Switch User Manual
clear tacacs server TACACS+ Configuration
SecureStack C3 Configuration Guide 27-5
Mode
Switchcommand,Read‐Write.
Usage
Upto5TACACS+serverscanbeconfigured,withtheindexvalueof1havingthehighestpriority.
Ifyouwanttochangethedefaulttimeoutvalueforaspecificserverorallservers,youmustenter
thecommandusingthetimeoutparameter.
Whenatleastonebackupserverhasbeen
configuredandtheswitchlosescontactwiththe
primaryserver,theswitchwillcontactthenextserverinpriority.Iftheswitchwastryingto
authenticateauserwhentheconnectionwaslost,orifthedefaultloginaccess(read‐only
permissions)hadbeenreceived,theswitchwilltrytoauthenticate
again.
Ifauserhadalreadybeenauthenticatedandauthorized,thenthebackupserveriscontacted
withoutrequiringanyauthentication.Thebackupserverwilljustauthorizeoraccountforthe
packetscominginforthatuser.SinceataskIDisassociatedwitheachaccountingsession,ifthere
isafailover
toabackupserver,theaccountinginformationwillstillbeassociatedwiththecorrect
sessionusingthetaskID.
Whenafailovertoabackupserveroccurs,syslogmessagesaregeneratedcontainingthereason
forthefailure.
Example
ThisexampleconfiguresTACACS+server1.Then,thedefaulttimeoutvalueof10secondsis
changedto20seconds.
C3(rw)->set tacacs server 1 192.168.10.10 49 mysecret
C3(rw)->set tacacs server 1 timeout 20
clear tacacs server
UsethiscommandtoremoveoneorallconfiguredTACACS+servers,ortoreturnthetimeout
valuetoitsdefaultvalueforoneorallconfiguredTACACS+servers.
Syntax
clear tacacs server {all | index} [timeout]
Parameters
Defaults
Iftimeoutisnotspecified,theaffectedTACACS+serverswillberemoved.
Mode
Switchcommand,Read‐Write.
all SpecifiesthatallconfiguredTACACS+serversshouldbeaffected.
index
SpecifiesoneTACACS+servertobeaffected.
timeout (Optional)Returnthetimeoutvaluetoitsdefaultvalueof10seconds.