cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1157
Views
0
Helpful
1
Replies

Nexus 5K and AAA config

kwanm63my
Level 1
Level 1

Can somebody help provide a config for the nexus 5548 in which it try to look for my 2 ACS servers and then authenticate,  authorize and also do the accounting ( logging of commands ) . If the 2 ACS servers cannot be found then it will default to the local database login credential which will provide user  full access. Right now, I just have simple local account with full admin right for login only.

I see some mention that the ACS need to have " Custom Attributes needed ACSAttribute: cisco-av-pair*shell:rolesValue: network-admin
" added but what about the 'network-operator' role ?. but not sure how to do this either. 

thanks all

1 Reply 1

kwanm63my
Level 1
Level 1

found this link .

http://www.cisco.com/en/US/docs/switches/datacenter/nexus5000/sw/configuration/guide/cli/sec_tacacsplus.html#wp1272485

then all the below mentioned section in ACS either in user account or the group account

worked great