Send feedback to nx5000-docfeedback@cisco.com
1-4
Cisco Nexus 5000 Series Switch CLI Software Configuration Guide
OL-16597-01
Chapter 1 Configuring TACACS+
Prerequisites for TACACS+
Prerequisites for TACACS+
TACACS+ has the following prerequisites:
• Obtain the IPv4 or IPv6 addresses or host names for the TACACS+ servers.
• Obtain the preshared keys from the TACACS+ servers, if any.
• Ensure that the Nexus 5000 Series switch is configured as a TACACS+ client of the AAA servers.
Guidelines and Limitations
TACACS+ has the following guidelines and limitations:
• You can configure a maximum of 64 TACACS+ servers on the Nexus 5000 Series switch.
Configuring TACACS+
This section includes the following topics:
• TACACS+ Server Configuration Process, page 1-5
• Enabling TACACS+, page 1-5
• Configuring TACACS+ Server Hosts, page 1-6
• Configuring Global Preshared Keys, page 1-6
• Configuring TACACS+ Server Preshared Keys, page 1-7
• Configuring TACACS+ Server Groups, page 1-8
• Specifying a TACACS+ Server at Login, page 1-9
• Configuring the Global TACACS+ Timeout Interval, page 1-10
• Configuring the Timeout Interval for a Server, page 1-10
• Configuring TCP Ports, page 1-11
• Configuring Periodic TACACS+ Server Monitoring, page 1-11
• Configuring the Dead-Time Interval, page 1-12
• Manually Monitoring TACACS+ Servers or Groups, page 1-13
• Disabling TACACS+, page 1-13
Note If you are familiar with the Cisco IOS CLI, be aware that the Cisco NX-OS commands for this feature
might differ from the Cisco IOS commands that you would use.