Management Commands
652
ProSafe Managed Switch
with messages passed in clear text over the network; TACACS+ uses TCP to ensure reliable
delivery and a shared key configured on the client and daemon server to encrypt all
messages.
tacacs-server host
Use the tacacs-server host command in Global Configuration mode to configure a
TACACS+ server. This command enters into the TACACS+ configuration mode. The
<ip-address|hostname> parameter is the IP address or hostname of the TACACS+
server. To specify multiple hosts, multiple
tacacs-server host commands can be used.
Format tacacs-server host <ip-address|hostname>
Mode
no tacacs-server host
Use the no tacacs-server host command to delete the specified hostname or IP
address. The <ip-address|hostname> parameter is the IP address of the TACACS+
server.
Format no tacacs-server host <ip-address|hostname>
Mode
tacacs-server key
Use the tacacs-server key command to set the authentication and encryption key for all
TACACS+ communications between the switch and the TACACS+ daemon. The
<key-string> parameter has a range of 0 - 128 characters and specifies the authentication
and encryption key for all TACACS communications between the switch and the TACACS+
server. This key must match the key used on the TACACS+ daemon.
Text-based configuration supports TACACS server’s secrets in encrypted and non-encrypted
format. When you save the configuration, these secret keys are stored in encrypted format
only. If you want to enter the key in encrypted format, enter the key along with the encrypted
keyword. In the show running config command’s display, these secret keys are displayed in
encrypted format. You cannot show these keys in plain text format.
Format tacacs-server key [<key-string> | encrypted <key-string>]
Mode
no tacacs-server key
Use the no tacacs-server key command to disable the authentication and encryption
key for all TACACS+ communications between the switch and the TACACS+ daemon. The
Global Config
Global Config
Global Config