[j-nsp] How to configure two Tacacs servers with different keys in the same router ?

hani ibrahim hani.ibrahim.aswn at gmail.com
Mon Sep 24 09:01:17 EDT 2012


Dear All,

Kindly, appreciate you help ,

i tired to configure two different tacacs servers on the same routes but i
observed the below :

1- the first configured server is authenticating , but the 2nd one is not ?
so is it possible to authenticate  using both servers ?
2- i can authenticate locally + tacacs although I'm configuring
authentication-order [tacplus password] ? so why ?

config sample :
tacplus-server {
        10.10.10.1 {=========================================>this server
is authenticating first
            port 49;
            secret "$898%&asdertynkll*&8778%^"; ## SECRET-DATA
            timeout 10;
            single-connection;
            source-address 11.11.11.1;
        }
        20.20.20.1 {========================================> this one is
not authenticating
            port 49
            secret "$9$-vdY46tyh890dr%%@3df"; ## SECRET-DATA
            timeout 10;
            source-address 21.21.21.1;
}

 user admin  {=========================================>this user is used
for both servers on the router
            uid 2010;
            class super-user;

BR,
Hany


More information about the juniper-nsp mailing list