tacacs-server enable
By default, access is allowed on all ports.
Global configuration mode
You can restrict management access to a device to ports within a specific port-based VLAN. VLAN-based access control works in conjunction with other access control methods. Clients connected to ports that are not in the VLAN are denied management access.
As in a switched network, the TACACS server and the SSH client should be included
in the same VLAN. Otherwise, the response expected from the TACACS server should be
sent in the same VLAN configured by the
tacacs-server enable vlan command. This configuration allows the TACACS server to be in a different VLAN and
still allow SSH connections in a routed network.
The
tacacs-server enable vlan command should not be configured in a network that uses dynamic routing, where the
TACACS server response might be routed on any path.