Page 2 - aaa accounting; commands
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software aaa accounting SR-2 Cisco IOS XR System Security Command Reference aaa accounting To create a method list for accounting, use the aaa accounting command in global configuration mode.To remove a list name from the system,...
Page 3 - This command cannot be used with TACACS or extended TACACS.; aaa authorization; Creates a method list to be used for authorization.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software aaa accounting SR-3 Cisco IOS XR System Security Command Reference Use the aaa accounting command to create default or named method lists defining specific accountingmethods and that can be used on a per-line or per-inte...
Page 4 - aaa accounting system default; no aaa accounting system default; AAA accounting is disabled.; none; method; group tacacs+—Uses the list of all TACACS+ servers for accounting.; This command was introduced on the Cisco CRS-1.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software aaa accounting system default SR-4 Cisco IOS XR System Security Command Reference aaa accounting system default To enable authentication, authorization, and accounting (AAA) system accounting, use the aaaaccounting syste...
Page 5 - You can specify up to four methods in the method list.; aaa authentication; Creates a method list for authentication.; Creates a method list for authorization.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software aaa accounting system default SR-5 Cisco IOS XR System Security Command Reference The default method list is automatically applied to all interfaces or lines. If no default method list isdefined, then no accounting takes...
Page 6 - Syntax Description; Default behavior applies the local authentication on all ports.; Command Modes; Global configuration; login; Sets authentication for login.; ppp; Character string used to name the authentication method list.; remote; The remote keyword is available only on the admin plane.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software aaa authentication SR-6 Cisco IOS XR System Security Command Reference aaa authentication To create a method list for authentication, use the aaa authentication command in global configurationmode. To disable this authen...
Page 7 - Creates a method list for accounting.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software aaa authentication SR-7 Cisco IOS XR System Security Command Reference Command History Usage Guidelines To use this command, you must be in a user group associated with a task group that includes the propertask IDs. For ...
Page 8 - aaa group server radius; Enables AAA authentication for logins.; Command
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software aaa authentication SR-8 Cisco IOS XR System Security Command Reference aaa group server radius Groups different RADIUS server hosts into distinct lists and distinctmethods. aaa group server tacacs+ Groups different TACAC...
Page 10 - local—Use local database for authorization.; Task ID; aaa
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software aaa authorization SR-10 Cisco IOS XR System Security Command Reference Use the aaa authorization command to create method lists defining specific authorization methods thatcan be used on a per-line or per-interface basis...
Page 11 - Examples
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software aaa authorization SR-11 Cisco IOS XR System Security Command Reference Examples The following example shows how to define the network authorization method list named listname1,which specifies that TACACS+ authorization i...
Page 12 - aaa default-taskgroup; no aaa default-taskgroup; No default task group is assigned for remote authentication.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software aaa default-taskgroup SR-12 Cisco IOS XR System Security Command Reference aaa default-taskgroup To specify a task group to be used for both remote TACACS+ authentication and RADIUSauthentication, use the aaa default-tas...
Page 13 - aaa group server radius group-name
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software aaa group server radius SR-13 Cisco IOS XR System Security Command Reference aaa group server radius To group different RADIUS server hosts into distinct lists, use the aaa group server radius commandin global configurat...
Page 15 - aaa group server tacacs+
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software aaa group server tacacs+ SR-15 Cisco IOS XR System Security Command Reference aaa group server tacacs+ To group different TACACS+ server hosts into distinct lists, use the b command in global configurationmode. To remove...
Page 17 - accounting
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software accounting SR-17 Cisco IOS XR System Security Command Reference accounting To enable authentication, authorization, and accounting (AAA) accounting services for a specific line orgroup of lines, use the accounting comman...
Page 19 - authorization
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software authorization SR-19 Cisco IOS XR System Security Command Reference authorization To enable authentication, authorization, and accounting (AAA) authorization for a specific line or groupof lines, use the authorization com...
Page 21 - deadtime minutes; no deadtime; Deadtime is set to 0.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software deadtime (server-group configuration) SR-21 Cisco IOS XR System Security Command Reference deadtime (server-group configuration) To configure the deadtime value at the RADIUS server group level, use the deadtime command ...
Page 22 - Related Commands
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software deadtime (server-group configuration) SR-22 Cisco IOS XR System Security Command Reference Related Commands Command Description aaa group server radius Groups different RADIUS server hosts into distinct lists anddistinct...
