tacacs-server enable

Configures the device to allow TACACS server management access only to clients connected to ports within port-based VLAN.
Syntax
tacacs-server enable vlan vlan-number
no tacacs-server enable vlan vlan-number
Command Default

By default, access is allowed on all ports.

Parameters
vlan vlan-number
Configures access only to clients connected to ports within the VLAN.
Modes

Global configuration mode

Usage Guidelines

You can restrict management access to a device to ports within a specific port-based VLAN. VLAN-based access control works in conjunction with other access control methods. Clients connected to ports that are not in the VLAN are denied management access.

As in a switched network, the TACACS server and the SSH client should be included in the same VLAN. Otherwise, the response expected from the TACACS server should be sent in the same VLAN configured by the tacacs-server enable vlan command. This configuration allows the TACACS server to be in a different VLAN and still allow SSH connections in a routed network.

The tacacs-server enable vlan command should not be configured in a network that uses dynamic routing, where the TACACS server response might be routed on any path.

The no form of the command removes the restriction.

Examples

The following example shows how to allow TACACS server access only to clients in a specific VLAN.

device(config)# tacacs-server enable vlan 10