Allowing Users To Specify A Tacacs+ Server At Login; Defining Custom Attributes For Roles; Supported Tacacs+ Server Parameters - Cisco AP776A - Nexus Converged Network Switch 5020 Configuration Manual

Cisco mds 9000 family cli configuration guide - release 4.x (ol-18084-01, february 2009)
Hide thumbs Also See for AP776A - Nexus Converged Network Switch 5020:
Table of Contents

Advertisement

Chapter 34
Configuring RADIUS and TACACS+
S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m

Allowing Users to Specify a TACACS+ Server at Login

To allow users logging into an MDS switch to select a TACACS+ server for authentication, follow these
steps:
Command
Step 1
switch# config t
Step 2
switch(config)# tacacs-server
directed-request
switch(config)# no tacacs-server
directed-request
You can use the show tacacs-server directed-request command to display the TACACS+ directed
request configuration.
switch# show tacacs-server directed-request
disabled

Defining Custom Attributes for Roles

Cisco MDS 9000 Family switches use the TACACS+ custom attribute for service shells to configure
roles to which a user belongs. TACACS+ attributes are specified in name=value format. The attribute
name for this custom attribute is cisco-av-pair. The following example illustrates how to specify roles
using this attribute:
cisco-av-pair=shell:roles="network-admin vsan-admin"
You can also configure optional custom attributes to avoid conflicts with non-MDS Cisco switches using
the same AAA servers.
cisco-av-pair*shell:roles="network-admin vsan-admin"
Additional custom attribute shell:roles are also supported:
shell:roles="network-admin vsan-admin"
or
shell:roles*"network-admin vsan-admin"
TACACS+ custom attributes can be defined on an Access Control Server (ACS) for various services (for
Note
example, shell). Cisco MDS 9000 Family switches require the TACACS+ custom attribute for the service
shell to be used for defining roles.

Supported TACACS+ Server Parameters

The Cisco NX-OS software currently supports the following parameters for the listed TACACS+ servers:
OL-18084-01, Cisco MDS NX-OS Release 4.x
TACACS+
cisco-av-pair=shell:roles="network-admin"
Cisco ACS TACACS+
Purpose
Enters configuration mode.
Allows users to specify a TACACS+ server to send the
authentication request when logging in.
Reverts to sending the authentication request to the first
server in the server group (default).
Cisco MDS 9000 Family CLI Configuration Guide
Configuring TACACS+
34-25

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents