User Guide     618
Configuring AAA AAA Configuration
Step 5 copy running-config startup-config
Save the settings in the configuration file.
The following example shows how to add a RADIUS server on the switch. Set the IP address 
of the server as 192.168.0.10, the authentication port as 1812, the shared key as 123456, 
the timeout as 8 seconds and the retransmit number as 3.
Switch#configure
Switch(config)#radius-server host 192.168.0.10 auth-port 1812 timeout 8 retransmit 3 
key 123456
Switch(config)#show radius-server
Server Ip              Auth Port     Acct Port    Timeout    Retransmit   NAS Identifier
 
Shared key
192.168.0.10      1812             1813                 5                     2               000AEB132397    123456
Switch(config)#end
Switch#copy running-config startup-config
 ■ Adding TACACS+ Server
Follow these steps to add TACACS+ server on the switch:
Step 1 configure
Enter global configuration mode.
Step 2 tacacs-server host 
ip-address
 [ port 
port-id
 ] [ timeout 
time 
] [ key { [ 0 ] 
string 
| 7 
encrypted-string 
} ] 
Add the RADIUS server and configure the related parameters as needed.
host 
ip-address
:
 
Enter the IP address of the server running the TACACS+ protocol. 
port 
port-id
:
 
Specify the TCP destination port on the TACACS+ server for authentication 
requests. The default setting is 49.
timeout 
time
:
 
Specify the time interval that the switch waits for the server to reply before 
resending. The valid values are from 1 to 9 seconds and the default setting is 5 seconds.
key { [ 0 ] 
string 
| 7 
encrypted-string 
}: Specify the shared key. 0 and 7 represent the 
encryption type. 0 indicates that an unencrypted key will follow. 7 indicates that a symmetric 
encrypted key with a xed length will follow. By default, the encryption type is 0. 
string
 is the 
shared key for the switch and the server, which contains 32 characters at most. 
encrypted-
string
 is a symmetric encrypted key with a fixed length, which you can copy from the 
conguration le of another switch. The key or encrypted-key you congured here will be 
displayed in the encrypted form. 
Step 3 show tacacs-server
Verify the configuration of TACACS+ server.