C H A P T E R
5
Configuring
This chapter describes how to configure the Terminal Access Controller Access Control System Plus
() protocol on Cisco NX-OS devices.
This chapter includes the following sections:
•
•
Licensing Requirements for , on page 71
•
Prerequisites for , on page 71
•
Guidelines and Limitations for , on page 71
•
Default Settings for , on page 72
•
•
Monitoring Servers, on page 99
•
Clearing Server Statistics, on page 99
•
Verifying the Configuration, on page 100
•
Configuration Examples for , on page 100
•
Where to Go Next , on page 102
•
Additional References for , on page 102
About
The security protocol provides centralized validation of users attempting to gain access to a Cisco
NX-OS device. services are maintained in a database on a daemon running, typically,
on a UNIX or Windows NT workstation. You must have access to and must configure a server
before the configured features on your Cisco NX-OS device are available.
provides for separate authentication, authorization, and accounting facilities. allows
for a single access control server (the daemon) to provide each service—authentication,
authorization, and accounting—independently. Each service can be tied into its own database to take advantage
of other services available on that server or on the network, depending on the capabilities of the daemon.
The client/server protocol uses TCP (TCP port 49) for transport requirements. Cisco NX-OS
devices provide centralized authentication using the protocol.
Advantages
has the following advantages over RADIUS authentication:
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
67