Page 23 - description string; no description; The default description is blank.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software description (AAA) SR-23 Cisco IOS XR System Security Command Reference description (AAA) To create a description of a task group or user group during configuration, use the description commandin task group configuration ...
Page 25 - group; netadmin
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software group SR-25 Cisco IOS XR System Security Command Reference group To add a user to a group, use the group command in username configuration mode. To remove the userfrom a group, use the no form of this command. group {roo...
Page 26 - command in global configuration mode.; usergroup; Configures a user group and associates it with a set of task groups.; username
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software group SR-26 Cisco IOS XR System Security Command Reference Use the group command in username configuration mode. To access username configuration mode, usethe username command in global configuration mode. If the group c...
Page 27 - inherit taskgroup
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software inherit taskgroup SR-27 Cisco IOS XR System Security Command Reference inherit taskgroup To enable a task group to derive permissions from another task group, use the inherit taskgroupcommand in task group configuration ...
Page 29 - inherit usergroup; inherit usergroup usergroup-name
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software inherit usergroup SR-29 Cisco IOS XR System Security Command Reference inherit usergroup To enable a user group to derive characteristics of another user group, use the inherit usergroupcommand in user group configuratio...
Page 30 - Configures a task group to be associated with a set of task IDs.; Configures a user group to be associated with a set of task groups.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software inherit usergroup SR-30 Cisco IOS XR System Security Command Reference Examples The following example shows how to enable the purchasing user group to inherit properties from thesales user group: RP/0/RP0/CPU0:router# co...
Page 31 - login authentication; no login authentication; Line configuration; default
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software login authentication SR-31 Cisco IOS XR System Security Command Reference login authentication To enable authentication, authorization, and accounting (AAA) authentication for logins, use the loginauthentication command ...
Page 33 - password
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software password (AAA) SR-33 Cisco IOS XR System Security Command Reference password (AAA) To create a login password for a user, use the password command in username or line configurationmode. To remove the password, use the no...
Page 34 - Adds a user to a group.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software password (AAA) SR-34 Cisco IOS XR System Security Command Reference Examples The following example shows how to establish the unencrypted password pwd1 for the user user1: RP/0/RP0/CPU0:router# configure RP/0/RP0/CPU0:ro...
Page 35 - no radius-server dead-criteria time seconds; seconds; The time criterion must be met for the server to be marked as dead.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software radius-server dead-criteria time SR-35 Cisco IOS XR System Security Command Reference radius-server dead-criteria time To specify the minimum amount of time, in seconds, that must elapse from the time that the router las...
Page 36 - Displays information for the dead-server detection criteria.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software radius-server dead-criteria time SR-36 Cisco IOS XR System Security Command Reference Examples The following example shows how to establish the time for the dead-criteria conditions for a RADIUSserver to be marked as dea...
Page 37 - no radius-server dead-criteria tries tries; tries; The tries criterion must be met for the server to be marked as dead.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software radius-server dead-criteria tries SR-37 Cisco IOS XR System Security Command Reference radius-server dead-criteria tries To specify the number of consecutive timeouts that must occur on the router before the RADIUS serve...
Page 39 - radius-server deadtime; radius-server deadtime minutes; no radius-server deadtime; Dead time is set to 0.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software radius-server deadtime SR-39 Cisco IOS XR System Security Command Reference radius-server deadtime To improve RADIUS response times when some servers are unavailable and cause the unavailableservers to be skipped immedia...
Page 40 - Configures the deadtime value at the RADIUS server group level.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software radius-server deadtime SR-40 Cisco IOS XR System Security Command Reference Related Commands Command Description deadtime (server-groupconfiguration) Configures the deadtime value at the RADIUS server group level. radius...
Page 43 - radius-server retransmit; Sets the interval a router waits for a server host to reply.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software radius-server host SR-43 Cisco IOS XR System Security Command Reference Related Commands Command Description aaa accounting Creates a method list for accounting. aaa authentication Creates a method list for authenticatio...
Page 44 - The authentication and encryption key is disabled.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software radius-server key SR-44 Cisco IOS XR System Security Command Reference radius-server key To set the authentication and encryption key for all RADIUS communications between the router andthe RADIUS daemon, use the radius-...
