Cisco MDS 9000 Series Configuration Manual page 93

Security
Hide thumbs Also See for MDS 9000 Series:
Table of Contents

Advertisement

Configuring Security Features on an External AAA Server
Sending TACACS+ Test Messages for Monitoring
You can manually send test messages to monitor a TACACS+ server.
To send the test message to the TACACS+ server, follow these steps:
Procedure
Step 1
switch# test aaa server tacacs+ 10.10.1.1 test
Sends a test message to a TACACS+ server using the default username (test) and password (test).
Step 2
switch# test aaa server tacacs+ 10.10.1.1 testuser Ur2Gd2BH
Sends a test message to a TACACS+ server using a configured test username and password. A configured
username and password is optional (see the
Password Aging Notification through TACACS+ Server
Password aging notification is initiated when the user authenticates to a Cisco MDS 9000 switch via a
TACACS+ account. The user is notified when a password is about to expire or has expired. If the password
has expired, user is prompted to change the password.
Note
As of Cisco MDS SAN-OS Release 3.2(1), only TACACS+ supports password aging notification. If you try
to use RADIUS servers by enabling this feature, RADIUSs will generate a SYSLOG message and authentication
will fall back to the local database.
Password aging notification facilitates the following:
• Password change—You can change your password by entering a blank password.
• Password aging notification—Notifies password aging. Notification happens only if the AAA server is
• Password change after expiration—Initiates password change after the old password expires. Initiation
Note
Password aging notification fails if you do not disable MSCHAP and MSCHAPv2 authentication.
To enable the password aging option in the AAA server, enter the following command:
aaa authentication login ascii-authentication
To determine whether or not password aging notification is enabled or disabled in the AAA server, enter the
following command:
show aaa authentication login ascii-authentication
configured and MSCHAP and MSCHAPv2 is disabled.
happens from the AAA server.
Sending TACACS+ Test Messages for Monitoring
Configuring Test Username, on page 73
Cisco MDS 9000 Series Security Configuration Guide, Release 8.x
section).
75

Advertisement

Table of Contents
loading

Table of Contents