tacacs-server host

Configures the TACACS/TACACS+ server host to authenticate access to a device.
Syntax
tacacs-server host { ipv4-address | host-name | ipv6-address } [ auth-port port-num [ authentication-only | authorization-only | accounting-only | default ] ] [ ke ykey-string ]
no tacacs-server host{ ipv4-address | host-name | ipv6-address } [ auth-port port-num [ authentication-only | authorization-only | accounting-only | default ] ] [ ke ykey-string ]
Command Default

The TACACS server host is not configured.

Parameters
ipv4-address
Configures the IPv4 address of the TACACS server.
host-name
Configures the host name of the TACACS server.
ipv6-address
Configures the IPv6 address of the TACACS server.
auth-port port-num
Configures the authentication port. The default value is 1812.
default
Configures the server to be used for any AAA operation. Supported for TACACS+ only.
accounting-only
Configures the server to be used only for accounting. Supported for TACACS+ only.
authentication-only
Configures the server to be used only for authentication. Supported for TACACS+ only.
authorization-only
Configures the server to be used only for authorization. Supported for TACACS+ only.
key key-string
Configures the TACACS key for the server. Supported for TACACS+ only. The key string can be from 1 to 32 characters in length. The string must not contain a space or any of the following characters: #, {, or }.
Modes

Global configuration mode

Usage Guidelines

You can specify up to eight servers. If you add multiple TACACS or TACACS+ authentication servers to the device, the device tries to reach them in the order you add them. You can designate a server to handle a specific AAA task. For example, you can designate one TACACS+ server to handle authorization and another TACACS+ server to handle accounting. You can set the TACACS key for each server.

The tacacs-server key command and the tacacas-sever host key parameter apply only to TACACS+ servers, not to TACACS servers. If you are configuring TACACS, do not configure a key on the TACACS server and do not enter a key on the Ruckus device.

The no form of this command removes the configuration.

Examples

The following example shows how to configure a TACACS server to authenticate access to a device.

device# configure terminal
device(config)# tacacs-server host 192.168.10.1

The following example shows how to specify different TACACS servers for authentication, authorization, and accounting.

device# configure terminal
device(config)# tacacs-server host 10.2.3.4 auth-port 1800 default key abc
device(config)# tacacs-server host 10.2.3.5 auth-port 1800 authentication-only key def
device(config)# tacacs-server host 10.2.3.6 auth-port 1800 authorization-only key def
device(config)# tacacs-server host 10.2.3.7 auth-port 1800 accounting-only key ghi
History
Release version Command history
10.0.10 This command was modified to remove the following characters from keykey-string syntax: #, {, and }.