Information About TACACS+ 41
TACACS+ and Switch Access 41
TACACS+ Overview 41
TACACS+ Operation 43
Method List 44
TACACS+ Configuration Options 44
TACACS+ Login Authentication 44
TACACS+ Authorization for Privileged EXEC Access and Network Services 44
TACACS+ Accounting 45
Default TACACS+ Configuration 45
How to Configure TACACS+ 45
Identifying the TACACS+ Server Host and Setting the Authentication Key 45
Configuring TACACS+ Login Authentication 47
Configuring TACACS+ Authorization for Privileged EXEC Access and Network Services 50
Starting TACACS+ Accounting 52
Establishing a Session with a Router if the AAA Server is Unreachable 53
Monitoring TACACS+ 54
Additional References 54
Feature Information for TACACS+ 55
CHAPTER 6
Configuring RADIUS 57
Finding Feature Information 57
Prerequisites for Configuring RADIUS 57
Restrictions for Configuring RADIUS 58
Information about RADIUS 59
RADIUS and Switch Access 59
RADIUS Overview 59
RADIUS Operation 60
RADIUS Change of Authorization 61
Change-of-Authorization Requests 62
RFC 5176 Compliance 63
Preconditions 64
CoA Request Response Code 64
Session Identification 64
CoA ACK Response Code 65
Catalyst 2960-X Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX
OL-29048-01 v
Contents