Users Guide

Table Of Contents
Usage
Information
Use this command to associate RADIUS servers with a VRF. If you do not configure a VRF on the RADIUS
server list, the servers are on the default VRF. RADIUS server lists and VRFs have one-to-one mapping.
The no version of this command removes the RADIUS server from the management VRF instance.
Example
OS10(config)# radius-server vrf management
OS10(config)# radius-server vrf blue
Supported
Releases
10.4.0E(R1) or later
tacacs-server host
Configures a TACACS+ server and the key used to authenticate the switch on the server.
Syntax
tacacs-server host {hostname | ip-address} key {0 authentication-key | 9
authentication-key | authentication-key} [auth-port port-number]
Parameters
hostname Enter the host name of the TACACS+ server.
ip-address Enter the IPv4 (A.B.C.D) or IPv6 (x:x:x:x::x) address of the TACACS+ server.
key 0 authentication-key Enter an authentication key in plain text. A maximum of 42
characters.
key 9 authentication-key Enter an authentication key in encrypted format with a maximum
of 128 characters.
authentication-key Enter an authentication in plain text with a maximum of 42 characters. It
is not necessary to enter 0 before the key.
key authentication-key Enter a text string for the encryption key used to authenticate the
switch on the TACACS+ server. A maximum of 42 characters.
Default Not configured
Command Mode CONFIGURATION
Usage
Information
The authentication key must match the key configured on the TACACS+ server. You cannot enter spaces
in the key. The show running-configuration output displays both unencrypted and encrypted
keys in encrypted format. Configure the global timeout allowed for authentication requests on TACACS+
servers using the tacacs-server timeout command. By default, OS10 times out an authentication
attempt on a TACACS+ server after five seconds.
Supported on the MX9116n and MX5108n switches in Full Switch mode starting in release 10.4.0E(R3S).
Also supported in SmartFabric mode starting in release 10.5.0.1.
The no version of this command removes a TACACS+ server configuration.
Example
OS10(config)# tacacs-server host 1.5.6.4 key secret1
Supported
Releases
10.4.0E(R2) or later
tacacs-server timeout
Configures the global timeout used for authentication attempts on TACACS+ servers.
Syntax
tacacs-server timeout seconds
Parameters seconds Enter the timeout period used to wait for an authentication response from a TACACS+
server, from 1 to 1000 seconds.
Default 5 seconds
Command Mode CONFIGURATION
Usage
Information
Supported on the MX9116n and MX5108n switches in Full Switch mode starting in release 10.4.0E(R3S).
Also supported in SmartFabric mode starting in release 10.5.0.1.
1030 Security