[c-nsp] TACACS+ per VRF

andi rusiawan rusiawan at ipv6.or.id
Thu Jan 3 04:27:19 EST 2008


Hi,

I have been searching IOS version that support TACACS+ per VRF  for 2600
series (2621) using Cisco feature navigator.
Using Search by Feature menu i didn't see 2600 family in the Platform
options. So I guess that no IOS for 2600 series that support TACACS+ per VRF
feature.

Cisco Documentation explained that TACACS+ per VRF was introduced since
release 12.3(7)T. Being desperate, i try to use
c2600-jsx-mz.123-11.T10.binimage.  Unfortunately the tacacs+ server is
in my customer network and i
cant use it now. Trying c2600-jsx-mz.123-11.T10.bin image in my offline
router, i can configure example configuration :

aaa group server tacacs+ tacacs1

     server-private 10.1.1.1 port 19 key cisco

     ip vrf forwarding cisco

     ip tacacs source-interface Loopback0

   ip vrf cisco

    rd 100:1

   interface Loopback0

    ip address 10.0.0.2 255.0.0.0

    ip vrf forwarding cisco

Seems that it supports TACACS+ per VRF, doesn't it ?

Comment ?
Any experience configuring  TACACS+ per VRF in 2600 series router ?


-- 

Best Regards
-arsw-


More information about the cisco-nsp mailing list