Technical data
BLADE OS 5.0 Command Reference
170
Chapter 6: The Configuration Menu BMD00142, November 2009
secbd enable|disable
Enables or disables TACACS+ secure back door access through Telnet, SSH/SCP, or
HTTP/HTTPS only when the TACACS+ servers are not responding.
This feature is recommended to permit access to the switch when the TACACS+ servers
become unresponsive. If no back door is enabled, the only way to gain access when
TACACS+ servers are unresponsive is to use the back door via the console port.
The default setting is disabled.
cmap enable|disable
Enables or disables TACACS+ privilege-level mapping.
The default value is disabled.
cauth disable|enable
Enables or disables TACACS+ command authorization.
clog disable|enable
Enables or disables TACACS+ command logging.
dreq disable|enable
Enables or disables TACACS+ directed request, which uses a specified TACACS+ server for
authentication, authorization, accounting. When enabled, When directed-request is enabled,
each user must add a configured TACACS+ server hostname to the username (for example,
username@hostname) during login.
This command allows the following options:
Restricted: Only the username is sent to the specified TACACS+ server.
No-truncate: The entire login string is sent to the TACACS+ server.
on
Enables the TACACS+ server. This is the default setting.
off
Disables the TACACS+ server.
cur
Displays current TACACS+ configuration parameters.
Table 77 TACACS+ Server Options
Command Syntax and Usage