1、一 、认证 1、拓扑图为:2、SW配备命令:aaa new-modeltacacs-server host 192.200.103.10tacacs-server key cisco (可选)aaa authentication login loginlist group tacacs+line vty 0 4 login authentication loginlist 3、SW show running-config配备sw#sh running-configBuilding configuration.Current configuration :1006 bytes!version 1
2、2.4service timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption!hostname sw!boot-start-markerboot-end-marker!aaa new-model!aaa authentication login loginlist group tacacs+!aaa session-id commonmemory-size iomem 5no ip routing!! no ip cefno ip domain lookup
3、!interface FastEthernet0/0 ip address 192.200.103.1 255.255.255.0 no ip route-cache duplex auto speed auto!interface FastEthernet2/0 ip address 192.200.103.2 255.255.255.0 no ip route-cache duplex auto speed auto!interface FastEthernet3/0 ip address 192.200.103.3 255.255.255.0 no ip route-cache dupl
4、ex auto speed auto!ip http serverno ip http secure-server! tacacs-server host 192.200.103.10tacacs-server directed-requesttacacs-server key cisco!control-plane!line con 0 exec-timeout 0 0 logging synchronousline aux 0line vty 0 4 login authentication loginlist!end 4、radius配备选中 右边 Add Entry选项5、在192.2
5、00.103.10 PC上测试 telnet 192.200.103.2 成功。使用test aaa group tacacs+ wolf wolf new-code 测试不成功因素:中默认server选项要修改命令中wolf是在user group中建立。 二、授权1、sw中命令配备:aaa authorization exec shouquan group tacacs+ localline vty 0 4 authorization exec shouquan2、ACS中配备:user setup中建立两个顾客cisco1和cisco2,分别属于group1和group2.group s
6、etup中shell值分别设立为15 和 1测试连接正常:sw# test aaa group tacacs+ cisco2 cisco2 new-codeUser successfully authenticated 在客户机上分别用cisco1和cisco2账号telnet 192.200.103.1结论:当权限为1顾客登录需要输入enable密码,用密码登录特权模式后提高为15级如cisco2;cisco1权限为15,不用输入enable直接进入特权模式。设立15级别group1顾客cisco1不能用show running-config命令:aaa authorization comm
7、ands 15 commands15 group tacacs+line vty 0 4 authorization commands 15 commands15测试成果:cisco1顾客: 审计:基于时间审计,会记录所用顾客进出时间。aaa accounting exec shenji start-stop group tacacs+基于命令审计,会记录所有1级和15级命令操作。aaa accounting commands 1 command1 start-stop group tacacs+aaa accounting commands 15 shenji15 start-stop gr
8、oup tacacs+sw(config)#line vty 0 4sw(config-line)#accounting exec shenji line vty 0 4 accounting commands 1 command1 accounting commands 15 shenji15 accounting exec shenji成果:sw#sh running-configBuilding configuration.Current configuration :1525 bytes!version 12.4service timestamps debug datetime mse
9、cservice timestamps log datetime msecno service password-encryption!hostname sw!boot-start-markerboot-end-marker!enable password enpass!aaa new-model!aaa authentication login loginlist group tacacs+aaa authorization exec shouquan group tacacs+ localaaa authorization commands 15 commands15 group taca
10、cs+aaa accounting exec shenji start-stop group tacacs+aaa accounting commands 1 command1 start-stop group tacacs+aaa accounting commands 15 shenji15 start-stop group tacacs+!aaa session-id commonmemory-size iomem 5no ip routing!no ip cefno ip domain lookup!interface Loopback0 ip address 1.1.1.1 255.
11、255.255.255!interface FastEthernet0/0 ip address 192.200.103.1 255.255.255.0 no ip route-cache duplex auto speed auto!interface FastEthernet2/0 ip address 192.200.103.2 255.255.255.0 no ip route-cache duplex auto speed auto! interface FastEthernet3/0 ip address 192.200.103.3 255.255.255.0 no ip rout
12、e-cache duplex auto speed auto!ip http serverno ip http secure-server!tacacs-server host 192.200.103.10tacacs-server directed-requesttacacs-server key cisco!control-plane!line con 0 exec-timeout 0 0 logging synchronousline aux 0line vty 0 4 authorization commands 15 commands15 authorization exec shouquan accounting commands 1 command1 accounting commands 15 shenji15 accounting exec shenji login authentication loginlist!end