Jump to content

Recommended Posts

Posted

В документации про конфигурацию tacacs упомянуто лишь вскольз.

 

Конфиг:

aaa authentication login default group external
...
aaa group server tacacs+ external
server 10.11.0.4 key XXXXXXXXXXXXXXXX

 

Пытаемся соединиться:

> telnet 10.10.29.1
Trying 10.10.29.1...
Connected to 10.10.29.1.
Escape character is '^]'.

Authentication failed!


Authentication failed!


Authentication failed!

Connection closed by foreign host.

 

Журнал:

Jan 23 12:08:09 User default logouted from 192.168.0.155 on vty 0
Jan 23 12:08:09 %SYS-5-AUTH: User  Authorization failed(from 192.168.0.155)
Jan 23 12:08:09 @(UM): Server qid not existed
Jan 23 12:08:09 %SYS-5-AUTH: User  Authorization failed(from 192.168.0.155)
Jan 23 12:08:09 @(UM): Server qid not existed
Jan 23 12:08:09 %SYS-5-AUTH: User  Authorization failed(from 192.168.0.155)
Jan 23 12:08:09 @(UM): Server qid not existed

 

Дебаг:

Jan 23 12:23:27 AAA/AUTHEN(1438): status = START
Jan 23 12:23:27 AAA/AUTHEN(1438): action = LOGIN
Jan 23 12:23:27 AAA/AUTHEN(1438): authen_type = LOGIN
Jan 23 12:23:27 AAA/AUTHEN(1438): Using 'default' method list
Jan 23 12:23:27 AAA/AUTHEN(1438): Method = GROUP(TACACS+)
Jan 23 12:23:27 AAA: TACACS+ server qid error!
Jan 23 12:23:27 @(UM): Server qid not existed
Jan 23 12:23:27 AAA/AUTHEN(1438): try next method
Jan 23 12:23:27 AAA/AUTHEN(1438): no methods left to try
Jan 23 12:23:27 AAA/AUTHEN(1438): status = FAIL
Jan 23 12:23:27 %SYS-5-AUTH: User  Authorization failed(from 192.168.0.155)

 

При этом попыток обращения к tacacs серверу нет. Что я делаю не так?

Posted

Добрый день.

 

aaa authentication login default group tacacs+ local
aaa authorization exec default group tacacs+ local

tacacs-server host 192.168.1.5 key 0 xxxxxxxx

switch_config#tacacs-server host 192.168.1.5 key 0 xxxxxxxx
tacacs-server host 192.168.1.5 key 0 xxxxxxxx
^
Unknown command

Posted
#sh ver
NAG LLC. Internetwork Operating System Software
SNR-S2970G-48S Series Software, Version 2.1.0A Build 5721, RELEASE SOFTWARE
Copyright (c) 2012 by NAG
Compiled: 2011-11-1 15:57:26 by SYS_5721, Image text-base: 0x80008000
ROM: System Bootstrap, Version 0.3.8
Serial num:S25060868, ID num:S25060868
System image file is "Switch.bin"
NAG SNR-S2970G-48S RISC
65536K bytes of memory,8192K bytes of flash
Base ethernet MAC Address: 00:e0:0f:a4:3a:cf
snmp info:
 product_ID:143   system_ID:1.3.6.1.4.1.3320.1.143.0
sw001 uptime is 164:05:20:31, The current time: 2013-1-24 12:4:48

Posted

Добрый день.

Извиняюсь, что пишу не по теме поста.

Проблема сходная, надо переходить на Version 2.1.0С, но не хотелось бы наткнутся на проблему с bootrom.

Можно по подробней про необходимость обновления bootrom?

Сейчас -

Switch#sh ver
NAG LLC. Internetwork Operating System Software
SNR-S2970G-48S Series Software, Version 2.1.0A Build 5721, RELEASE SOFTWARE
Copyright (c) 2011 by NAG
Compiled: 2011-11-1 15:57:26 by SYS_5721, Image text-base: 0x80008000
ROM: System Bootstrap, Version 0.3.7
Serial num:S25060679, ID num:S25060679
System image file is "Switch.bin"
NAG SNR-S2970G-48S RISC
65536K bytes of memory,8192K bytes of flash
Base ethernet MAC Address: 00:e0:0f:a4:16:a2
snmp info:
 product_ID:143   system_ID:1.3.6.1.4.1.3320.1.143.0
Switch uptime is 209:14:43:59, The current time: 2013-1-24 15:12:57

  • 2 months later...

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...
На сайте используются файлы cookie и сервисы аналитики для корректной работы форума и улучшения качества обслуживания. Продолжая использовать сайт, вы соглашаетесь с использованием файлов cookie и с Политикой конфиденциальности.