Sending Tacacs+ Test Messages For Monitoring; Password Aging Notification Through Tacacs+ Server; About Users Specifying A Tacacs+ Server At Login - Cisco AP776A - Nexus Converged Network Switch 5020 Configuration Manual

Cisco mds 9000 family cli configuration guide - release 4.x (ol-18084-01, february 2009)
Hide thumbs Also See for AP776A - Nexus Converged Network Switch 5020:
Table of Contents

Advertisement

Configuring TACACS+
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m

Sending TACACS+ Test Messages for Monitoring

You can manually send test messages to monitor a TACACS+ server.
To send the test message to the TACACS+ server, follow these steps:
Command
switch# test aaa server tacacs+
10.10.1.1 test test
switch# test aaa server tacacs+
10.10.1.1 testuser Ur2Gd2BH

Password Aging Notification through TACACS+ Server

Password aging notification is initiated when the user authenticates to a Cisco MDS 9000 switch via a
TACACS+ account. The user is notified when a password is about to expire or has expired. If the
password has expired, user is prompted to change the password.
As of Cisco MDS SAN-OS Release 3.2(1), only TACACS+ supports password aging notification. If you
Note
try to use RADIUS servers by enabling this feature, RADIUSs will generate a SYSLOG message and
authentication will fall back to the local database.
Password aging notification facilitates the following:
To enable the password aging option in the AAA server, enter the following command:
aaa authentication login password-aging enable
To determine whether or not password aging notification is enabled or disabled in the AAA server, enter
the following command:
show aaa authentication login password-aging

About Users Specifying a TACACS+ Server at Login

By default, an MDS switch forwards an authentication request to the first server in the TACACS+ server
group. You can configure the switch to allow the user to specify which TACACS+ server to send the
authenticate request. If you enable this feature, the user can log in as username@hostname, where the
hostname is the name of a configured TACACS+ server.
Cisco MDS 9000 Family CLI Configuration Guide
34-24
Password change — You can change your password by entering a blank password.
Password aging notification — Notifies password aging. Notification happens only if the AAA
server is configured.
Password change after expiration — Initiates password change after the old password expires.
Initiation happens from the AAA server.
Purpose
Sends a test message to a TACACS+ server using the
default username (test) and password (test).
Sends a test message to a TACACS+ server using a
configured test username and password.
A configured username and password is optional (see the
"Configuring Test Username" section on page
Chapter 34
Configuring RADIUS and TACACS+
34-22).
OL-18084-01, Cisco MDS NX-OS Release 4.x

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents