04-01-2016 06:37 AM - edited 03-10-2019 11:38 PM
I have been tasked to setup a bunch of remotes sites to a different AAA/TACACS server.
Can I run the old settings and the new settings on a router without any conflicts?
What issues could I run into?
04-01-2016 06:50 AM
I'm not sure I understand your question.
You can have multiple TACACS+ servers on the configuration, and use them for different purposes. Can you please expand a bit on what you're trying to accomplish?
Javier Henderson
Cisco Systems
04-01-2016 07:14 AM
TACACS setup present
aaa group server tacacs+ tacacs_admin
server
server
!
aaa authentication login default group tacacs_admin local
aaa authentication enable default group tacacs_admin enable
aaa accounting exec 15 start-stop group tacacs+
aaa accounting exec 1 stop-only group tacacs+
aaa accounting commands 1 default stop-only group tacacs+
aaa accounting commands 15 default stop-only group tacacs+
TACACS setup new
aaa group server tacacs+ name
server
server
server
ip tacacs source-interface Serial0/0/0
aaa authentication login default group name local
aaa authentication login console none
aaa authorization console
aaa authorization exec default group name local
aaa authorization exec console none
aaa accounting exec default start-stop group name
Different TACACS keys also
Can I run both at the same time until I verify the new setup is working?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide