TACACS+ Authentication
Configuring TACACS+ on the Switch
[< local | none >]
If the primary authentication method fails, determines
whether to use the local password as a secondary method
or to disallow access.
aaa authentication num-attempts < 1-10 >
Specifies the maximum number of login attempts allowed in
the current session. Default: 3
Authentication Parameters
Table 4-1. AAA Authentication Parameters
Name Default Range Function
console, Telnet,
SSH, web or port-
access
n/a n/a Specifies the access method used when authenticating. TACACS+
authentication only uses the console, Telnet or SSH access methods.
enable n/a n/a Specifies the Manager (read/write) privilege level for the access
method being configured.
login <privilege-
mode>
privilege-mode
disabled
n/a login: Specifies the Operator (read-only) privilege level for the
access method being configured.
The privilege-mode option enables TACACS+ for a single login. The
authorized privilege level (Operator or Manager) is returned to the
switch by the TACACS+ server.
local
- or -
tacacs
local n/a Specifies the primary method of authentication for the access
method being configured.
local: Use the username/password pair configured locally in the
switch for
the privilege level being configured
tacacs: Use a TACACS+ server.
4-12