Cisco SFS7000P-SK9 Command Reference - Page 22

Customizing the Login Prompt, Entering CLI Modes

Page 22 highlights

Entering CLI Modes Chapter 1 Using the CLI Authentication local and then TACAS TACAS and then local How it Works Verifies against the chassis database then checks the TACAS client. Checks the TACAS client and then verifies against the chassis database. When local authentication is in effect and a user logs in, the user must be configured as a CLI user. The login username and password are verified against the local CLI user database. If a match is found, the login succeeds, and the user is assigned a pre-configured privilege level. When TACACS+ authentication is in effect, the login username and password are passed to the TACACS+ server for verification. The TACACS+ server verifies the login username and password, and it sends back a reply. No TACACS+ user information is stored locally. The show user all command shows local users only. The config TACACS-server host command (see config TACACS-server host, page 2-22) configures the IP address of TACACS+ servers. There can be three TACACS+ servers configured. The first server is queried, the second server is queried if the first server is not reachable, and the third server is queried if the both of the other servers are not reachable. Cisco supports only TACACS+ authentication; therefore, no privilege level is verified against the TACACS+ server. All users authenticated by the TACACS+ server are given unrestricted rights. If a TACACS+ user makes changes to system configuration, the log will include the TACACS+ username and the config information, just as it does for a local user. Like RADIUS users, the TACACS+ users do not have associating SNMP community strings. There are no SNMP logins for TACACS+ users. Note The following are limitations to TACACS+ authentication: TACACS+ authorization and accounting are not supported. TACACS+ single-connection not supported. Each login authentication makes its own connection to the TACACS+ server. TACACS+ user privilege level is always unrestricted. Customizing the Login Prompt The CLI checks the file login-banner for customized text to include in the prompt. Use the copy command to place a file named login-banner in the config directory of the switch. You can do this with FTP: copy ftp://user:xxx.x.x.x/my-banner config:login-banner Entering CLI Modes The CLI uses the following three command modes: • User Execute mode • Privileged Execute mode • Global Configuration mode Cisco SFS 7000 Series Product Family Command Reference Guide 1-4 OL-9163-02

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404

1-4
Cisco SFS 7000 Series Product Family Command Reference Guide
OL-9163-02
Chapter 1
Using the CLI
Entering CLI Modes
When local authentication is in effect and a user logs in, the user must be configured as a CLI user. The
login username and password are verified against the local CLI user database. If a match is found, the
login succeeds, and the user is assigned a pre-configured privilege level.
When TACACS+ authentication is in effect, the login username and password are passed to the
TACACS+ server for verification. The TACACS+ server verifies the login username and password, and
it sends back a reply. No TACACS+ user information is stored locally. The
show user all
command
shows local users only.
The
config TACACS-server host
command (see
config TACACS-server host, page 2-22
) configures the
IP address of TACACS+ servers. There can be three TACACS+ servers configured. The first server is
queried, the second server is queried if the first server is not reachable, and the third server is queried if
the both of the other servers are not reachable.
Cisco supports only TACACS+ authentication; therefore, no privilege level is verified against the
TACACS+ server. All users authenticated by the TACACS+ server are given unrestricted rights. If a
TACACS+ user makes changes to system configuration, the log will include the TACACS+ username
and the config information, just as it does for a local user.
Like RADIUS users, the TACACS+ users do not have associating SNMP community strings. There are
no SNMP logins for TACACS+ users.
Note
The following are limitations to TACACS+ authentication:
TACACS+ authorization and accounting are not supported.
TACACS+ single-connection not supported. Each login authentication makes its own connection to the
TACACS+ server.
TACACS+ user privilege level is always unrestricted.
Customizing the Login Prompt
The CLI checks the file
login-banner
for customized text to include in the prompt. Use the copy
command to place a file named
login-banner
in the config directory of the switch. You can do this with
FTP:
copy ftp://user:xxx.x.x.x/my-banner config:login-banner
Entering CLI Modes
The CLI uses the following three command modes:
User Execute mode
Privileged Execute mode
Global Configuration mode
local and then TACAS
Verifies against the chassis database then checks the TACAS client.
TACAS and then local
Checks the TACAS client and then verifies against the chassis
database.
Authentication
How it Works