首页
学习
活动
专区
圈层
工具
发布
社区首页 >问答首页 >Cisco通过TACACS+管理?

Cisco通过TACACS+管理?
EN

Network Engineering用户
提问于 2020-04-01 11:14:07
回答 1查看 628关注 0票数 0

在APIC中,AAA的实现可以从以下途径看到:

代码语言:javascript
复制
APIC > ADMIN > AAA > RADIUS Management > RADIUS Providers
APIC > ADMIN > AAA > TACACS+ Management > TACACS+ Providers

*来自https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/basic-config/b_ACI_配置_指南/b_ACI_配置_指南_第二章_011.html的图像

此命令的等效命令是什么?我需要得到这个信息,包括Host NameDescriptionPort号码和Timeout (sec)设置通过SSH。

代码语言:javascript
复制
APIC# show aaa ?
 authentication  Show AAA Authentication information
 groups          Show AAA group information
APIC# 

APIC# show aaa authentication ?
 <CR>
APIC# show aaa authentication
Default : radius
Console : radius

APIC# show aaa groups ?
 <CR>
APIC# 

APIC# show aaa groups
Total number of Groups: 2

RadiusGroups : XYZ-RADIUS
TacacsGroups : XYZ-TACACS
LdapGroups   :
EN

回答 1

Network Engineering用户

回答已采纳

发布于 2020-04-01 12:42:29

在CLI中,可以运行以下命令:

代码语言:javascript
复制
APIC# show run aaa group server tacacsplus TACACS
# Command: show running-config aaa group server tacacsplus TACACS
# Time: Wed Apr  1 15:27:27 2020
  aaa group server tacacsplus TACACS
    server SERVER-2 priority 10
    server SERVER-1 priority 5
    exit

APIC# show run tacacs-server host "SERVER-2"
# Command: show running-config tacacs-server host SERVER-2
# Time: Wed Apr  1 15:28:05 2020
  tacacs-server host "SERVER-2"
    exit

您可能会注意到,没有显示其他参数,如端口或超时。这是因为它们设置为默认值。

和往常一样,你可以从MO那里得到这个信息。在APIC上运行bash,然后执行curl命令:

代码语言:javascript
复制
icurl -g -X GET 'http://localhost:7777/api/node/class/aaaTacacsPlusProvider.json' | jq '.'

RADIUS:

代码语言:javascript
复制
icurl -g -X GET 'http://localhost:7777/api/node/class/aaaRadiusProvider.json' | jq '.'

TACACS的产出:

代码语言:javascript
复制
{
  "totalCount": "2",
  "imdata": [
    {
      "aaaTacacsPlusProvider": {
        "attributes": {
          "annotation": "",
          "authProtocol": "pap",
          "childAction": "",
          "descr": "",
          "dn": "uni/userext/tacacsext/tacacsplusprovider-SERVER-2",
          "epgDn": "",
          "extMngdBy": "",
          "lcOwn": "local",
          "modTs": "2019-02-11T10:23:19.748+03:00",
          "monPolDn": "uni/fabric/monfab-default",
          "monitorServer": "disabled",
          "monitoringUser": "default",
          "name": "SERVER-2",
          "nameAlias": "",
          "operState": "unknown",
          "ownerKey": "",
          "ownerTag": "",
          "port": "49",
          "retries": "1",
          "snmpIndex": "2",
          "status": "",
          "timeout": "5",
          "uid": "15374",
          "vrfName": ""
        }
      }
    },
    {
      "aaaTacacsPlusProvider": {
        "attributes": {
          "annotation": "",
          "authProtocol": "pap",
          "childAction": "",
          "descr": "",
          "dn": "uni/userext/tacacsext/tacacsplusprovider-SERVER-1",
          "epgDn": "",
          "extMngdBy": "",
          "lcOwn": "local",
          "modTs": "2019-02-11T10:23:14.350+03:00",
          "monPolDn": "uni/fabric/monfab-default",
          "monitorServer": "disabled",
          "monitoringUser": "default",
          "name": "SERVER-1",
          "nameAlias": "",
          "operState": "unknown",
          "ownerKey": "",
          "ownerTag": "",
          "port": "49",
          "retries": "1",
          "snmpIndex": "1",
          "status": "",
          "timeout": "5",
          "uid": "15374",
          "vrfName": ""
        }
      }
    }
  ]
}
票数 2
EN
页面原文内容由Network Engineering提供。腾讯云小微IT领域专用引擎提供翻译支持
原文链接:

https://networkengineering.stackexchange.com/questions/66953

复制
相关文章

相似问题

领券
问题归档专栏文章快讯文章归档关键词归档开发者手册归档开发者手册 Section 归档