Chapter5ServiceConguration
ThuJul116:07:102004HostTopologychanged
zteA(cfg)#showudldport17
Port17
Administrativeconfiguration:Enable
Portmode:Aggressive(Aggr)
Currentstate:Unidirectional-Detectedlinkfailure
Recoveryconfiguration:Disable
Recoverytimeinterval:30s
Messagetimeinterval:15s
Forcecheckconfiguration:Disable
Forcechecktime:30s,Remaining:0s
Noneighbourinformationstored
5.39TACACS+Conguration
TACACS+Overview
TerminalAccessControllerAccess-ControlSystemPlus(TACACS+)isdevelopedfrom
TACACSandXTACACS.ItisthelatestversionofTACACS(notcompatiblewiththe
previoustwoversions).ItisapopularAAAprotocolatpresent.
TACACS+supportsseparateauthentication,authorization,andaccounting.Different
TACACS+serverscanactrespectivelyastheauthentication,authorization,and
accountingservers.
ConguringTACACS+
TheTACACS+congurationincludesthefollowingcommands:
CommandFunction
zte(cfg-nas)#tacacs-plusgroup<group-name>{enable|disable}Enablesordisablesaserver
group.
zte(cfg-nas)#tacacs-plusgroup<group-name>{add|delete}host
<A.B.C.D>[<49,1025-65535>|<4-180>|<string>]
Addsordeletesaserver
in/fromaTACACS+server
group.
zte(cfg-nas)#tacacs-plusloginauthendefaultgroup<group-name>SetsthedefaultTACACS+
loginauthenticationserver
group.
zte(cfg-nas)#tacacs-plusloginauthordefaultgroup<group-name>Setsthedefaultservergroup
authorizedforTACACS+
login.
5-143
SJ-20130731155059-002|2013-11-27(R1.0)ZTEProprietaryandCondential