Cisco 4700M Configuration Manual page 104

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Configuring the ACE as a Client of a RADIUS, TACACS+, or LDAP Server
Setting the Global TACACS+ Server Dead-Time Interval
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
2-34
0—Configures a key specified in clear text (indicated by 0) to authenticate
communication between the TACACS+ client and server.
7—Configures a key specified in encrypted text (indicated by 7) to
authenticate communication between the TACACS+ client and server.
For example, to globally configure an authentication key in encrypted text
(indicated by 7) to authenticate communication between the TACACS+ client and
server, enter:
host1/Admin(config)# tacacs-server key 7 abe4DFeeweo00o
To delete the key, enter:
host1/Admin(config)# no tacacs-server key 7 abe4DFeeweo00o
During the dead-time interval, the ACE sends probe access-request packets to
verify that the TACACS+ server is available and can receive authentication
requests. The dead-time interval starts when the server does not respond to an
authentication request transmission. When the server responds to a probe
access-request packet, the ACE retransmits the authentication request to the
server.
Use the tacacs-server deadtime command to globally set the time interval in
which the ACE verifies whether a nonresponsive server is operational.
This command causes the ACE to mark any TACACS+ servers that fail to respond
to authentication requests as dead. This action avoids the wait for the request to
time out before trying the next configured server. The ACE skips a TACACS+
server that is marked as dead by sending additional requests for the duration of the
minutes argument.
The syntax of this command is as follows:
tacacs-server deadtime minutes
The minutes argument is the length of time that the ACE skips a nonresponsive
TACACS+ server for transaction requests. Valid entries are from 0 to 1440
minutes (24 hours). The default is 0.
For example, to globally configure a 15-minute dead-time interval for TACACS+
servers that fail to respond to authentication requests, enter:
host1/Admin(config)# tacacs-server deadtime 15
Chapter 2
Configuring Authentication and Accounting Services
OL-16202-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents