zoukankan      html  css  js  c++  java
  • 配置Nexus Tacacs管理

    1、设备拓扑:

    N7K(mgmt0)----VMnet1-----ACS5.2

    2、设备配置:
    2.1、基础配置
    第一部分:N7K
    interface mgmt0
    vrf member management
    ip address 10.0.0.101/24
    测试连通性:
    N7K-2# ping 10.0.0.1
    PING 10.0.0.1 (10.0.0.1): 56 data bytes
    ping: sendto 10.0.0.1 64 chars, No route to host
    ^C
    --- 10.0.0.1 ping statistics ---
    1 packets transmitted, 0 packets received, 100.00% packet loss
    N7K-2# ping 10.0.0.1 vrf management
    PING 10.0.0.1 (10.0.0.1): 56 data bytes
    64 bytes from 10.0.0.1: icmp_seq=0 ttl=63 time=0.677 ms
    64 bytes from 10.0.0.1: icmp_seq=1 ttl=63 time=0.524 ms
    64 bytes from 10.0.0.1: icmp_seq=2 ttl=63 time=0.952 ms
    64 bytes from 10.0.0.1: icmp_seq=3 ttl=63 time=0.843 ms
    64 bytes from 10.0.0.1: icmp_seq=4 ttl=63 time=0.469 ms

    --- 10.0.0.1 ping statistics ---
    5 packets transmitted, 5 packets received, 0.00% packet loss
    round-trip min/avg/max = 0.469/0.692/0.952 ms

    第二部分:ACS5.2
    ACS/admin# sho interface gigabitEthernet 0
    eth0 Link encap:Ethernet HWaddr 00:0C:29:33:F9:EF
    inet addr:10.0.0.102 Bcast:10.0.0.255 Mask:255.255.255.0
    inet6 addr: fe80::20c:29ff:fe33:f9ef/64 Scope:Link
    UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
    RX packets:5735 errors:0 dropped:0 overruns:0 frame:0
    TX packets:7979 errors:0 dropped:0 overruns:0 carrier:0
    collisions:0 txqueuelen:1000
    RX bytes:1319303 (1.2 MiB) TX bytes:8018911 (7.6 MiB)
    Interrupt:177 Base address:0x2000

    测试连通性:
    ACS/admin# ping 10.0.0.1
    PING 10.0.0.1 (10.0.0.1) 56(84) bytes of data.
    64 bytes from 10.0.0.1: icmp_seq=0 ttl=64 time=0.240 ms
    64 bytes from 10.0.0.1: icmp_seq=1 ttl=64 time=0.190 ms
    64 bytes from 10.0.0.1: icmp_seq=2 ttl=64 time=0.207 ms
    64 bytes from 10.0.0.1: icmp_seq=3 ttl=64 time=0.185 ms

    --- 10.0.0.1 ping statistics ---
    4 packets transmitted, 4 received, 0% packet loss, time 3016ms
    rtt min/avg/max/mdev = 0.185/0.205/0.240/0.025 ms, pipe 2

    ACS/admin#

    2.2、保证N7K和ACS之前的连通性:
    N7K-2# ping 10.0.0.102 vrf management
    PING 10.0.0.102 (10.0.0.102): 56 data bytes
    64 bytes from 10.0.0.102: icmp_seq=0 ttl=63 time=0.713 ms
    64 bytes from 10.0.0.102: icmp_seq=1 ttl=63 time=0.564 ms
    64 bytes from 10.0.0.102: icmp_seq=2 ttl=63 time=0.629 ms
    64 bytes from 10.0.0.102: icmp_seq=3 ttl=63 time=0.654 ms
    64 bytes from 10.0.0.102: icmp_seq=4 ttl=63 time=1.162 ms

    --- 10.0.0.102 ping statistics ---
    5 packets transmitted, 5 packets received, 0.00% packet loss
    round-trip min/avg/max = 0.564/0.744/1.162 ms
    N7K-2#

    2.3、配置Tacacs
    主要配置部分体现为绿色配置,其他部分为默认或自动产生配置。
    N7K-2# sho running-config tacacs+ all

    !Command: show running-config tacacs+ all
    !Time: Mon Sep 2 12:21:19 2019

    version 6.1(1)
    feature tacacs+

    tacacs-server key 7 "Fewhg@123"
    no ip tacacs source-interface
    tacacs-server test username test password test idle-time 0
    tacacs-server timeout 5
    tacacs-server deadtime 0
    tacacs-server host 10.0.0.102 port 49
    tacacs-server host 10.0.0.102 test username test password test idle-time 0
    aaa group server tacacs+ TACACS
      server 10.0.0.102
      use-vrf management
      no source-interface

    2.4、ACS配置
    N7K-2这个名字不一定要和设备一样,这里为了好分别!这只是定义设备的一个名字,主要是那个IP地址。

     

     

    3、验证

    N7K-2# exit


    *****************
    Username: admin
    Password: cisco
    *****************
    N7K-2 login: admin
    Password: (这里使用的是cisco,错误了!)
    Login incorrect


    *****************
    Username: admin
    Password: cisco
    *****************
    login: admin
    Password: (这里使用了AAA的账户,成功了!)
    Last login: Mon Sep 2 12:03:31 UTC 2019 on ttyS0
    Last login: Mon Sep 2 12:25:25 on ttyS0
    Cisco NX-OS Software
    Copyright (c) 2002-2012, Cisco Systems, Inc. All rights reserved.
    NX-OS/Titanium software ("NX-OS/Titanium Software") and related
    documentation, files or other reference materials ("Documentation")
    are the proprietary property and confidential information of Cisco
    Systems, Inc. ("Cisco") and are protected, without limitation,
    pursuant to United States and International copyright and trademark
    laws in the applicable jurisdiction which provide civil and criminal
    penalties for copying or distribution without Cisco's authorization.
    The use of NX-OS/Titanium Software and Documentation is strictly
    limited to Cisco's internal use.

    Any use or disclosure, in whole or in part, of the NX-OS/Titanium
    Software or Documentation to any third party for any purposes is
    expressly prohibited except as otherwise authorized by Cisco in writing.
    The copyrights to certain works contained herein are owned by other
    third parties and are used and distributed under license. Some parts
    of this software may be covered under the GNU Public License or the
    GNU Lesser General Public License. A copy of each such license is
    available at
    http://www.gnu.org/licenses/gpl.html and
    http://www.gnu.org/licenses/lgpl.html
    N7K-2#

    4、ACS上查看认证信息

     

    可以看到如下是我前后两次输错和输对密码的情况:

    Detail信息:

     

  • 相关阅读:
    Ansible 的初步使用
    HBase 和 Hive 的差别是什么,各自适用在什么场景中?Spark SQL能做什么?
    spark安装配置
    scala安装配置
    Apache Spark 3.0.0重磅发布 —— 重要特性全面解析
    hbase的安装与配置(三台集群分布式)
    Flv的结构分析
    几种直播流媒体协议
    rtmp推送aac没有声音的问题记录
    c++中SetEvent和ResetEvent的使用
  • 原文地址:https://www.cnblogs.com/MomentsLee/p/11520165.html
Copyright © 2011-2022 走看看