Users Guide

268 Authentication, Authorization, and Accounting
subscriber:command=disable-host-port (COA only)
FILTER-ID
Name of an existing ACL or DiffServ policy for this user. Names ending
with an ".in" suffix are ACLs.
FRAMED-IP-ADDRESS
The IP address assigned to the host accessing the network. Cached and
transmitted in accounting packets.
FRAMED-IPv6-ADDRESS
The IPv6 address assigned to the host accessing the network. Cached and
transmitted in accounting packets.
TUNNEL-TYPE
Used to indicate that a VLAN is to be assigned to the user when set to
tunnel type VLAN (13).
TUNNEL-MEDIUM-TYPE
Used to indicate the tunnel medium type. Must be set to medium type
802 (6) to enable VLAN assignment.
TUNNEL-PRIVATE-GROUP-ID
Used to indicate the VLAN to be assigned to the user. May be a string
which matches a preconfigured VLAN name or a VLAN ID. If a VLAN ID
is given, the string must contain only decimal digits.
Using TACACS+ Servers to Control Management Access
TACACS+ (Terminal Access Controller Access Control System) provides
access control for networked devices via one or more centralized servers.
TACACS+ simplifies authentication by making use of a single database that
can be shared by many clients on a large network. TACACS+ uses TCP to
ensure reliable delivery and a shared key configured on the client and daemon
server to encrypt all messages.
If TACACS+ is configured as the authentication method for user login and a
user attempts to access the user interface on the switch, the switch prompts
for the user login credentials and requests services from the TACACS+
client. The client then uses the configured list of servers for authentication,
and provides results back to the switch.