
C-2 TACACS+ Authentication Example
LX Series Configuration Guide
The TACACS+ superuser request attribute is independent from
the TACACS+ login. The TACACS+ superuser request attribute
is used to indicate which database to authenticate the superuser
password against after a user is logged in. When a user types
the enable command, and the TACACS+ superuser request is
enabled, the enable password will be authenticated against the
TACACS+ server database; otherwise it is checked against the
LX database "system".
TACACS+ Authentication Example
The following example describes the steps in the TACACS+
authentication process. In this example, the user attempts to
gain access to an LX asynchronous port.
1. The LX unit prompts the user for a username and password.
2. The username is sent to the TACACS+ authentication start
packet.
3. The server responds with an authentication reply packet,
which will either allow the user access or require a
password.
4. If a password is required, the user is prompted for one and
the LX sends it to the server in an authentication continue
packet.
5. The server responds with a packet that contains an
authentication status pass or an authentication status fail.
6. If the request is successful, the user will be allowed to log in;
otherwise the user will have two more chances to receive an
authentication status pass back from the server.
7. The LX unit then grants the user the services requested.
Comentarios a estos manuales