Group - Cisco 4700M Configuration Manual

Application control engine appliance security
Hide thumbs Also See for 4700M:
Table of Contents

Advertisement

Chapter 2
Configuring Authentication and Accounting Services
Creating a TACACS+, RADIUS, or LDAP Server Group
OL-16202-01
Configuring the ACE as a Client of a RADIUS, TACACS+, or LDAP Server
A server group is a list of server hosts of a particular type. The ACE allows you
to configure multiple TACACS+, RADIUS, and LDAP servers as a named server
group. You group the different AAA server hosts into distinct lists. The ACE
searches for the server hosts in the order in which you specify them within a

group.

Use the aaa group server command to configure independent server groups of
TACACS+, RADIUS, or LDAP servers. You can configure server groups at any
time, but they only take effect when you apply them to the AAA service using the
aaa authentication login or the aaa accounting default commands.
You can configure a maximum of 10 server groups for each context in the ACE.
The ACE attempts to contact the first server listed in the server group for user
authentication and accounting. If that server is unavailable, the ACE attempts to
contact the next configured server listed in the group. If all servers in the group
are unavailable, the ACE then tries the servers in the next configured server group.
The ACE repeats this process until the authentication request can be handled by
an AAA server. If the specified AAA servers in a server group are unavailable,
and you specify local authentication as the fallback method (as specified in the
aaa authentication login command), the ACE attempts to authenticate the user
against the local database on the ACE. If you do not have a fallback method, the
ACE continues to contact one of the AAA servers listed in the server group.
The syntax of this command is as follows:
aaa group server {ldap | radius | tacacs+} group_name
The arguments and keywords are as follows:
ldap—Specifies an LDAP directory server group.
radius—Specifies a RADIUS server group.
tacacs+—Specifies a TACACS+ server group.
group_name—Group of servers. The server group name is a maximum of 64
alphanumeric characters with no spaces.
The CLI displays the TACACS+, RADIUS, or LDAP server configuration mode
where you identify the name of one or more previously configured servers that
you want added to the server group.
Cisco 4700 Series Application Control Engine Appliance Security Configuration Guide
2-39

Advertisement

Table of Contents
loading

This manual is also suitable for:

4700 series

Table of Contents