Configuration Guide User guide

1458 BigIron RX Series Configuration Guide
53-1002484-04
Security/Management
E
TACACS and TACACS+
Telnet access
ip ssl port <port-number> “Specifying a port for SSL communication” on
page 74
ip ssl private-key-file tftp
<ip-addr> <key-filename> “Importing digital certificates and RSA private key
files” on page 74
web-management https “Enabling the SSL server on the device” on page 74
Commands See ...
aaa accounting commands <privilege-level> default
start-stop tacacs+ | none
“Configuring TACACS+ accounting for CLI commands”
on page 88
aaa accounting exec default
start-stop tacacs+ | none
“Configuring TACACS+ accounting for Telnet/SSH
(Shell) access” on page 88
aaa accounting system default start-stop tacacs+ | none “Configuring TACACS+ accounting for system events”
on page 88
aaa authentication enable implicit-user “Configuring Enable authentication to prompt for
password only” on page 84
aaa authentication login privilege-mode “Entering privileged EXEC mode after a Telnet or SSH
login” on page 84
aaa authorization commands
<privilege-level> default
tacacs+ | none
“Configuring command authorization on page 87
aaa authorization exec default tacacs+ | none “Configuring Exec authorization” on page 85
enable aaa console “AAA support for console commands” on page 87
show aaa “Displaying TACACS and TACACS+ statistics and
configuration information” on page 89
tacacs-server dead-time
<number> “Setting the dead time parameter” on page 83
tacacs-server host
<ip-addr> | <server-name> [auth-port
<number> [authentication-only | authorization-only |
accounting-only | default] [key
<string>]]
“Specifying different servers for individual AAA
functions” on page 81
tacacs-server key [0 | 1]
<string> “Setting the TACACS+ key” on page 82
tacacs-server retransmit
<number> “Setting the retransmission limit” on page 82
tacacs-server timeout
<number> “Setting the timeout parameter” on page 83
Commands See ...
telnet access-group <num> | <name> “Using an ACL to restrict Telnet access” on page 56
telnet client
<ip-addr> “Restricting Telnet access to a specific IP address” on
page 59
telnet login-retries
<number> “Specifying the maximum number of login attempts
for Telnet access” on page 60
Commands See ...