Page 45 - Specifies a RADIUS server host.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software radius-server key SR-45 Cisco IOS XR System Security Command Reference Related Commands Command Description radius-server host Specifies a RADIUS server host.
Page 46 - radius-server retransmit retries; no radius-server retransmit
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software radius-server retransmit SR-46 Cisco IOS XR System Security Command Reference radius-server retransmit To specify the number of times the Cisco IOS XR software retransmits a packet to a server before givingup, use the ra...
Page 47 - radius-server timeout; radius-server timeout seconds; no radius-server timeout
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software radius-server timeout SR-47 Cisco IOS XR System Security Command Reference radius-server timeout To set the interval for which a router waits for a server host to reply before timing out, use theradius-server timeout com...
Page 48 - radius source-interface; no radius source-interface
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software radius source-interface SR-48 Cisco IOS XR System Security Command Reference radius source-interface To force RADIUS to use the IP address of a specified interface or subinterface for all outgoing RADIUSpackets, use the ...
Page 50 - secret
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software secret SR-50 Cisco IOS XR System Security Command Reference secret To create a secure login secret for a user, use the secret command in username or line configurationmode. To remove the secure secret, use the no form of...
Page 52 - If no port attributes are defined, the defaults are as follows:
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software server (RADIUS) SR-52 Cisco IOS XR System Security Command Reference server (RADIUS) To associate a particular RADIUS server with a defined server group, use the server command inRADIUS server-group configuration mode. T...
Page 54 - hostname
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software server (TACACS+) SR-54 Cisco IOS XR System Security Command Reference server (TACACS+) To associate a particular TACACS+ server with a defined server group, use the server command inTACACS+ server-group configuration mod...
Page 55 - Groups different TACACS+ server hosts into distinct lists.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software server (TACACS+) SR-55 Cisco IOS XR System Security Command Reference Related Commands Command Description aaa group server tacacs+ Groups different TACACS+ server hosts into distinct lists.
Page 56 - show aaa; taskgroup
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software show aaa SR-56 Cisco IOS XR System Security Command Reference show aaa To display information about a user group, local user, or task group; to list all task IDs associated withall user groups, local users, or task group...
Page 59 - Displays task IDs enabled for the currently logged-in user.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software show aaa SR-59 Cisco IOS XR System Security Command Reference Task: inventory : READ WRITE EXECUTE DEBUG Task: ip-services : READ WRITE EXECUTE DEBUG Task: ipv4 : READ WRITE EXECUTE DEBUG Task: ipv6 : READ WRITE EXECUTE ...
Page 60 - show radius
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software show radius SR-60 Cisco IOS XR System Security Command Reference show radius To display information about the RADIUS servers that are configured in the system, use the show radiuscommand in EXEC mode. show radius Syntax ...
Page 61 - Field; Server
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software show radius SR-61 Cisco IOS XR System Security Command Reference Table 2 describes the significant fields shown in the display. Related Commands Table 2 show radius Field Descriptions Field Description Server Server IP a...
Page 62 - show radius accounting; This command has no arguments or keywords.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software show radius accounting SR-62 Cisco IOS XR System Security Command Reference show radius accounting To obtain information and detailed statistics for the RADIUS accounting server and port, use the showradius accounting co...
Page 63 - show radius authentication
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software show radius accounting SR-63 Cisco IOS XR System Security Command Reference Server: 12.38.28.18, port: 29199 0 requests, 0 pending, 0 retransmits 0 responses, 0 timeouts, 0 bad responses 0 bad authenticators, 0 unknown t...
Page 66 - show radius client; The following sample output is for the show radius client command:
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software show radius client SR-66 Cisco IOS XR System Security Command Reference show radius client To obtain general information about the RADIUS client on Cisco IOS XR software, use the show radiusclient command in EXEC mode. s...
Page 67 - Client NAS identifier
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software show radius client SR-67 Cisco IOS XR System Security Command Reference Table 5 describes the significant fields shown in the display. Related Commands Table 5 show radius client Field Descriptions Field Description Clie...
Page 68 - show radius dead-criteria; EXEC
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software show radius dead-criteria SR-68 Cisco IOS XR System Security Command Reference show radius dead-criteria To obtain information about the dead server detection criteria, use the show radius dead-criteriacommand in EXEC mo...
