Send documentation comments to mdsfeedback-doc@cisco.com
41-15
Cisco MDS 9000 Family Fabric Manager Configuration Guide
OL-17256-03, Cisco MDS NX-OS Release 4.x
Chapter 41 Configuring RADIUS and TACACS+
Configuring TACACS+ Server Monitoring Parameters
• Timeout value
• Number of retransmission attempts
• Allowing the user to specify a TACACS+ server at login
About the Default TACACS+ Server Encryption Type and Preshared Key
You need to configure the TACACS+ preshared key to authenticate the switch to the TACACS+ server.
The length of the key is restricted to 64 characters and can include any printable ASCII characters (white
spaces are not allowed). You can configure a global key to be used for all TACACS+ server
configurations on the switch.
You can override this global key assignment by explicitly using the key option when configuring and
individual TACACS+ server.
Setting the Default TACACS+ Server Encryption Type and Preshared Key
To configure the default TACACS+ server encryption type and preshared key using Fabric Manager,
follow these steps:
Step 1 Expand Switches > Security > AAA, and then select TACACS+.
You see the TACACS+ configuration in the Information pane.
Step 2 If the Defaults tab is dimmed, click the CFS tab.
Step 3 Click the Defaults tab.
You see the TACACS+ default settings.
Step 4 Select plain or encrypted from the AuthType drop-down menu and set the key in the Auth Key field.
Step 5 Click the Apply Changes icon to save the changes.
Setting the Default TACACS+ Server Timeout Interval and Retransmits
By default, a switch retries a TACACS+ server only once. This number can be configured. The maximum
is five retries per server. You can also configure the timeout value for the TACACS+ server.
To configure the number of retransmissions and the time between retransmissions to the TACACS+
servers using Fabric Manager, follow these steps:
Step 1 Expand Switches > Security > AAA, and then select TACACS+.
You see the TACACS+ configuration in the Information pane.
Step 2 Choose the Defaults tab. (If the Defaults tab is disabled, click the CFS tab first.)
You see the TACACS+ default settings.
Step 3 Supply values for the Timeout and Retransmits fields for authentication attempts.