tacacs-server host
tacacs-server host
{
ipv4-address
|
host-name
|
ipv6-address
}
[
auth-port
port-num
[
authentication-only
|
authorization-only
|
accounting-only
|
default
]
]
[
key
key-string
]
no tacacs-server host
{
ipv4-address
|
host-name
|
ipv6-address
}
[
auth-port
port-num
[
authentication-only
|
authorization-only
|
accounting-only
|
default
]
]
[
key
key-string
]
The TACACS server host is not configured.
Global configuration mode
You can specify up to eight servers. If you add multiple TACACS or TACACS+ authentication servers to the device, the device tries to reach them in the order you add them. You can designate a server to handle a specific AAA task. For example, you can designate one TACACS+ server to handle authorization and another TACACS+ server to handle accounting. You can set the TACACS key for each server.
The
tacacs-server key
command and the
tacacas-sever host key parameter apply only to TACACS+ servers, not to TACACS servers. If you are configuring
TACACS, do not configure a key on the TACACS server and do not enter a key on the
Ruckus device.
The following example shows how to configure a TACACS server to authenticate access to a device.
device# configure terminal device(config)# tacacs-server host 192.168.10.1
The following example shows how to specify different TACACS servers for authentication, authorization, and accounting.
device# configure terminal device(config)# tacacs-server host 10.2.3.4 auth-port 1800 default key abc device(config)# tacacs-server host 10.2.3.5 auth-port 1800 authentication-only key def device(config)# tacacs-server host 10.2.3.6 auth-port 1800 authorization-only key def device(config)# tacacs-server host 10.2.3.7 auth-port 1800 accounting-only key ghi