Identifying the TACACS+ Servers

To use TACACS+ servers to authenticate access to a RUCKUS device, you must identify the servers to the RUCKUS device.

To identify a TACACS+ server, enter the tacacs-server host command followed by the address or name of the server as shown in the following example, which identifies three TACACS+ servers.

device# configure terminal
device(config)# tacacs-server host 10.94.6.161
device(config)# tacacs-server host 10.94.6.191
device(config)# tacacs-server host 10.94.6.122

An IP address, IPv6 address, or hostname can be used to designate the server. You can enter up to eight tacacs-server host commands to specify up to eight different servers.

Note: To specify the server's host name instead of its IP address, you must first identify a DNS server using the ip dns server-address command as shown in the following example.
device# configure terminal
device(config)# ip dns server-address 10.94.6.161
device(config)# tacacs-server host frog

If you add multiple TACACS+ authentication servers to the RUCKUS device, the device tries to reach them in the order you add them. For the previous example, the software tries the servers in the following order.

  • 10.94.6.161
  • 10.94.6.191
  • 10.94.6.122

You can remove a TACACS+ server by entering no followed by the tacacs-server command. For example, to remove 10.94.6.161, enter the following command.

device(config)# no tacacs-server host 10.94.6.161
Note: If you remove a TACACS+ server with the no tacacs-server command, make sure you also erase any related aaa commands that specify TACACS+ as an authentication method. Otherwise, when you exit from configuration mode or from a Telnet session, the system continues to try TACACS+ authentication, and you will not be able to access the system.