Send documentation comments to mdsfeedback-doc@cisco.com
41-24
Cisco MDS 9000 Family Fabric Manager Configuration Guide
OL-17256-03, Cisco MDS NX-OS Release 4.x
Chapter 41 Configuring RADIUS and TACACS+
MSCHAP Authentication
To discard RADIUS or TACACS+ distribution using Fabric Manager, follow these steps:
Step 1 Expand Switches > Security > AAA, and then select either RADIUS or TACACS+. You see either the
RADIUS or TACACS+ configuration in the Information pane.
Step 2 Click the CFS tab. You see either the RADIUS or TACACS+ CFS configuration.
Step 3 Choose abort from the Config Action drop-down list for each switch that should discard the pending
RADIUS or TACACS+ distribution.
Step 4 Click Apply Changes.
.
Clearing Sessions
To clear a RADIUS or TACACS+ distribution using Fabric Manager, follow these steps:
Step 1 Expand Switches > Security > AAA and then select either RADIUS or TACACS+.
You see either the RADIUS or TACACS+ configuration in the Information pane.
Step 2 Choose the CFS tab. You see either the RADIUS or TACACS+ CFS configuration.
Step 3 Choose clear from the Config Action drop-down list for each switch that should clear the pending
RADIUS or TACACS+ distribution.
Step 4 Click Apply Changes.
.
Merge Guidelines for RADIUS and TACACS+ Configurations
The RADIUS and TACACS+ server and global configuration are merged when two fabrics merge. The
merged configuration is applied to CFS distribution-enabled switches.
When merging the fabric, be aware of the following conditions:
• The server groups are not merged.
• The server and global keys are not changed during the merge.
• The merged configuration contains all servers found on all CFS enabled switches.
• The timeout and retransmit parameters of the merged configuration are the largest values found per
server and global configuration.
Caution If there is a conflict between two switches in the server ports configured, the merge fails.
MSCHAP Authentication
Microsoft Challenge Handshake Authentication Protocol (MSCHAP) is the Microsoft version of CHAP.
You can use MSCHAP for user logins to an MDS switch through a remote authentication server
(RADIUS or TACACS+).