Troubleshooting Guide

Table Of Contents
Switch access level TACACS+ privilege level Description
READ WRITE ALL 15 Permits you to have all the
rights of read-write access and
the ability to change security
settings, including Avaya
command line interface (ACLI)
and Web-based management
user names and passwords,
and the SNMP community
strings.
Note:
Access level 15 is
internally mapped to
access level 6, which
ensures consistency with
other vendor
implementations. The
switch does not
differentiate between an
access level of 6 and an
access level of 15.
After you enable TACACS+ authorization, the current privilege-level to command mapping
on the switch is no longer relevant because the TACACS+ server has complete responsibility
for command authorization. TACACS+ authorization provides access to the system based on
username, not based on privilege level.
Note:
If you want to switch to a privilege level 'X' using tacacs switch level <1-15>
command, you must create a user "$enabX$" on the TACACS+ server. X is the privilege
level that you want to change.
3. On the TACACS+ server, check whether you configured the password and user name
correctly.
4. On the TACACS+ server, check whether you configured the switch IP address in the trust
list.
5. Check whether you configured the encryption key, connection mode (single connection or
per-session connection), and TCP port number the same on the TACACS+ server and
switch.
6. If you can log on to the switch, check whether the TACACS+ server configured on the
platform has the correct IP address:
show tacacs
7. Use the output from the preceding step to verify whether the key field configured on the
platform is the same as that on the TACACS+ server.
Upper layer troubleshooting
January 2017 Troubleshooting 238
Comments on this document? infodev@avaya.com