Configuring TACACS+ set tacacs session
25-68 Authentication Configuration
Matrix(ro)->show tacacs session authorization
TACACS+ service: exec
TACACS+ session authorization A-V pairs:
access level attribute value
read-only 'priv-lvl' '0'
read-write 'priv-lvl' '1'
super-user 'priv-lvl' '15'
Thisexampleshowshowtodisplayclientsessionaccountingstate.
Matrix(ro)->show tacacs session accounting state
TACACS+ session accounting state: enabled
set tacacs session
UsethiscommandtoenableordisableTACACS+sessionaccounting,ortoconfigureTACACS+
sessionauthorizationparameters.Forsimplicity, separatesyntaxformatsareshownfor
configuringsessionaccountingandsessionauthorization.
Syntax
set tacacs session accounting {enable | disable}
settacacssessionauthorization{service name| read-onlyattributevalue| read-write
attributevalue|
super-user attributevalue}
Parameters
Defaults
None.
accounting SpecifiesthatTACACS+sessionaccountingisbeingconfigured.
enable|disable EnablesordisablesTACACS+sessionaccounting.
authorization SpecifiesthatTACACS+sessionauthorizationisbeingconfigured.
servicename Specifies thenameoftheservicethattheTACACS+clientwillrequest
fromtheTACACS+server.Thenamespecifiedheremustmatchthe
nameof
aserviceconfiguredontheserver.
read‐onlyattribute
value
SpecifiesthattheMatrixread‐onlyaccessprivilegelevelshouldbe
matchedtoaprivilegelevelconfiguredontheTACACS+serverby
meansofanattribute‐valuepairspecifiedbyattributeandvalue.
Bydefault,attributeis“priv‐lvl”andvalue
is0.
read‐writeattribute
value
SpecifiesthattheMatrixread‐writeaccessprivilegelevelshouldbe
matchedtoaprivilegelevelconfiguredontheTACACS+serverby
meansofanattribute‐valuepairspecifiedbyattributeandvalue.
Bydefault,attributeis“priv‐lvl”andvalueis1.
super‐userattribute
value
SpecifiesthattheMatrixsuper‐useraccessprivilegelevelshouldbe
matchedtoaprivilegelevelconfiguredontheTACACS+serverby
meansofanattribute‐valuepairspecifiedbyattributeandvalue.
Bydefault,attributeis“priv‐lvl”andvalueis15.