Administrator Guide

Security Commands 958
If no encryption parameter is present, the key string is interpreted as an un-
encrypted shared secret.
Keys are always displayed in their encrypted form in the running
configuration.
In an Access-Request, encrypted passwords are sent using the RSA Message
Digest algorithm (MD5). MD5 always transmits the encrypted password in 32
characters.
The encryption algorithm is the same across switches. Encrypted passwords
may be copied from one switch and pasted into another switch and will send
the same MD5 encrypted password over the wire.
Command History
Updated in version 6.3.0.1 firmware.
Example
The following example sets the authentication encryption key.
console(config)#key “This is a key string”
console(config)#key 0 “This is a key string”
port
Use the port command in TACACS Configuration mode to specify a port
number on which a TACACS server listens for connections.
Syntax
port [port-number]
port-number
— The server port number. If left unspecified, the default
port number is 49. (Range: 0–65535)
Default Configuration
The default port number is 49.
Command Mode
TACACS Configuration mode
2CSNXXX_SWUM204.book Page 958 Monday, January 25, 2016 1:25 PM