HP GbE2c HP GbE2c Ethernet Blade Switch for c-Class BladeSystem ISCLI Referenc - Page 86

NTP server configuration, user|oper|admin}

Page 86 highlights

Table 79 TACACS+ Server Configuration commands Command [no] tacacs-server telnet-backdoor [no] tacacs-server secure-backdoor [no] tacacs-server privilege-mapping tacacs-server user-mapping { user|oper|admin} tacacs-server enable no tacacs-server enable show tacacs-server Description Enables or disables the TACACS+ back door for telnet. The telnet command also applies to SSH/SCP connections and the Browser-based Interface (BBI). This command does not apply when secure backdoor (secbd) is enabled. Command mode: Global configuration Enables or disables the TACACS+ back door using secure password for telnet/SSH/ HTTP/HTTPS. This command does not apply when backdoor (telnet) is enabled. Command mode: Global configuration Enables or disables TACACS+ privilege-level mapping. The default value is disabled. Command mode: Global configuration Maps a TACACS+ authorization level to a GbE2c user level. Enter a TACACS+ privilege level (0-15), followed by the corresponding GbE2c user level (user, oper, admin). Command mode: Global configuration Enables the TACACS+ server. Command mode: Global configuration Disables the TACACS+ server. Command mode: Global configuration Displays current TACACS+ configuration parameters. Command mode: All IMPORTANT: If TACACS+ is enabled, you must login using TACACS+ authentication when connecting via the console or Telnet/SSH/HTTP/HTTPS. Backdoor for console is always enabled, so you can connect using notacacs and the administrator password even if the backdoor (telnet) or secure backdoor (secbd) are disabled. If Telnet backdoor is enabled (telnet ena), type in notacacs as a backdoor to bypass TACACS+ checking, and use the administrator password to log into the switch. The switch allows this even if TACACS+ servers are available. If secure backdoor is enabled (secbd ena), type in notacacs as a backdoor to bypass TACACS+ checking, and use the administrator password to log into the switch. The switch allows this only if TACACS+ servers are not available. NTP server configuration These commands enable you to synchronize the switch clock to a Network Time Protocol (NTP) server. By default, this option is disabled. The following table describes the NTP Server Configuration commands. Table 80 NTP Server Configuration commands Command [no] ntp prisrv [no] ntp secsrv ntp interval Description Prompts for the IP addresses of the primary NTP server to which you want to synchronize the switch clock. For example, 100.10.1.1 Command mode: Global configuration Prompts for the IP addresses of the secondary NTP server to which you want to synchronize the switch clock. For example, 100.10.1.2 Command mode: Global configuration Specifies the interval, in minutes (1-44640), to resynchronize the switch clock with the NTP server. The default is 1440 seconds. Command mode: Global configuration Configuration Commands 86

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153

Configuration Commands 86
Table 79
TACACS+ Server Configuration commands
Command
Description
[no] tacacs-server telnet-backdoor
Enables or disables the TACACS+ back door for telnet. The
telnet
command also applies to
SSH/SCP connections and the
Browser-based Interface (BBI). This command does not apply when
secure backdoor (
secbd
) is enabled.
Command mode
: Global configuration
[no] tacacs-server secure-backdoor
Enables or disables the TACACS+ back door using secure
password for telnet/SSH/ HTTP/HTTPS. This command does not
apply when backdoor (
telnet
) is
enabled
.
Command mode
: Global configuration
[no] tacacs-server privilege-mapping
Enables or disables TACACS+ privilege-level mapping.
The default value is
disabled
.
Command mode
: Global configuration
tacacs-server user-mapping {<
0-15
>
user|oper|admin}
Maps a TACACS+ authorization level to a GbE2c user level. Enter
a TACACS+ privilege level (0-15), followed by the corresponding
GbE2c user level (user, oper, admin).
Command mode
: Global configuration
tacacs-server enable
Enables the TACACS+ server.
Command mode
: Global configuration
no tacacs-server enable
Disables the TACACS+ server.
Command mode
: Global configuration
show tacacs-server
Displays current TACACS+ configuration parameters.
Command mode
: All
IMPORTANT:
If TACACS+ is enabled, you must login using TACACS+ authentication when connecting via the
console or Telnet/SSH/HTTP/HTTPS. Backdoor for console is always enabled, so you can connect using
notacacs
and the administrator password even if the backdoor (
telnet
) or secure backdoor (
secbd
) are
disabled.
If Telnet backdoor is enabled (
telnet ena
), type in
notacacs
as a backdoor to bypass TACACS+
checking, and use the administrator password to log into the switch. The switch allows this even if TACACS+
servers are available.
If secure backdoor is enabled (
secbd ena
), type in
notacacs
as a backdoor to bypass TACACS+ checking,
and use the administrator password to log into the switch. The switch allows this only if TACACS+ servers are
not available.
NTP server configuration
These commands enable you to synchronize the switch clock to a Network Time Protocol (NTP) server. By default, this
option is disabled.
The following table describes the NTP Server Configuration commands.
Table 80
NTP Server Configuration commands
Command
Description
[no] ntp prisrv
<IP address>
Prompts for the IP addresses of the primary NTP server to which you
want to synchronize the switch clock. For example, 100.10.1.1
Command mode
: Global configuration
[no] ntp secsrv
<IP address>
Prompts for the IP addresses of the secondary NTP server to which you
want to synchronize the switch clock. For example, 100.10.1.2
Command mode
: Global configuration
ntp interval
<1-44640>
Specifies the interval, in minutes (1-44640), to resynchronize the switch
clock with the NTP server. The default is 1440 seconds.
Command mode
: Global configuration