Page 70 - show radius server-groups
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software show radius server-groups SR-70 Cisco IOS XR System Security Command Reference show radius server-groups To display information about the RADIUS server groups that are configured in the system, use the showradius server-...
Page 72 - show tacacs
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software show tacacs SR-72 Cisco IOS XR System Security Command Reference show tacacs To display information about the TACACS+ servers that are configured in the system, use the showtacacs command in EXEC mode. show tacacs Syntax...
Page 74 - show tacacs server-groups
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software show tacacs server-groups SR-74 Cisco IOS XR System Security Command Reference show tacacs server-groups To display information about the TACACS+ server groups that are configured in the system, use theshow tacacs server...
Page 76 - show task supported
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software show task supported SR-76 Cisco IOS XR System Security Command Reference show task supported To display all task IDs available in the system, use the show task supported command in EXEC mode. show task supported Syntax D...
Page 78 - show user; all
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software show user SR-78 Cisco IOS XR System Security Command Reference show user To display all user groups and task IDs associated with the currently logged-in user, use the show usercommand in EXEC mode. show user [all | authe...
Page 81 - Displays all task IDs defined in the system.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software show user SR-81 Cisco IOS XR System Security Command Reference Task: logging : READ WRITE EXECUTE DEBUG Task: lpts : READ WRITE EXECUTE DEBUG Task: monitor : READ WRITE EXECUTE DEBUG Task: mpls-ldp : READ WRITE EXECUTE D...
Page 82 - (Optional) Entering 7 specifies that an encrypted key follows.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software tacacs-server host SR-82 Cisco IOS XR System Security Command Reference tacacs-server host To specify a TACACS+ host server, use the tacacs-server host command in global configuration mode.To delete the specified name or...
Page 83 - tacacs-server timeout
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software tacacs-server host SR-83 Cisco IOS XR System Security Command Reference Usage Guidelines To use this command, you must be in a user group associated with a task group that includes the propertask IDs. For detailed inform...
Page 84 - No default behavior or values
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software tacacs-server key SR-84 Cisco IOS XR System Security Command Reference tacacs-server key To set the authentication encryption key used for all TACACS+ communications between the HF and theTACACS+ daemon, use the tacacs-s...
Page 86 - tacacs-server timeout seconds; no tacacs-server timeout
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software tacacs-server timeout SR-86 Cisco IOS XR System Security Command Reference tacacs-server timeout To set the interval that the server waits for a server host to reply, use the tacacs-server timeout commandin global config...
Page 87 - tacacs source-interface; tacacs source-interface type instance
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software tacacs source-interface SR-87 Cisco IOS XR System Security Command Reference tacacs source-interface To specify the source IP address of a selected interface for all outgoing TACACS+ packets, use thetacacs source-interfa...
Page 89 - task
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software task SR-89 Cisco IOS XR System Security Command Reference task To add a task ID to a task group, use the task command in task group configuration mode. To remove atask ID from a task group, use the no form of this comman...
Page 91 - string
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software taskgroup SR-91 Cisco IOS XR System Security Command Reference taskgroup To configure a task group to be associated with a set of task IDs, and to enter task group configurationmode, use the taskgroup command in global c...
Page 92 - Adds a task ID to a task group.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software taskgroup SR-92 Cisco IOS XR System Security Command Reference Entering the taskgroup command with no keywords or arguments enters task group configuration mode,in which you can use the description, inherit, show, and ta...
Page 93 - timeout login response; timeout login response seconds
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software timeout login response SR-93 Cisco IOS XR System Security Command Reference timeout login response To set the interval that the server waits for a reply to a login, use the timeout login response commandin line configura...
Page 95 - Five predefined user groups are available by default.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software usergroup SR-95 Cisco IOS XR System Security Command Reference usergroup To configure a user group and associate it with a set of task groups, and to enter user group configurationmode, use the usergroup command in globa...
Page 98 - Defines a method list for authentication.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software username SR-98 Cisco IOS XR System Security Command Reference From global configuration mode, you can display all the configured usernames. However, you cannotdisplay all the configured usernames in username configuratio...
Page 99 - users group; The serviceadmin keyword was added.
Authentication, Authorization, and Accounting Commands on Cisco IOS XR Software users group SR-99 Cisco IOS XR System Security Command Reference users group To associate a user group and its privileges with a line, use the users group command in lineconfiguration mode. To delete a user group associa...