HP GbE2c HP GbE2c Ethernet Blade Switch for c-Class BladeSystem Browser-based - Page 122

Switch TACACS+ Configuration controls, Table 95, IMPORTANT

Page 122 highlights

The following table describes Switch TACACS+ Configuration controls: Table 95 Switch TACACS+ Configuration controls Control Description Primary Tacacs+ IP Address Secondary Tacacs+ IP Address Tacacs+ port (1-65000) Tacacs+ timeout (4-15) Tacacs+ retries (1-3) Enable/Disable Tacacs+ Server Enable/Disable Tacacs+ Backdoor for telnet Enable/Disable Tacacs+ new privilege level mapping Tacacs+ Secret Secondary Tacacs+ Server Secret Tacacs+ User Mappings Configuration Configures the primary TACACS+ server address. Configures the secondary TACACS+ server address. Configures the number of the TCP port to be configured, between 1 and 65000. The default is 49. Configures the amount of time, in seconds, before a TACACS+ server authentication attempt is considered to have failed. The default timeout is 5 seconds. Configures the number of failed authentication requests before switching to a different TACACS+ server. The default retry count is 3 requests. Enables or disables the Tacacs+ server. Enables or disables the Tacacs+ backdoor for telnet. Telnet also applies to SSH/SCP connections. Enables or disables TACACS+ privilege-level mapping. The default value is disabled. Configures the shared secret (up to 32 characters) between the switch and the TACACS+ server. Configures the secondary shared secret (up to 32 characters) between the switch and the TACACS+ server. Maps a TACACS+ privilege level to a GbE2c user level, as follows: Remote Privilege Enter a TACACS+ privilege level (0-15) Local Privilege Select the corresponding GbE2c user level. IMPORTANT: If TACACS+ is enabled, you must login using TACACS+ authentication when connecting via the console or Telnet/SSH/HTTP/HTTPS. Backdoor for console is always enabled, so you can connect using notacacs and the administrator password even if the backdoor (telnet) or secure backdoor (secbd) are disabled. If Telnet backdoor is enabled (telnet ena), type in notacacs as a backdoor to bypass TACACS+ checking, and use the administrator password to log into the switch. The switch allows this even if TACACS+ servers are available. If secure backdoor is enabled (secbd ena), type in notacacs as a backdoor to bypass TACACS+ checking, and use the administrator password to log into the switch. The switch allows this only if TACACS+ servers are not available. Configuring the switch 122

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209

Configuring the switch 122
The following table describes Switch TACACS+ Configuration controls:
Table 95
Switch TACACS+ Configuration controls
Control
Description
Primary Tacacs+ IP Address
Configures the primary TACACS+ server address.
Secondary Tacacs+ IP Address
Configures the secondary TACACS+ server address.
Tacacs+ port (1-65000)
Configures the number of the TCP port to be configured, between 1 and
65000. The default is 49.
Tacacs+ timeout (4-15)
Configures the amount of time, in seconds, before a TACACS+ server
authentication attempt is considered to have failed. The default timeout is
5 seconds.
Tacacs+ retries (1-3)
Configures the number of failed authentication requests before switching
to a different TACACS+ server. The default retry count is 3 requests.
Enable/Disable Tacacs+ Server
Enables or disables the Tacacs+ server.
Enable/Disable Tacacs+ Backdoor for telnet
Enables or disables the Tacacs+ backdoor for telnet. Telnet also applies
to SSH/SCP connections.
Enable/Disable Tacacs+ new privilege level
mapping
Enables or disables TACACS+ privilege-level mapping.
The default value is
disabled
.
Tacacs+ Secret
Configures the shared secret (up to 32 characters) between the switch
and the TACACS+ server.
Secondary Tacacs+ Server Secret
Configures the secondary shared secret (up to 32 characters) between the
switch and the TACACS+ server.
Tacacs+ User Mappings Configuration
Maps a TACACS+ privilege level to a GbE2c user level, as follows:
Remote Privilege
Enter a TACACS+ privilege level (0-15)
Local Privilege
Select the corresponding GbE2c user level.
IMPORTANT:
If TACACS+ is enabled, you must login using TACACS+ authentication when connecting via the
console or Telnet/SSH/HTTP/HTTPS. Backdoor for console is always enabled, so you can connect using
notacacs
and the administrator password even if the backdoor (
telnet
) or secure backdoor (
secbd
) are
disabled.
If Telnet backdoor is enabled (
telnet ena
), type in
notacacs
as a backdoor to bypass TACACS+
checking, and use the administrator password to log into the switch. The switch allows this even if TACACS+
servers are available.
If secure backdoor is enabled (
secbd ena
), type in
notacacs
as a backdoor to bypass TACACS+
checking, and use the administrator password to log into the switch. The switch allows this only if TACACS+
servers are
not available.