User's Manual

Table Of Contents
Configuration Guide of XGS-5240-Series
51-2
tacacs-server authentication host <ip-a
ddress> [port <port-number>] [timeout
<seconds>] [key {0 | 7} <string>] [pri
mary]
no tacacs-server authentication host <
ip-address>
Configure the IP address, listening port
number, the value of timeout timer and
the key string of the TACACS+ server; t
he no form of this command deletes th
e TACACS+ authentication server.
3. Configure the TACACS+ authentication timeout time
Command
Explanation
Global Mode
tacacs-server timeout <seconds>
no tacacs-server timeout
Configure the authentication timeout for
the TACACS+ server, theno tacacs-se
rver timeout” command restores the de
fault configuration.
4. Configure the IP address of the TACACS+ NAS
Command
Explanation
Global Mode
tacacs-server nas-ipv4 <ip-address>
no tacacs-server nas-ipv4
To configure the source IP address for t
he TACACS+ packets for the switch.
51.3 TACACS+ Scenarios Typical Examples
Fig 7-1 TACACS Configuration
A computer connects to a switch, of which the IP address is 10.1.1.2 and connect
ed with a TACACS+ authentication server; IP address of the server is 10.1.1.3 and the
authentication port is defaulted at 49, set telnet log on authentication of the switch as
tacacs local, via using TACACS+ authentication server to achieve telnet user authenticat
10.1.1.1
10.1.1.2
Tacacs Server
10.1.1.3