copies the running configuration to the
startup configuration.
"Configuring Global Preshared Keys" section on page 18-6
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
Configuring TACACS+
and the
"Configuring TACACS+
and the
"Configuring AAA"
18-9.
18-11.
and the
18-7).
18-5