Chapter 34
Configuring RADIUS and TACACS+
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
Allowing Users to Specify a TACACS+ Server at Login
To allow users logging into an MDS switch to select a TACACS+ server for authentication, follow these
steps:
Command
Step 1
switch# config t
Step 2
switch(config)# tacacs-server
directed-request
switch(config)# no tacacs-server
directed-request
You can use the show tacacs-server directed-request command to display the TACACS+ directed
request configuration.
switch# show tacacs-server directed-request
disabled
Defining Custom Attributes for Roles
Cisco MDS 9000 Family switches use the TACACS+ custom attribute for service shells to configure
roles to which a user belongs. TACACS+ attributes are specified in name=value format. The attribute
name for this custom attribute is cisco-av-pair. The following example illustrates how to specify roles
using this attribute:
cisco-av-pair=shell:roles="network-admin vsan-admin"
You can also configure optional custom attributes to avoid conflicts with non-MDS Cisco switches using
the same AAA servers.
cisco-av-pair*shell:roles="network-admin vsan-admin"
Additional custom attribute shell:roles are also supported:
shell:roles="network-admin vsan-admin"
or
shell:roles*"network-admin vsan-admin"
TACACS+ custom attributes can be defined on an Access Control Server (ACS) for various services (for
Note
example, shell). Cisco MDS 9000 Family switches require the TACACS+ custom attribute for the service
shell to be used for defining roles.
Supported TACACS+ Server Parameters
The Cisco NX-OS software currently supports the following parameters for the listed TACACS+ servers:
•
•
OL-18084-01, Cisco MDS NX-OS Release 4.x
TACACS+
cisco-av-pair=shell:roles="network-admin"
Cisco ACS TACACS+
Purpose
Enters configuration mode.
Allows users to specify a TACACS+ server to send the
authentication request when logging in.
Reverts to sending the authentication request to the first
server in the server group (default).
Cisco MDS 9000 Family CLI Configuration Guide
Configuring TACACS+
34-25