BLADE OS™ ISCLI Reference HP GbE2c L2/L3 Ethernet Blade Switch Version 5.1 Advanced Functionality Software

BLADE OS 5.1 ISCLI Reference
BMD00115, August 2009 Chapter 4: Configuration Commands
183
Note – If TACACS+ is enabled, you must login using TACACS+ authentication when connecting
via the console or Telnet/SSH/HTTP/HTTPS. Backdoor for console is always enabled, so you can
connect using notacacs and the administrator password even if the backdoor (telnet) or
secure backdoor (secbd) are disabled.
If backdoor is enabled, type in notacacs as a backdoor to bypass TACACS+ checking, and use
the administrator password to log into the switch. The switch allows this even if TACACS+ servers
are available.
If secure backdoor is enabled, type in notacacs as a backdoor to bypass TACACS+ checking,
and use the administrator password to log into the switch. The switch allows this only if TACACS+
servers are not available.
[no] tacacs-server command-logging
Enables or disables TACACS+ command logging.
Command mode: Global configuration
[no] tacacs-server directed-request [restricted|no-truncate]
Enables or disables TACACS+ directed request, which uses a specified TACACS+ server for
authentication, authorization, accounting. When enabled, When directed-request is enabled,
each user must add a configured TACACS+ server hostname to the username (for example,
username@hostname) during login.
This command allows the following options:
Restricted: Only the username is sent to the specified TACACS+ server.
No-truncate: The entire login string is sent to the TACACS+ server.
[no] tacacs-server enable
Enables or disables the TACACS+ server. By default, the server is disabled.
Command mode: Global configuration
show tacacs-server
Displays current TACACS+ configuration parameters.
Command mode: All
Table 92 TACACS+ Server Commands
Command Syntax and Usage