Users Guide
aaa authentication login default radius local
2. Specify the protocol for authentication.
CONFIGURATION mode
aaa radius auth-method mschapv2
3. Establish a host address and password.
CONFIGURATION mode
radius-server host H key K
4. Log in to switch using console or telnet or ssh with a valid user role.
When 1-factor authentication is used, the authentication succeeds enabling you to access the switch. When two-factor
authentication is used, the system prompts you to enter a one-time password as a second step of authentication. If a valid one-
time password is supplied, the authentication succeeds enabling you to access the switch.
TACACS+
Dell EMC Networking OS supports terminal access controller access control system (TACACS+ client, including support for
login authentication.
Configuration Task List for TACACS+
The following list includes the configuration task for TACACS+ functions.
● Choosing TACACS+ as the Authentication Method
● Monitoring TACACS+
● TACACS+ Remote Authentication
● Specifying a TACACS+ Server Host
For a complete listing of all commands related to TACACS+, refer to the Security chapter in the Dell EMC Networking OS
Command Reference Guide.
Choosing TACACS+ as the Authentication Method
One of the login authentication methods available is TACACS+ and the user’s name and password are sent for authentication to
the TACACS hosts specified.
To use TACACS+ to authenticate users, specify at least one TACACS+ server for the system to communicate with and
configure TACACS+ as one of your authentication methods.
To select TACACS+ as the login authentication method, use the following commands.
1. Configure a TACACS+ server host.
CONFIGURATION mode
tacacs-server host {ip-address | host}
Enter the IP address or host name of the TACACS+ server.
Use this command multiple times to configure multiple TACACS+ server hosts.
2. Enter a text string (up to 16 characters long) as the name of the method list you wish to use with the TACAS+
authentication method.
CONFIGURATION mode
aaa authentication login {method-list-name | default} tacacs+ [...method3]
The TACACS+ method must not be the last method specified.
3. Enter LINE mode.
CONFIGURATION mode
line {aux 0 | console 0 | vty number [end-number]}
4. Assign the method-list to the terminal line.
LINE mode
login authentication {method-list-name | default}
760
Security