Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell EMC SmartFabric OS10 User Guide Release 10.5.0

AAA with TACACS+ authentication

Configure a TACACS+ authentication server by entering the server IP address or host name. You must also enter a text string for the key used to authenticate the OS10 switch on a TACACS+ host. The Transmission Control Protocol (TCP) port entry is optional.

TACACS+ provides greater data security by encrypting the entire protocol portion in a packet sent from the switch to an authentication server. RADIUS encrypts only passwords.

  • Configure a TACACS+ authentication server in CONFIGURATION mode. By default, a TACACS+ server uses TCP port 49 for authentication.
    tacacs-server host {hostname | ip-address}  key {0 authentication-key | 9 authentication-key | authentication-key} [auth-port port-number]
    Re-enter the tacacs-server host command multiple times to configure more than one TACACS+ server. If you configure multiple TACACS+ servers, OS10 attempts to connect in the order you configured them. An OS10 switch connects with the configured TACACS+ servers one at a time, until a TACACS+ server responds with an accept or reject response.

Configure a global timeout setting allowed on TACACS+ servers. By default, OS10 times out after five seconds. No source interface is configured. The default VRF instance is used to contact TACACS+ servers.

NOTE You cannot configure both a nondefault VRF instance and a source interface at the same time for TACACS+ authentication.
NOTE A TACACS+ server configured with a host name is not supported on a nondefault VRF.
  • Configure the global timeout used to wait for an authentication response from TACACS+ servers in CONFIGURATION mode, from 1 to 1000 seconds; the default is 5.
    tacacs-server timeout seconds
  • (Optional) Specify an interface whose IP address is used as the source IP address for user authentication with a TACACS+ server in CONFIGURATION mode. By default, no source interface is configured. OS10 selects the source IP address of any interface from which a packet is sent to a TACACS+ server.
    NOTE If you configure a source interface which has no IP address, the IP address of the management interface is used.
    ip tacacs source-interface interface
  • (Optional) By default, the switch uses the default VRF instance to communicate with TACACS+ servers. You can optionally configure a non-default or the management VRF instance for TACACS+ authentication in CONFIGURATION mode.
    tacacs-server vrf management
    tacacs-server vrf vrf-name

Configure TACACS+ server

OS10(config)# tacacs-server host 1.2.4.5 key mysecret
OS10(config)# ip tacacs source-interface loopback 2

Configure TACACS+ server for non-default VRFs

OS10(config)# ip vrf blue
OS10(conf-vrf)# exit
OS10(config)# tacacs-server vrf blue

View TACACS+ server configuration

OS10# show running-configuration
...
tacacs-server host 1.2.4.5 key 9 3a95c26b2a5b96a6b80036839f296babe03560f4b0b7220d6454b3e71bdfc59b
ip tacacs source-interface loopback 2 
...

Delete TACACS+ server

OS10# no tacacs-server host 1.2.4.5

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\