9-70
Cisco MGX 8850 (PXM1E/PXM45), Cisco MGX 8950, Cisco MGX 8830, and Cisco MGX 8880 Configuration Guide
Release 5.0.10, OL-3845-01 Rev. B0, August 16, 2004
Chapter 9 Switch Operating Procedures
Managing Remote (TACACS+) Authentication and Authorization
Replace the authorType variable with group to select group mode or with command to select command
mode. As with the cnfaaa-authen command, you can specify up to three methods (see Table 9-30) for
authorization, and the switch will use these methods in the configured order. As with authentication, the
local method is not a practical substitute for AAA server authorization because it requires data entry in
the AAA server and every supported switch.
The following example configures the switch to use group mode for authorization:
M8830_SF.2.PXM.a > cnfaaa-author group tacacs+
AAA CONFIGURATION:
Authentication Methods : tacacs+ cisco
Authorization Methods : tacacs+ cisco
Authorization Type : group
Default Privilege Level : NOUSER_GP
Prompt Display : acs
SSH/FTP Message Type : Inbound ASCII Login
IOS Exclusion List :
WARNING: The newly configured authentication/authorization methods will
apply to new session. This configuration has no impact on existing sessions.
Configuring FTP and SSH Messaging Format for AAA Servers
When the switch configuration uses an AAA server for authentication and authorization, FTP and SSH
requests are directed to the remote server. The TACACS+ message format for these requests can be either
ASCII or PAP.
One special application of the FTP and SSH messaging format applies when the AAA server is
configured to issue challenges, which are not supported by FTP and SSH. In this application, the PAP
message format should be configured.
To select the messaging format, log in using a username with SERVICE_GP privileges or higher and
enter the cnfaaa-ftpssh command in the following format:
M8850_LA.7.PXM.a > cnfaaa-ftpssh <ascii|pap|default>
Enter the ascii keyword to select TACACS+ ASCII login messages. Enter the pap keyword to select
TACACS+ PAP login messages. The default keyword selects TACACS+ ASCII login messages.
The following example selects the PAP message format:
M8830_SF.2.PXM.a > cnfaaa-ftpssh pap
AAA CONFIGURATION:
Authentication Methods : tacacs+ cisco
Authorization Methods : local cisco
Authorization Type : group
Default Privilege Level : NOUSER_GP
Prompt Display : acs
SSH/FTP Message Type : Inbound PAP Login
IOS Exclusion List :
Comments to this Manuals