TACACS認証
-
「clear ns config」コマンドを実行するときは、TACACS関連の設定を変更しないことをお勧めします。
-
詳細ポリシーの「clear ns config」コマンドで「RBAConfig」パラメータが NO に設定されている場合、詳細ポリシーに関連する TACACS 関連の設定はクリアされ、再適用されます。
TACACS 認証用の名前/値属性のサポート
-
TACACSaction コマンドでは、最大 64 個の属性をカンマで区切って設定でき、合計サイズは 2048 バイト未満です。
CLI を使用して名前と値の属性を設定するには
add authentication tacacsAction <name> [-Attributes <string>]
add authentication tacacsAction tacacsAct1 -attributes “mail,sn,userprincipalName”
コマンドラインインターフェイスを使用して認証アクションを追加するには
add authentication tacacsAction <name> -serverip <IP> [-serverPort <port>][-authTimeout <positive_integer>][ ... ]
add authentication tacacsaction Authn-Act-1 -serverip 10.218.24.65 -serverport 1812 -authtimeout 15 -tacacsSecret "minotaur" -authorization OFF -accounting ON -auditFailedCmds OFF -defaultAuthenticationGroup "users"
コマンドラインインターフェイスを使用して認証アクションを設定するには
set authentication tacacsAction <name> -serverip <IP> [-serverPort <port>][-authTimeout <positive_integer>][ ... ]
> set authentication tacacsaction Authn-Act-1 -serverip 10.218.24.65 -serverport 1812 -authtimeout 15 -tacacsSecret "minotaur" -authorization OFF -accounting ON -auditFailedCmds OFF -defaultAuthenticationGroup "users" Done
コマンドラインインターフェイスを使用して認証アクションを削除するには
rm authentication radiusAction <name>
rm authentication tacacsaction Authn-Act-1