AOS-CX 10.13 Security Guide | (832x, 8400, 9300, 10000 Switch Series) 5
TACACS+ authentication 92
About authentication fail-through 93
TACACS+ authentication tasks 93
TACACS+ authorization 94
Using local authorization as fallback from TACACS+ authorization 94
About authentication fail-through and authorization 94
TACACS+ authorization tasks 94
TACACS+ accounting 95
Sample accounting information on a TACACS+ server 95
Sample REST accounting information on a TACACS+ server 96
TACACS+ accounting tasks 96
Example: Configuring the switch for Remote AAA with TACACS+ 97
Remote AAA with RADIUS 100
Parameters for RADIUS server 100
Default server groups 101
Supported platforms and standards 102
About global versus per-RADIUS server passkeys (shared secrets) 103
Remote AAA RADIUS server configuration requirements 103
User role assignment using RADIUS attributes 103
RADIUS server redundancy and access sequence 104
Configuration task list 104
Single source IP address for consistent source identification to AAA servers 105
RADIUS general tasks 106
Per-port RADIUS server group configuration 107
RADIUS authentication 107
About authentication fail-through 107
RADIUS authentication tasks 108
Two-factor authentication 109
Configuring two-factor authentication (for local users) 109
Configuring two-factor authentication with SSH (for remote-only users) 110
Configuring two-factor authentication with HTTPS server and REST (for remote-only
users) 113
Two-factor authentication commands 116
aaa authorization radius 116
https-server authentication certificate 117
ssh certificate-as-authorized-key 118
ssh two-factor-authentication 119
Secure RADIUS (RadSec) 120
RadSec configuration 121
Deployment scenarios 121
RadSec example configuration 122
RADIUS accounting 124
Sample general accounting information 124
RADIUS accounting tasks 126
Example: Configuring the switch for Remote AAA with RADIUS 127
Remote AAA (TACACS+, RADIUS) commands 129
aaa accounting allow-fail-through 129
aaa accounting all-mgmt 129
aaa authentication allow-fail-through 132
aaa authentication login 133
aaa authorization allow-fail-through 135
aaa authorization commands 137
aaa group server 140
radius-server auth-type 141