Aaa Server Distribution; Enabling Aaa Server Distribution - Cisco AP776A - Nexus Converged Network Switch 5020 Configuration Manual

Cisco mds 9000 family cli configuration guide - release 4.x (ol-18084-01, february 2009)
Hide thumbs Also See for AP776A - Nexus Converged Network Switch 5020:
Table of Contents

Advertisement

AAA Server Distribution

S e n d d o c u m e n t a t i o n c o m m e n t s t o m d s f e e d b a c k - d o c @ c i s c o . c o m
Command
Step 4
switch(config-tacacs+)# server ServerB
switch(config-tacacs+)# no server ServerB
Step 5
switch(config-tacacs+)# deadtime 30
switch(config-tacacs+)# no deadtime 30
AAA Server Distribution
Configuration for RADIUS and TACACS+ AAA on an MDS switch can be distributed using the Cisco
Fabric Services (CFS). The distribution is disabled by default (see
Infrastructure").
After enabling the distribution, the first server or global configuration starts an implicit session. All
server configuration commands entered thereafter are stored in a temporary database and applied to all
switches in the fabric (including the originating one) when you explicitly commit the database. The
various server and global parameters are distributed, except the server and global keys. These keys are
unique secrets to a switch and should not be shared with other switches.
Note
Server group configurations are not distributed.
For an MDS switch to participate in AAA server configuration distribution, it must be running Cisco
Note
MDS SAN-OS Release 2.0(1b) or later, or Cisco NX-OS 4.1(1).

Enabling AAA Server Distribution

Only switches where distribution is enabled can participate in the distribution activity.
Cisco MDS 9000 Family CLI Configuration Guide
34-30
Chapter 34
Configuring RADIUS and TACACS+
Purpose
Configures ServerB to be tried second within the
server group TacacsServer1.
Deletes ServerB within the TacacsServer1 list of
servers.
Configures the monitoring dead time to 30 minutes.
The range is 0 through 1440.
If the dead-time interval for an individual
Note
TACACS+ server is greater than 0, that value
takes precedence over the value set for the
server group.
Reverts to the default value (0 minutes).
Note
If the dead-time interval for both the
TACACS+ server group and an individual
TACACS+ server in the TACACS+ server
group is set to 0, the switch does not mark the
TACACS+ server as dead when it is found to
be unresponsive by periodic monitoring.
Also, the switch does not perform dead server
monitoring for that TACACS+ server. (See
the
"Configuring TACACS+ Server
Monitoring Parameters" section on
page
34-21.)
Chapter 7, "Using the CFS
OL-18084-01, Cisco MDS NX-OS Release 4.x

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents