33-24
To do…
Use the command…
Remarks
Required
Set the IP address and port
number of the primary
TACACS authentication server
By default, the IP address of
the primary authentication
server is 0.0.0.0, and the port
number is 0.
primary authentication
ip-address
[
port
]
Optional
Set the IP address and port
number of the secondary
TACACS authentication server
By default, the IP address of
the secondary authentication
server is 0.0.0.0, and the port
number is 0.
secondary authentication
ip-address
[
port
]
z
You are not allowed to configure the same IP address for both primary and secondary
authentication servers. If you do this, the system will prompt that the configuration fails.
z
You can remove an authentication server setting only when there is no active TCP connection that
is sending authentication messages to the server.
Configuring TACACS Authorization Servers
Follow these steps to configure TACACS authorization servers:
To do…
Use the command…
Remarks
Enter system view
—
system-view
Required
Create a HWTACACS scheme
and enter its view
hwtacacs scheme
hwtacacs-scheme-name
By default, no HWTACACS
scheme exists.
Required
Set the IP address and port
number of the primary
TACACS authorization server
By default, the IP address of
the primary authorization
server is 0.0.0.0, and the port
number is 0.
primary authorization
ip-address
[
port
]
Optional
Set the IP address and port
number of the secondary
TACACS authorization server
By default, the IP address of
the secondary authorization
server is 0.0.0.0, and the port
number is 0.
secondary authorization
ip-address
[
port
]